Cloud 101CircleEventsBlog
Register for CSA’s free Virtual Cloud Trust Summit to tackle enterprise challenges in cloud assurance.

Download Publication

The Continuous Audit Metrics Catalog
The Continuous Audit Metrics Catalog
Who it's for:
Compliance managers

The Continuous Audit Metrics Catalog

Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evolving with continuous integration and deployment. Therefore, a certification obtained once a year after a third-party audit is not a
sufficient source of assurance anymore. It’s time to move from “point-in-time” assurance to continuous assurance. This change requires moving away from manual audits and instead building automated tools that continuously assess the effectiveness of an information system. In other words, it’s time to move to the world of security metrics.

There is no standard reference for the continuous auditing of cloud services that supports security metrics in a way that is comparable to what the CSA CCM or ISO/IEC 27002 does for security controls. To address this gap, CSA launched the Continuous Audit Metrics Working Group in early 2020 to build the first catalog of security metrics for the cloud. We have released the first version of this catalog that contains an initial set of 34 security metrics, each mapped to the CCM v4. These metrics aim to support internal CSP governance, risk, and compliance (GRC) activities and provide a helpful baseline for service-level agreement transparency. 

Topics covered: 
  • Explanation of security metrics
  • How to measure the effectiveness of an information system
  • How to enable continuous auditing
  • Catalog listing the 34 metrics

Included in this zip file:
  • Continuous Audit Metrics Catalog
  • Code of Practice for Implementing and Maintaining Key Metrics
Download this Resource

Bookmark
Share
Related resources
Standardizing Security in Diverse Sectors: A Template for STAR-Aligned Sector-Specific Standards
Standardizing Security in Diverse Sectors: A Te...
Defining the Zero Trust Protect Surface
Defining the Zero Trust Protect Surface
STAR Attestation Value Proposition
STAR Attestation Value Proposition
Evaluate the Security of Your Cloud Service Provider with the CSA STAR Registry
Evaluate the Security of Your Cloud Service Provider with the CSA S...
Published: 04/13/2024
Building a SOC for Compliance
Building a SOC for Compliance
Published: 04/11/2024
The Secret to Supercharging LLMs: It's Not Answers, It's Questions
The Secret to Supercharging LLMs: It's Not Answers, It's Questions
Published: 04/10/2024
The Modern Data Stack Has Changed the Security Landscape
The Modern Data Stack Has Changed the Security Landscape
Published: 04/05/2024

Acknowledgements

Daniele Catteddu
Daniele Catteddu
Chief Technology Officer, CSA

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Alain Pannetrat
Alain Pannetrat
Senior Researcher, STAR Product Manager, CSA

Alain Pannetrat

Senior Researcher, STAR Product Manager, CSA

This person does not have a biography listed with CSA.

John DiMaria
John DiMaria
Director of Operations Excellence, CSA

John DiMaria

Director of Operations Excellence, CSA

This person does not have a biography listed with CSA.

Max Pritikin
Max Pritikin
Principal Engineer, Cisco

Max Pritikin

Principal Engineer, Cisco

This person does not have a biography listed with CSA.

Jonathan Lewis Christopherson
Jonathan Lewis Christopherson

Jonathan Lewis Christopherson

This person does not have a biography listed with CSA.

Raj Krishnamurthy
Raj Krishnamurthy

Raj Krishnamurthy

Raj has experience engineering next generation security and compliance systems. He is a volunteer for the Continuous Audit Metrics working group.

Read more

Dili Origbo
Dili Origbo
Technology Audit & Project Assurance U.K.

Dili Origbo

Technology Audit & Project Assurance U.K.

This person does not have a biography listed with CSA.

Mosi Platt
Mosi Platt

Mosi Platt

This person does not have a biography listed with CSA.

Carlos Victoria
Carlos Victoria

Carlos Victoria

Carlos is a cybersecurity governance, risk, audit and compliance professional with over 12 years of experience. Carlos is CISSP, CISA, and CCSK certified. https://www.linkedin.com/in/carlosevictoria/

Read more

Bowen Close Headshot Missing
Bowen Close

Bowen Close

This person does not have a biography listed with CSA.

Michaela Iorga
Michaela Iorga
Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

Michaela Iorga

Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

This person does not have a biography listed with CSA.

Massimiliano Rak Headshot Missing
Massimiliano Rak

Massimiliano Rak

This person does not have a biography listed with CSA.

Willy Fabritius
Willy Fabritius

Willy Fabritius

This person does not have a biography listed with CSA.

Kevin Murphy Headshot Missing
Kevin Murphy

Kevin Murphy

This person does not have a biography listed with CSA.

Chris Pedigo
Chris Pedigo
Global Field CTO at Lacework

Chris Pedigo

Global Field CTO at Lacework

This person does not have a biography listed with CSA.

Anthony Scarfe Headshot Missing
Anthony Scarfe

Anthony Scarfe

This person does not have a biography listed with CSA.

James Condon Headshot Missing
James Condon

James Condon

This person does not have a biography listed with CSA.

Julien Mauvieux Headshot Missing
Julien Mauvieux

Julien Mauvieux

This person does not have a biography listed with CSA.

Carlos Victoria
Carlos Victoria

Carlos Victoria

Carlos is a cybersecurity governance, risk, audit and compliance professional with over 12 years of experience. Carlos is CISSP, CISA, and CCSK certified. https://www.linkedin.com/in/carlosevictoria/

Read more

Louis Seefried Headshot Missing
Louis Seefried

Louis Seefried

This person does not have a biography listed with CSA.

Jonathan Villa Headshot Missing
Jonathan Villa

Jonathan Villa

This person does not have a biography listed with CSA.

Christian Banse
Christian Banse
Head of Department "Service & Application Security"

Christian Banse

Head of Department "Service & Application Security"

This person does not have a biography listed with CSA.

Michael Bently Headshot Missing
Michael Bently

Michael Bently

This person does not have a biography listed with CSA.

Amanda King Headshot Missing
Amanda King

Amanda King

This person does not have a biography listed with CSA.

Tinsae Erkailo Headshot Missing
Tinsae Erkailo

Tinsae Erkailo

This person does not have a biography listed with CSA.

Alexandre Higuchi Headshot Missing
Alexandre Higuchi

Alexandre Higuchi

This person does not have a biography listed with CSA.

Judy Owen Headshot Missing
Judy Owen

Judy Owen

This person does not have a biography listed with CSA.

Brian Milbier Headshot Missing
Brian Milbier

Brian Milbier

This person does not have a biography listed with CSA.

Hafiz Sheikh Adnan Ahmed
Hafiz Sheikh Adnan Ahmed

Hafiz Sheikh Adnan Ahmed

Hafiz Sheikh Adnan Ahmed is a futurist and technology/Security leader with 17+ years track record in the areas of ICT Governance, Cyber Security & Resilience, Data Privacy & Protection, Risk Management, Corporate Excellence & Innovation, Digital Transformation, Strategic Transformation.

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training