Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
New Training Courses: Turn CSA research into practical skills with self-paced Frontier Ready Training.

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Frontier Ready Assessment Framework

Frontier Ready Assessment Framework

Release Date: 10/08/2026

AI-enabled adversaries are compressing exploit timelines, multiplying attack capacity, and putting expert-grade capabilities within reach of lower-skilled attackers. Preparing for these threats requires security program transformation: applying security fundamentals consistently, at machine...
Integrating DNS and SDP: Enhanced Zero Trust Policy Enforcement 2.0

Integrating DNS and SDP: Enhanced Zero Trust Policy Enforcement 2.0

Release Date: 10/07/2026

The Domain Name System (DNS) is a foundational Internet service and a persistent security blind spot in enterprise environments. DNS over HTTPS (DoH) and DNS over TLS (DoT) protect the confidentiality of DNS queries. However, encryption alone does not provide the identity awareness, policy...
Comparing FHE and Other PETs

Comparing FHE and Other PETs

Release Date: 09/28/2026

Privacy-enhancing technologies (PETs) offer a broad spectrum of solutions for data confidentiality. Selecting the right technology for a given privacy challenge requires careful consideration. A strong choice is fully homomorphic encryption (FHE), which enables computation directly on encrypted...