ChaptersEventsBlog
Register for DataSecAI 2025 in Dallas – Protect Data, Secure AI, and Drive Innovation

Download Publication

Security Guidance for Critical Areas of Focus in Cloud Computing v5
Security Guidance for Critical Areas of Focus in Cloud Computing v5

Security Guidance for Critical Areas of Focus in Cloud Computing v5

Release Date: 07/15/2024

Updated On: 08/26/2025

Working Group: Security Guidance

Cloud computing has firmly cemented its place as the foundation of the information security industry. The Cloud Security Alliance’s Security Guidance v5 is professionals' go-to resource for understanding modern cloud components and cloud security best practices. Balancing foundational knowledge with in-depth exploration of specialized topics across 12 domains, this essential document equips professionals with actionable skills and enables them to effectively address modern cloud security challenges.

This fifth version is built on previous iterations of the Security Guidance and is enhanced with a decade’s worth of insights about the skills needed to be successful in today's complex environments. Additions include the latest developments in Zero Trust, Generative AI, CI/CD, Security Monitoring and Operations, Resilience, Cloud Telemetry and Security Analytics, and Data Lakes. Version 5 also has reduced coverage of Laws and Regulations and has removed the Security-as-a-Service domain.

Note that Security Guidance is no longer the primary study material for the Certificate of Cloud Security Knowledge (CCSK). Access the CCSK v5 Study Guide here. Security Guidance v5 provides a more comprehensive understanding of the 12 domains, but is not required to pass the CCSK v5 exam.

Cloud Security Domains Covered:
  • Cloud Computing Concepts and Architectures
  • Cloud Governance
  • Risk, Audit, and Compliance
  • Organization Management
  • Identity and Access Management
  • Security Monitoring
  • Infrastructure and Networking
  • Cloud Workload Security
  • Data Security
  • Application Security
  • Incident Response and Resilience
  • Related Technologies and Strategies

Related Materials:
Download this Resource

Bookmark
Share
View translations
Related resources
Security Guidance v4.0 Info Sheet
Security Guidance v4.0 Info Sheet
Security Guidance for Critical Areas of Focus in Cloud Computing v4.0
Security Guidance for Critical Areas of Focus i...
FedRAMP Cloud Controls Matrix v3.0.1 Candidate Mapping
FedRAMP Cloud Controls Matrix v3.0.1 Candidate ...
Why I'm Joining CSA
Why I'm Joining CSA
Published: 09/16/2025
Jurassic Access: What Jurassic Park Teaches Us About Identity and Access Management
Jurassic Access: What Jurassic Park Teaches Us About Identity and A...
Published: 08/01/2025
Implementing CCM: Cloud Security Monitoring & Logging
Implementing CCM: Cloud Security Monitoring & Logging
Published: 07/28/2025
Introducing the OWASP NHI Top 10: Standardizing Non-Human Identity Security
Introducing the OWASP NHI Top 10: Standardizing Non-Human Identity ...
Published: 06/30/2025

Acknowledgements

Daniele Catteddu
Daniele Catteddu
Chief Technology Officer, CSA

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Rich Mogull
Rich Mogull
Chief Analyst, CSA

Rich Mogull

Chief Analyst, CSA

Rich is the Chief Analyst at the Cloud Security Alliance where he focuses on leading-edge cloud and AI security research and implementation. He has over 25 years of security experience, with over 15 years of focusing on cloud and emerging technologies. Prior to joining the CSA full time Rich frequently collaborated with CSA as the principle course designer of the CCSK training class, primary author of the Guidance, and developer of the Clou...

Read more

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.

He has co-chaired...

Read more

John Yeoh
John Yeoh
Chief Scientific Officer, CSA

John Yeoh

Chief Scientific Officer, CSA

With over 15 years of experience in research and technology, John excels at executive-level leadership, relationship management, and strategy development. He is a published author, technologist, and researcher with areas of expertise in cybersecurity, cloud computing, information security, and next generation technology (IoT, Big Data, SecaaS, Quantum). John specializes in risk management, third party assessment, GRC, data protection, incid...

Read more

Asif Jamal
Asif Jamal
Cloud Security Consultant, Jcloudit Service & Training Inc.

Asif Jamal

Cloud Security Consultant, Jcloudit Service & Training Inc.

As a Cloud Computing, Cybersecurity, and AI/ML Solution Consultant, I specialize in helping businesses leverage cutting-edge technologies to drive innovation, enhance security, and optimize operations. With a strong background in cloud architecture, cybersecurity frameworks, and data-driven solutions, I bring a holistic approach to solving complex challenges in the digital landscape.

My passion lies in guiding organizati...

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training