ChaptersEventsBlog
Register now for NHIcon 2026, a half-day online event, to learn what the future of AI security requires.

Working Group

Privacy

The Privacy Working Group develops privacy-enhancing technologies and engineering best practices that protect sensitive data throughout its lifecycle, especially during processing.
The Privacy Working Group advances technologies and engineering practices that protect sensitive data throughout its entire lifecycle—especially during processing, where traditional security models leave information most vulnerable. The group focuses on privacy-enhancing technologies (PETs), trusted execution and computation models, and privacy-by-design methodologies that enable secure analytics, collaboration, and data-driven innovation without exposing underlying data.

Through research, experimentation, and standards development, the group promotes practical approaches for integrating strong privacy protections into modern cloud environments, development workflows, and data science practices. Its mission is to help organizations adopt high-assurance privacy controls, reduce risk and attack surfaces, and meet evolving regulatory and compliance expectations while enabling responsible and secure use of data.

Working Group Leadership

Josh Buker
Josh Buker

Josh Buker

Research Analyst, CSA

Ryan Gifford
Ryan Gifford

Ryan Gifford

Senior Research Analyst, CSA

Working Group Co-Chairs

Mark Bower
Mark Bower

Mark Bower

VP, Product Management at Anjuna

Mark Bower has two decades of experience at leading security companies in the U.S., Australia, U.K., and Germany. He is a noted expert in data protection, data privacy, and information risk reduction. Before joining Anjuna, where he owns product strategy for advanced confidential computing, he headed product and business strategy for Comforte AG, Voltage Security (acquired by HPE) and the Atalla HSM business at Hewlett Packard Enterprise. ...

Read more

Daniella Alpher
Daniella Alpher

Daniella Alpher

Lattica.ai

Daniella Alpher is an experienced tech marketer who specializes in strategy, branding and content marketing. Before focusing on marketing for cybersecurity and AI, she worked as a television producer at ABC News in New York, where she produced news segments for Good Morning America. Daniella has led marketing at CoolaData, Iguazio, DeepKeep, RevealSecurity and PeerSpot. She holds an MBA from INSEAD.

Read more

Joseph Wilson
Joseph Wilson

Joseph Wilson

Joseph Wilson is co-Chair for the Cloud Security Alliance's (CSA's) Fully Homomorphic Encryption (FHE) Working Group (WG), which was formed to address industrial deployment and adoption of FHE and to help the industry navigate this branch of Privacy Enhancing Technologies. He holds a PhD in Theoretical Physics from the University of Leeds, and an MPhys in Experimental Physics from the University of York. He is currently Head of Strategic In...

Read more

Steve Foster
Steve Foster

Steve Foster

Publications in ReviewOpen Until
SSCF Implementation GuidelinesDec 25, 2025
SSCF-CAIQDec 25, 2025
DLP and DSPM inHealthcare: AI-EnhancedSecurity and PrivacyDec 26, 2025
AICM to AIUC-1 MappingDec 28, 2025
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Virtual Meetings

Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can view all research meetings here.

Dec

17

Wed, December 17, 9:00am - 10:00am PST
CSA Privacy Working Group Meeting
See details
This is a meeting for the entirety of the CSA Privacy Working Group. The topics will vary, but largely we will talk about what's going on within the working group, how to participate, and other relevant news/topics pertaining to our Privacy research.

Currently we meet every other Wednesday, 9am-10am Pacific Time.

If this time does not work well for you, please let us know. We are considering having a second time slot to accommodate the greatest number of folks possible.

Useful links:

Dec

31

Wed, December 31, 9:00am - 10:00am PST
CSA Privacy Working Group Meeting
See details
This is a meeting for the entirety of the CSA Privacy Working Group. The topics will vary, but largely we will talk about what's going on within the working group, how to participate, and other relevant news/topics pertaining to our Privacy research.

Currently we meet every other Wednesday, 9am-10am Pacific Time.

If this time does not work well for you, please let us know. We are considering having a second time slot to accommodate the greatest number of folks possible.

Useful links:

Jan

14

Wed, January 14, 9:00am - 10:00am PST
CSA Privacy Working Group Meeting
See details
This is a meeting for the entirety of the CSA Privacy Working Group. The topics will vary, but largely we will talk about what's going on within the working group, how to participate, and other relevant news/topics pertaining to our Privacy research.

Currently we meet every other Wednesday, 9am-10am Pacific Time.

If this time does not work well for you, please let us know. We are considering having a second time slot to accommodate the greatest number of folks possible.

Useful links:

Jan

28

Wed, January 28, 9:00am - 10:00am PST
CSA Privacy Working Group Meeting
See details
This is a meeting for the entirety of the CSA Privacy Working Group. The topics will vary, but largely we will talk about what's going on within the working group, how to participate, and other relevant news/topics pertaining to our Privacy research.

Currently we meet every other Wednesday, 9am-10am Pacific Time.

If this time does not work well for you, please let us know. We are considering having a second time slot to accommodate the greatest number of folks possible.

Useful links:

Feb

11

Wed, February 11, 9:00am - 10:00am PST
CSA Privacy Working Group Meeting
See details
This is a meeting for the entirety of the CSA Privacy Working Group. The topics will vary, but largely we will talk about what's going on within the working group, how to participate, and other relevant news/topics pertaining to our Privacy research.

Currently we meet every other Wednesday, 9am-10am Pacific Time.

If this time does not work well for you, please let us know. We are considering having a second time slot to accommodate the greatest number of folks possible.

Useful links:

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

SSCF Implementation Guidelines

Open Until: 12/25/2025

The Cloud Security Alliance (CSA), in collaboration with the SaaS Security Capability Framework (SSCF) Working Group, is pl...

SSCF-CAIQ

Open Until: 12/25/2025

The Cloud Security Alliance (CSA), in collaboration with the SaaS Security Capability Framework (SSCF) Working Group, is pl...

DLP and DSPM inHealthcare: AI-EnhancedSecurity and Privacy

Open Until: 12/26/2025

Healthcare organizations face growing risks of data exposure as they adopt cloud platforms, AI tools, and connected technol...

AICM to AIUC-1 Mapping

Open Until: 12/28/2025

This document is an addendum to the 'AICM' that contains controls mapping between the CSA's AI Controls Matrix v1.0 and 'AI...