Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join Identity Week America to explore secure credentials, biometrics, and digital identity solutions while connecting with industry experts. Save 20% on your ticket with code CSASAVE20

All Articles

All Articles
Cloud Security Alliance Extends AI Assurance Leadership Into Agentic AI With Addition of AIUC-1 Certification to STAR Registry

Press Release Published: 06/30/2026

New designation allows enterprises to identify providers that have demonstrated safe, secure, and reliable AI agents SEATTLE – June 30, 2026 – The Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, to...

AI-Speed Risk Requires Identity-Defined Reachability

Blog Published: 07/02/2026

Why Zero Trust Steps 3, 4, and 5 must evolve beyond patching, topology, and ticket-driven connectivity   Written by Philip Griffiths, Head of Strategic Sales, NetFoundry. Executive Summary AI is compressing the time between vulnerability discovery, exploitation, and impact. Patc...

ISO 42001: The Importance of Knowing Your Role Before Building Your AI System

Blog Published: 07/21/2026

ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System (AIMS). Structured similarly to other ISO management system standards, like ISO 27001, with mandatory clauses 4 through 10 and an Annex A control set, it shares the same Plan-Do-Check-Act l...

Unpacking the Salesloft Incident

Blog Published: 07/20/2026

  Introduction On August 26, 2025, Google Threat intelligence Group released a report detailing a widespread data theft campaign targeting the sales automation platform Salesloft, via compromised OAuth tokens used by the third-party Drift AI chat agent [1][2].  The attack has been...

The Hidden Risks of the Agentic Enterprise: Bridging the AI Governance Gap

Blog Published: 07/17/2026

Software used to wait for permission. It executed specific instructions predictably, transparently, and only when a human initiated a process. Today, AI agents are crowding into IT environments. These autonomous entities can execute complex workflows, access critical systems and sensitive dat...

A Network Security Strategy for AI-Accelerated Attacks

Blog Published: 08/07/2026

AI is changing the speed of offensive security. Attackers are rapidly identifying vulnerabilities that once took months or years to discover and exploit. The technical barriers required to turn those vulnerabilities into attacks are rapidly collapsing. For network defenders, that means a fam...

How Organizations Build Mature Cloud Governance Programs

Blog Published: 07/24/2026

Most organizations have successfully adopted cloud technologies. However, far fewer have developed the governance maturity required to manage cloud environments consistently, securely, and at scale. As cloud ecosystems become more distributed, automated, and identity-driven, governance challe...

Today's Global Event. Tomorrow's Brand: The DNS Security Risks Behind Brand Impersonation

Blog Published: 07/27/2026

  Executive Summary Every major global event creates opportunities for cybercriminals to exploit trust. Whether it's an international sporting tournament, a holiday shopping season, tax season, a product launch, or a breaking news event, attackers quickly register lookalike domains, cr...

Humans, Machines, and the Future of Work

Blog Published: 07/28/2026

As AI becomes increasingly capable, where we are headed will be determined by the guidance and guardrails provided by those of us working in the field. How humans and AI will work together is an essential, some might say existential, question that will shape the future. What we need to reme...

The Growing Threat of Docusign Phishing Attacks

Blog Published: 07/29/2026

  Introduction: Docusign phishing attacks Researchers from Cado Security Labs (now part of Darktrace) identified a recent Docusign spearphishing email campaign targeting tech executives. Docusign email phishing is a type of email phishing where malicious actors send fraudulent emails...

CMMC Certification Deadlines are Coming Soon. Here’s What That Means for You

Blog Published: 07/15/2026

Organizations can no longer treat CMMC compliance as something to address later. In November 2025, the U.S. Department of War (DoW) began incorporating CMMC assessment requirements into applicable defense procurements. While the first phase of implementation focuses primarily on Level 1 and ...

PCI DSS 6.4.3 and 11.6.1: A Deep Dive into Payment Page Security and Integrity Requirements

Blog Published: 07/23/2026

For organizations that process payment card data online, the payment page has become one of the most targeted points of attack. Modern e-commerce environments rely heavily on third-party scripts, embedded payment forms, and dynamic content—all of which expand the attack surface in ways that...

Why M2M Authentication and API Security Must Work Together

Blog Published: 07/22/2026

TL;DR: Non-human identities are calling APIs across cloud environments every day. Securing those interactions requires two layers of control: Machine-to-machine authentication to prove the caller is legitimate API security to limit what that caller can access or do Organizations ar...

When "Who Are You?’ Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agents

Blog Published: 07/14/2026

It keeps coming back to a conversation I had about six months ago. I sat with the CISO of a fortune 50 retail organization to review an incident that had kept the security team up for two straight nights. No credentials were stolen. No malware was deployed. No firewall rule was broken....

Implementing CCM: Universal Endpoint Management Controls

Blog Published: 07/17/2026

The Cloud Controls Matrix (CCM) is a framework of controls that are essential for cloud computing security. Created by CSA, the CCM aligns with CSA best practices. You can use CCM to assess and guide the security of any cloud service. CCM also provides guidance on which actors within t...

AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI

Blog Published: 07/14/2026

The Cloud Security Alliance (CSA) recently announced the release of the AI Controls Matrix (AICM) v1.1, a significant update to our comprehensive framework for secure and trustworthy AI systems. Building on the strong foundation established with the original AICM release in 2025, this up...

How to Request Security Budget from Your CFO and Exec Teams

Blog Published: 07/29/2026

Security and finance teams both care deeply about risk, but they define and measure it differently. Security leaders often lead with controls, frameworks, and technical severity, while finance executives focus on outcomes like revenue, predictability, and cost containment.  But when sec...

A Zero Trust Approach to AI Asset Inventory

Blog Published: 07/31/2026

In a Zero Trust architecture, the foundational rule is simple: "You cannot protect what you cannot see." Organizations are rapidly adopting Artificial Intelligence, leading to a sprawling ecosystem of Large Language Models (LLMs), internal machine learning models, third-party APIs, trai...

Securing Agent Identities: 8 Risks Every CISO Must Address

Blog Published: 07/30/2026

Enterprises have spent two decades building real discipline around human identity: provisioning, least privilege, access reviews, clean deprovisioning. AI agents arrived faster than that discipline could be extended to them, so a population of powerful new identities is now operating ahead of...

Agent vs. Agentless Cloud Security: Why Deployment Methods Matter

Blog Published: 08/03/2026

The rapid adoption of cloud technologies has brought significant security challenges for organizations of all sizes. According to recent studies, over 70% of enterprises now operate in hybrid or multi-cloud environments, with 93% employing a multi-cloud strategy[1]. This complexity requires ro...

Looking for the CCM?

Start using the Cloud Controls Matrix to simplify compliance with multiple standards & regulations.