ChaptersEventsBlog
How is your enterprise using AI Agents? Help us benchmark security and take the survey before November 30 →

Working Group

Enterprise Architecture

This group follows closely to the CCM working group in order to map the architecture domains that help enterprises identify critical components that are key to their cloud security architecture. These domains, when agreed upon to an adjacent CCM control domain, create a larger picture for easily implementing strategies.
Enterprise Architecture Reference Diagram
Enterprise Architecture Reference Diagram

Download

Enterprise Architecture
Working Group Overview

This group follows closely to the CCM working group in order to map the architecture domains that help enterprises identify critical components that are key to their cloud security architecture. These domains, when agreed upon to an adjacent CCM control domain, create a larger picture for easily implementing strategies.

Explore the CSA Enterprise Architecture →


What do we discuss? 

During these meetings we typically discuss changes in the industry and collaborate on projects the group is currently working on. We welcome anyone who would like to join, even if you would like to just listen-in on your first call. 

Working Group Leadership

Jon-Michael Brook
Jon-Michael Brook

Jon-Michael Brook

Jon-Michael C. Brook is a certified, 25-year practitioner of cybersecurity, cloud, and privacy. He is the principal contributor to certification sites for privacy and cloud security, and has published books on privacy. Jon-Michael received numerous awards and recognition during his time with Raytheon, Northrop Grumman, Symantec, and Starbucks. He holds patents and trade secrets in intrusion detection, GUI design, and semantic data redaction...

Read more

Michael Roza
Michael Roza

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.

He has co-chaired...

Read more

Publications in ReviewOpen Until
Standards-Benchmarks-MaturityDec 13, 2025
Open Source Red Teaming Tool: PyRIT Automation Capability in Agentic Red Team Testing EnvironmentsDec 13, 2025
Using Zero Trust Against Identity Spoofing and AbuseDec 20, 2025
Using Zero Trust to Secure Enterprise Information in LLM EnvironmentsDec 20, 2025
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Virtual Meetings

Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can view all research meetings here.

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

Standards-Benchmarks-Maturity

Open Until: 12/13/2025

Standardization serves as a foundational backbone that enables uniqueness and diversity to flourish within structured envir...

Open Source Red Teaming Tool: PyRIT Automation Capability in Agentic Red Team Testing Environments

Open Until: 12/13/2025

This paper presents an open source red teaming tool for simulating adversarial attacks in modern systems. Designed for secu...

Using Zero Trust Against Identity Spoofing and Abuse

Open Until: 12/20/2025

The shift towards zero trust architectures brings in a heightened focus on the integrity of identity and identity attribute...

Using Zero Trust to Secure Enterprise Information in LLM Environments

Open Until: 12/20/2025

Guidance for safe enterprise enablement of AI/ML apps while protecting sensitive organizational information (IP, PII, etc.)...