CSAIChaptersEventsBlog
Join Anthropic, AWS, Google Cloud, Microsoft, SANS, and more this August at the SANS Cloud Security Exchange Summit →

All Articles

All Articles
Cloud Security Alliance Extends AI Assurance Leadership Into Agentic AI With Addition of AIUC-1 Certification to STAR Registry

Press Release Published: 06/30/2026

New designation allows enterprises to identify providers that have demonstrated safe, secure, and reliable AI agents SEATTLE – June 30, 2026 – The Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, to...

AI-Speed Risk Requires Identity-Defined Reachability

Blog Published: 07/02/2026

Why Zero Trust Steps 3, 4, and 5 must evolve beyond patching, topology, and ticket-driven connectivity   Written by Philip Griffiths, Head of Strategic Sales, NetFoundry. Executive Summary AI is compressing the time between vulnerability discovery, exploitation, and impact. Patc...

ISO 42001: The Importance of Knowing Your Role Before Building Your AI System

Blog Published: 07/21/2026

ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System (AIMS). Structured similarly to other ISO management system standards, like ISO 27001, with mandatory clauses 4 through 10 and an Annex A control set, it shares the same Plan-Do-Check-Act l...

Unpacking the Salesloft Incident

Blog Published: 07/20/2026

  Introduction On August 26, 2025, Google Threat intelligence Group released a report detailing a widespread data theft campaign targeting the sales automation platform Salesloft, via compromised OAuth tokens used by the third-party Drift AI chat agent [1][2].  The attack has been...

The Hidden Risks of the Agentic Enterprise: Bridging the AI Governance Gap

Blog Published: 07/17/2026

Software used to wait for permission. It executed specific instructions predictably, transparently, and only when a human initiated a process. Today, AI agents are crowding into IT environments. These autonomous entities can execute complex workflows, access critical systems and sensitive dat...

CMMC Certification Deadlines are Coming Soon. Here’s What That Means for You

Blog Published: 07/15/2026

Organizations can no longer treat CMMC compliance as something to address later. In November 2025, the U.S. Department of War (DoW) began incorporating CMMC assessment requirements into applicable defense procurements. While the first phase of implementation focuses primarily on Level 1 and ...

Why M2M Authentication and API Security Must Work Together

Blog Published: 07/22/2026

TL;DR: Non-human identities are calling APIs across cloud environments every day. Securing those interactions requires two layers of control: Machine-to-machine authentication to prove the caller is legitimate API security to limit what that caller can access or do Organizations ar...

When "Who Are You?’ Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agents

Blog Published: 07/14/2026

It keeps coming back to a conversation I had about six months ago. I sat with the CISO of a fortune 50 retail organization to review an incident that had kept the security team up for two straight nights. No credentials were stolen. No malware was deployed. No firewall rule was broken. ...

Implementing CCM: Universal Endpoint Management Controls

Blog Published: 07/17/2026

The Cloud Controls Matrix (CCM) is a framework of controls that are essential for cloud computing security. Created by CSA, the CCM aligns with CSA best practices. You can use CCM to assess and guide the security of any cloud service. CCM also provides guidance on which actors within t...

AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI

Blog Published: 07/14/2026

The Cloud Security Alliance (CSA) recently announced the release of the AI Controls Matrix (AICM) v1.1, a significant update to our comprehensive framework for secure and trustworthy AI systems. Building on the strong foundation established with the original AICM release in 2025, this ...

The Model Did Exactly What We Asked

Blog Published: 07/21/2026

An AI "went rogue" last week, just like out of a science fiction movie. Not because it turned on us, but to achieve its defined objective. Just as we were planning our CISO huddle on the Hugging Face attacks, a jaw dropping post from OpenAI was released that completely reframed the entire ...

Looking for the CCM?

Start using the Cloud Controls Matrix to simplify compliance with multiple standards & regulations.