ChaptersEventsBlog
Join Cohesity Catalyst on Tour at the data security and AI summit in NYC, Paris, or Singapore →

Cloud OS Security Specification v2.0

Released: 10/14/2020

Cloud Component Specifications

Cloud OS Security Specification v2.0
Cloud OS Security Specification v2.0
Currently, most of the standards related to cloud computing security focus on information security management systems (ISMS), and corresponding certifications only concentrate on cloud services rather than specific cloud components. There is a lack of internationally recognized technical security specifications and certifications for cloud components such as the cloud operating system (OS). CSA believes the guidance provided in this paper will be useful to help regulate security requirements for the cloud OS to prevent security threats and improve security capabilities of cloud OS products.

CSA’s Cloud Component Specifications Working Group first published the Cloud OS Security Specification v1 in July 2019. Some of the key changes and updates made in this revised version are:

  • Adjusted document structure to be more in line with logical architecture. Corresponding contents in version 1 are also moved / combined / removed according to the structure adjustment.

  • New requirements added in view of cloud security technology developments, including micro segmentation, hardware-based encryption, VM High availability, backup & recovery capability, key management service, cloud bastion host.

  • Several requirements are improved and revised to be more precise and instructive, such as the processing / saving of sensitive information, identity management and log functions.


Prefer to access this resource without an account? Download it now.

About the Sponsor

Accedere Logo
Accedere is an end-to-end Cybersecurity Audit/Assessment and Managed Security Services (MSSP) firm. As a Colorado CPA firm registered with PCAOB, and CSA, we specialize in Cloud Security and Privacy, helping clients navigate the evolving risks in today’s digital landscape. With cyber risk now the 3rd biggest risk in business, we provide deep expertise in evaluating Cyber Governance Maturity to safeguard your data. As CSA STAR auditors, we engage with CSP’s towards achieving CSA STAR compliance.
Our GRC automation tool Controllo is AI-powered and designed to streamline cyber compliance with frameworks like SOC 2, ISO 27001 (ISMS), and ISO 27701 (PIMS) & CSA’s CCM. Controllo helps manage risks across Assets, Organizational Risks, and Vendor Risks, leveraging NIST CSF 2.0 for comprehensive risk management.
We offer compliance audits focusing on SOC 1, SOC 2, and SOC 3 reports and as an ISO/IEC Certification Body for ISMS, PIMS, BCMS,SMS and AIMS (Artificial Intelligence) along with CSA STAR Audits.
From our India-based Security Operations Center (24x7 CSOC), we provide AI-driven monitoring and threat detection, powered by Microsoft Sentinel. Our real-time alerts on intrusions and Indicators of Compromise (IOCs) are supported by advanced assessments like Penetration Testing, Breach and Attack Simulation, and Configuration Reviews.
With years of experience auditing both large enterprises and SMBs, we bring exceptional capabilities and over 22 years of experience in Cyber, Cloud Security Assessments and Audits. Our business is led by Ashwin Chaudhary, an MBA, CPA, and certified expert with credentials including CCSK, CISSP, CISA, CISM, CEGIT,CRISC,CDPSE, and more.
For more information on how Accedere can protect your business, contact us at [email protected] or visit www.accedere.io

Partner Event Spotlight

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.