Download Publication
![Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted]](https://cloudsecurityalliance.org/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTc3MjEsInB1ciI6ImJsb2JfaWQifX0=--846e63ecb5438faa0471cb729b8fd20217573428/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJhdXRvX29yaWVudCI6dHJ1ZSwicm90YXRlIjowLCJncmF2aXR5IjoiY2VudGVyIiwiYmFja2dyb3VuZCI6Im5vbmUiLCJyZXNpemUiOiIyMjJ4Mjg2In0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--35dd4a886aca6333c466432352c9b33722c460a6/CAIQ-No-Longer-Accepted.png)
Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted]
Release Date: 04/01/2020
Working Group: Consensus Assessments
This version of the CAIQ is no longer accepted to the STAR Registry. Please download the new version of CAIQ Version 4, which has been combined with the Cloud Controls Matrix.
The Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services, providing security control transparency. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM). Therefore, it helps cloud customers to gauge the security posture of prospective cloud service providers and determine if their cloud services are suitably secure.
The CAIQ and CCM are used by CSPs to submit to the CSA STAR Registry. You can learn about the transition timeline for v3.1 to v4, and how that will affect submission to the STAR Registry in this blog.
The CAIQ and CCM are used by CSPs to submit to the CSA STAR Registry. You can learn about the transition timeline for v3.1 to v4, and how that will affect submission to the STAR Registry in this blog.
Download this Resource
Related Resources
Interested in helping develop research with CSA?
Related Certificates & Training
.png)
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more

.jpeg)
.jpeg)
.jpeg)