CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | Requirements for Bodies Providing STAR Certification Release Date: 03/31/2025 This document outlines how to conduct STAR certification assessments to the Cloud Controls Matrix (CCM) as part of an ISO 27001 assessment. The STAR certi... Request to download |
![]() | NIST CSF v2 Cloud Community Profile - Based on CCM v4 Release Date: 10/15/2024 The CSFv2.0 Cloud Community Profile aligns the Cloud Controls Matrix (CCM) version 4.0 with the Cybersecurity Framework (CSF) version 2.0 by mapping equiv... Request to download |
![]() | Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2 Release Date: 10/08/2024 The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices for securing cloud... Request to download |
![]() | CCM v4.0 Implementation Guidelines Release Date: 06/03/2024 This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM cont... Request to download |
![]() | Cloud Controls Matrix and CAIQ v4 Release Date: 06/03/2024 The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s... Request to download |
![]() | Standardizing Security in Diverse Sectors: A Template for STAR-Aligned Sector-Specific Standards Release Date: 03/06/2024 The CSA Security, Trust, Assurance, and Risk (STAR) program encompasses the key principles of transparency, rigorous auditing, and harmonization of cybers... Request to download |
![]() | STAR Attestation Value Proposition Release Date: 10/03/2023 Request to download |
![]() | Guidelines for CPAs Providing CSA STAR Attestation v4 Release Date: 09/07/2023 This document provides guidance for CPAs in conducting a STAR Attestation. It includes relevant information including professional requirements, competenc... Request to download |
![]() | Release Date: 08/31/2023 The CSA Security, Trust, Assurance, and Risk (STAR) program is the most complete and largest cloud assurance program in the world that constitutes an ecos... Request to download |
![]() | Release Date: 04/05/2023 The Cloud Controls Matrix (CCM) is a framework of controls (policies and procedures) that are essential for cloud computing security. It is created and up... Request to download |
![]() | Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix Release Date: 03/01/2023 The download file also contains the following: Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud ... Request to download |
![]() | Deconstructing Application Connectivity Challenges in a Complex Cloud Environment Release Date: 12/14/2022 The production and use of SaaS applications in organizations has grown exponentially over the past several years. Application Security has become an integ... Request to download |
![]() | CSA CCM v4.0 Addendum - Spain National Security Framework (ENS) Release Date: 12/08/2022 This document is an addendum to the CCM V4.0 that contains controls mapping between the CSA CCM and Spain's National Security Framework (ENS).The document... Request to download |
![]() | Release Date: 10/04/2022 This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and Japan's Information System Security Management and Asse... Request to download |
![]() | CSA CCM v4.0 Addendum - CRI FS Profile v1.2 Release Date: 07/15/2022 This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t... Request to download |
![]() | Release Date: 07/05/2022 This document serves as a mapping exercise between the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR) and the CS... Request to download |
![]() | CSA CCM v4.0 Addendum - UAE IA Regulation Release Date: 07/05/2022 This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and the UAE Information Assurance (IA) Regulation. The docu... Request to download |
![]() | Release Date: 03/17/2022 Compliance requires a comprehensive review of services and processes related to cloud infrastructure and how it is managed during a data lifecycle. STAR f... Request to download |
![]() | Release Date: 12/08/2021 This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework align... Request to download |
![]() | STAR Level 1: Security Questionnaire (CAIQ v4) - Japanese Translation Release Date: 11/02/2021 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |