Circle
Events
Blog

Welcome to the Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.

Latest News from CSA

Measuring Risk and Risk Governance
Measuring Risk and Risk Governance
The goal of this research project is to assess the maturity of public cloud and risk management within the enterprise. The key areas of interest include…

  • Assess the maturity of public cloud consumption and risk management in enterprises
  • Understand current challenges and perceived effectiveness of risk management in public cloud
  • Understand the impact of effective risk management practices in the cloud
  • Identify best practices to reduce risk and address risk tolerance in the cloud
Download the publlication
Top Threats to Cloud Computing Pandemic Eleven
Top Threats to Cloud Computing Pandemic Eleven
The Top Threats reports have traditionally aimed to raise awareness of threats, risks, and vulnerabilities in the cloud. Such issues are often the result of the shared, on-demand nature of cloud computing. In this fifth installment, we surveyed 703 industry experts on security issues in the cloud industry. This year our respondents identified eleven salient threats, risks, and vulnerabilities in their cloud environments. The Top Threats Working Group used the survey results and its expertise to create the 2022 Top Cloud Threats report - the ‘Pandemic Eleven’.
Download the publication
CISO Perspectives and Progress in Deploying Zero Trust
CISO Perspectives and Progress in Deploying Zero Trust
Some of the areas covered in this survey include where Zero Trust falls as a priority in the organization, the percentage of those who have completed related implementations, top business challenges, and top technical challenges. Through the survey and upcoming report, CSA is looking to learn where C-level executives are in terms of their Zero-Trust strategies, pain points, vendor needs, management requirements/oversight, technical considerations, legacy challenges, adoption rates, and stakeholder involvement. CSA is dedicated to educating the C-suite, board members, staff, and stakeholders on the benefits of Zero Trust.  
Download the publication

Explore resources for cloud security and learn more about CSA.

Research

Research
Emerging cloud technologies

Cloud has become the foundation for launching new technologies. Explore emerging technologies that impact the enterprise and adopt industry best practices for implementing and preparing for the future.

Leverage frameworks and architectures specific to cloud

Adopt core tools used by government and regulated industries for the use and management of cloud services. Build a foundation for secure cloud environments with proven models for mitigations, countermeasures, and capabilities specific to cloud computing. The following tools have been used by enterprises to implement frameworks, architectures, and approaches:

Increase transparency

Go beyond security and start building trust. Programs like CSA STAR help improve transparency between cloud customers and providers and bridge the communication gap. From streamlining risk assessments to improving your organization's position to offering an option for continuous self-assessments, it allows our industry to unite effectively to secure the cloud. 

Become certified in cloud security.

Gain the necessary knowledge to support a smooth cloud transition and beyond with focused training from CSA. Start by mastering the best practices of cloud security with the Certificate of Cloud Security Knowledge (CCSK). Earning the CCSK will lay the necessary foundation to prepare you to earn the new cloud auditing credential in development by CSA and ISACA. 

Certificate of Cloud Auditing Knowledge (CCAK)

The Certificate of Cloud Auditing Knowledge (CCAK) is the first credential available for industry professionals to demonstrate their expertise in the essential principles of auditing cloud computing systems. The CCAK credential and training program will fill the gap in the market for technical education for cloud IT auditing.

CSA Online Training

The CSA Knowledge Center is a centralized platform where you can access training based on CSA's vendor-neutral research. Creating an account on the Knowledge Center gives you access to free mini-courses, training and educational tools to help you better understand security in the cloud.

Certificates & Training

Certificates & Training

Membership for Businesses

Membership for Businesses
Become a CSA Corporate Member

Regardless if you already have a well established cloud security program or are starting your cloud migration for the first time, CSA can help you enhance your security strategy. As a corporate member, your team will be able to receive consultations on your current cloud projects and initiatives.


For organizations providing cloud or security services, joining CSA allows you to educate potential users and showcase your own expertise and good practices to a global marketplace.


SaaS Membership

SaaS companies represent the heart of business solutions and are growing rapidly. SaaS companies are very diverse in their size and security maturity. CSA’s SaaS membership provides specific benefits geared towards SaaS provider needs and pain points. Our goal is to help SaaS companies achieve excellent security and communicate a sense of trust to their customers and the greater market.

Cloud Security Executive Briefings

On-site and virtual private executive briefings give your team access to subject matter experts to discuss cloud-specific platforms, industry trends, and technology implementations. Attendees receive valuable insights presented exclusively to this group by some of the top industry experts leading CSA’s research activities. As a member you can start a conversation around what you're doing, and CSA can help connect you with the right people to talk through that strategy.

SECtember 2022 is the essential industry conference to assist organizations in elevating their cybersecurity capabilities. Held in the heart of the cloud industry in Bellevue, WA from September 26-30, 2022, SECtember will feature leaders from Government, Cloud, Cybersecurity and Global 2000 enterprises. The event will provide critical insights into board oversight of cybersecurity, CISO strategies, emerging threats and best practices, all against the backdrop of cloud and related leading edge technologies.

Register Today

Join the Alliance

CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products.

33

active working
groups and initiatives

413

research publications

57,000+

visitors view CSA
research each month

126,000+

industry professionals
are a part of CSA

1,400+

services listed in
the STAR Registry

Latest News

Zero Trust Creator John Kindervag Joins Cloud Security Alliance as Security Advisor

June 30, 2022

 

Cloud Security Alliance, Cyber Risk Institute Partner to Create Cloud Controls Matrix (CCM) Addendum for the Financial Sector

June 28, 2022

 

New Survey from Cloud Security Alliance and Google Finds Cloud Adoption Improves Risk Management and Mitigation

June 22, 2022

 

Cloud Security Alliance Offers Governance Best Practices for Protecting Data Throughout Software-as-a-Service (SaaS) Lifecycle

June 09, 2022

 

See more

Industry Insights

CCSK Success Stories: From a CISO and Chief Privacy Officer

CCSK Success Stories: From a CISO and Chief Privacy Officer

July 01, 2022

 
What is the CSA Cloud Controls Matrix and Why Should Everyone on the Cloud Care?

What is the CSA Cloud Controls Matrix and Why Should Everyone on the Cloud Care?

July 01, 2022

 
Five Steps to a Secure Cloud Architecture

Five Steps to a Secure Cloud Architecture

June 30, 2022

 
Definitive Guide to Kubernetes Admission Controller

Definitive Guide to Kubernetes Admission Controller

June 30, 2022

 

See more

Upcoming CSA Events

Cloudbytes Webinar Series
Cloudbytes Webinar Series

January 2022 | online

Learn more

It’s time to Zero In on Zero Trust
It’s time to Zero In on Zero Trust

March 23 - September 15 | Online

Learn more

CloudCon 2022
CloudCon 2022

July 25 | Grand Rapids, MI

Learn more

SECtember 2022
SECtember 2022

September 26 | Bellevue, WA - Meydenbauer Center

Learn more