Cloud 101CircleEventsBlog

Download Publication

STAR Continuous Technical Guidance
STAR Continuous Technical Guidance

STAR Continuous Technical Guidance

Release Date: 02/27/2019

STAR Continuous specifies the necessary activities and conditions for the continuous auditing of the cloud service over a defined set of security requirements, covering aspects from governance to infrastructure, and requiring the cloud service to define necessary processes that will be executed during the validation of controls within the scope of assessment. The program promotes trust by ensuring that a cloud service’s necessary activities and conditions are continuously met by through continuous auditing, such as through the operationalization of security and privacy requirements. This document explains the program and how to achieve STAR Continuous for an organization.
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
NIST CSF v2 Cloud Community Profile - Based on CCM v4
NIST CSF v2 Cloud Community Profile - Based on ...
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2
Informative Reference Details for the Mapping o...
CCM v4.0 Implementation Guidelines
CCM v4.0 Implementation Guidelines
The EU Cloud Code of Conduct: Apply GDPR Compliance Regulations to the Cloud
The EU Cloud Code of Conduct: Apply GDPR Compliance Regulations to ...
Published: 10/31/2024
Learn How to Conduct a Cybersecurity Audit for the Cloud with These CSA Training Options
Learn How to Conduct a Cybersecurity Audit for the Cloud with These...
Published: 10/18/2024
The Need for Continuous Assurance and Compliance Automation
The Need for Continuous Assurance and Compliance Automation
Published: 10/15/2024
CSA Community Spotlight: Bolstering the Mission of Cybersecurity with CEO Avani Desai
CSA Community Spotlight: Bolstering the Mission of Cybersecurity wi...
Published: 10/02/2024

Acknowledgements

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Since 2012 Michael has contributed to over 100 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud K...

Read more

Daniele Catteddu
Daniele Catteddu
Chief Technology Officer, CSA

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Damir Savanovic
Damir Savanovic

Damir Savanovic

Damir Savanovic (M) is an Associate Director - Cloud Controls Lead at Willis Towers Watson, leading a team of subject matter experts to address compliance and control requirements for multiple compliance frameworks within information and cybersecurity for a global financial institution.

As a security evangelist and subject matter expert in the areas of security governance, risk and compliance, data protection with over...

Read more

Alain Pannetrat
Alain Pannetrat
Senior Researcher, STAR Product Manager, CSA

Alain Pannetrat

Senior Researcher, STAR Product Manager, CSA

John DiMaria
John DiMaria
Director of Operations Excellence, CSA

John DiMaria

Director of Operations Excellence, CSA

John DiMaria; CSSBB, HISP, MHISP, AMBCI, CERP is the Director of Operations Excellence and Research Fellow with the Cloud Security Alliance. He has 40 years of experience in Standards and management System Development, including Information Systems, Business Continuity, and Quality. John was one of the innovators and co-founders of the CSA STAR programs Open Certification Framework for cloud providers and developed the first certification s...

Read more

Ronald Tse
Ronald Tse
CEO, Ribose

Ronald Tse

CEO, Ribose

Ronald has served CSA in numerous capacities, including as a member of CSA's APAC Research Advisory and International Standardization Council. Additionally, he co-chairs the Open Certification Framework (OCF), SaaS Governance, and DevSecOps working groups. He is the founder and CEO of Ribose, where under his leadership the company has been consistently awarded the industry's highest cloud security ratings, including being the on...

Read more

Tim Dafoe Headshot Missing
Tim Dafoe

Tim Dafoe

Timo Alexander Grof Headshot Missing
Timo Alexander Grof

Timo Alexander Grof

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training