Publication Coming Soon

The Continuous Audit Metrics Catalog
The Continuous Audit Metrics Catalog

The Continuous Audit Metrics Catalog

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evolving with continuous integration and deployment. Therefore, a certification obtained once a year after a third-party audit is not a sufficient source of assurance anymore. It’s time to move from “point-in-time” assurance to continuous assurance. This change requires moving away from manual audits and instead building automated tools that continuously assess the effectiveness of an information system. In other words, it’s time to move to the world of security metrics.

There is no standard reference that supports security metrics in a way that is comparable to what the CSA CCM or ISO/IEC 27002 does for security controls. To address this gap, CSA launched the Continuous Audit Metrics Working Group in early 2020 to build the first catalog of security metrics for the cloud. We have released the first version of this catalog as a request for comment. It contains an initial set of 33 security metrics, each mapped to the CCM v4. We invite the community to provide feedback by directly making comments in the document or sending them to [email protected]. Please share this work as widely as possible.

Coming Soon!

This research document is still being finalized. Fill out the following form and we’ll send you the final document once it is released.

CSA is a community driven organization. We would like to send you updates about our ongoing initiatives and opportunities to participate.

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).