CSA Official Press Release
Published 06/23/2020
Cloud Security Alliance Announces Availability of Key Cloud Security Assessment and Guidance Documents in 10 Additional Languages
Cloud Controls Matrix, Consensus Assessments Initiative Questionnaire, and PLA Code of Conduct for GDPR Compliance available to global audience
SEATTLE – June 23, 2020 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications and best practices to help ensure a secure cloud computing environment, announced today that three of its most popular assessment and guidance documents that ensure compliance with cloud security protocols are now, in the context of an agreement with OneTrust, available in 10 languages. The Cloud Controls Matrix, Consensus Assessments Initiative Questionnaire, and Privacy Level Agreement Code of Conduct for GDPR Compliance are now available in Spanish (ES), German (DE), French (FR), Italian (IT), Japanese (JA), Danish (DA), Dutch (NL), Portuguese (PT), Romanian (RO), and Swedish (SV).
“By expanding language formats, it’s our hope that these translations will facilitate the adoption of these valuable assets by even more organizations around the globe,” said Daniele Catteddu, Chief Technology Officer, Cloud Security Alliance. “As the cloud continues to grow in importance in today’s business landscape, the ability to ascertain which providers are mapping to security and compliance standards is an integral part of doing business. Moreover, the need to stay on the right side of privacy regulations are essential as enterprises continue to expand their business scope.”
About the frameworks:
- Cloud Controls Matrix (CCM): A cybersecurity control framework for cloud computing, composed of 133 control objectives that are structured in 16 domains covering all key aspects of the cloud technology. It can be used as a tool for the systematic assessment of a cloud implementation, and provides guidance on which security controls should be implemented by which actor within the cloud supply chain. The controls framework is aligned to the Security Guidance v4 and is currently considered a de-facto standard for cloud security assurance and compliance.
- Consensus Assessments Initiative Questionnaire (CAIQ): A companion to the CCM that provides a set of “yes or no” questions a cloud consumer or auditor may wish to ask a cloud provider. Based on the security controls in the CCM, the questions can be used to document which security controls exist in a provider’s IaaS, PaaS, and SaaS offerings. Over 500 organizations currently use the CAIQ to submit self-assessments on the STAR registry.
- Privacy Level Agreement Code of Conduct for GDPR Compliance (PLA CoC): The PLA CoC provides a consistent and comprehensive framework for complying with the European General Data Protection Regulation (GDPR) and is designed to be an appendix to a Cloud Services Agreement to describe the level of privacy protection that a cloud service provider will provide.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.