Download Publication

Security Guidance for Critical Areas of Focus in Cloud Computing v5
Release Date: 07/15/2024
Updated On: 08/26/2025
Working Group: Security Guidance
Note that Security Guidance is no longer the primary study material for the Certificate of Cloud Security Knowledge (CCSK). Access the CCSK v5 Study Guide here. Security Guidance v5 provides a more comprehensive understanding of the 12 domains, but is not required to pass the CCSK v5 exam.
Cloud Security Domains Covered:
- Cloud Computing Concepts and Architectures
- Cloud Governance
- Risk, Audit, and Compliance
- Organization Management
- Identity and Access Management
- Security Monitoring
- Infrastructure and Networking
- Cloud Workload Security
- Data Security
- Application Security
- Incident Response and Resilience
- Related Technologies and Strategies
Download this Resource
Related Resources
Acknowledgements

Daniele Catteddu
Chief Technology Officer, CSA
Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Rich Mogull
Chief Analyst, CSA
Rich is the Chief Analyst at the Cloud Security Alliance where he focuses on leading-edge cloud and AI security research and implementation. He has over 25 years of security experience, with over 15 years of focusing on cloud and emerging technologies. Prior to joining the CSA full time Rich frequently collaborated with CSA as the principle course designer of the CCSK training class, primary author of the Guidance, and developer of the Clou...

Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.
He has co-chaired...

John Yeoh
Chief Scientific Officer, CSA
With over 15 years of experience in research and technology, John excels at executive-level leadership, relationship management, and strategy development. He is a published author, technologist, and researcher with areas of expertise in cybersecurity, cloud computing, information security, and next generation technology (IoT, Big Data, SecaaS, Quantum). John specializes in risk management, third party assessment, GRC, data protection, incid...

Asif Jamal
Cloud Security Consultant, Jcloudit Service & Training Inc.
Interested in helping develop research with CSA?
Related Certificates & Training

Learn more