Circle
Events
Blog

Download Publication

The Continuous Audit Metrics Catalog
The Continuous Audit Metrics Catalog
Who it's for:
Compliance managers

The Continuous Audit Metrics Catalog

Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evolving with continuous integration and deployment. Therefore, a certification obtained once a year after a third-party audit is not asufficient source of assurance anymore. It’s time to move from “point-in-time” assurance to continuous assurance. This change requires moving away from manual audits and instead building automated tools that continuously assess the effectiveness of an information system. In other words, it’s time to move to the world of security metrics.

There is no standard reference for the continuous auditing of cloud services that supports security metrics in a way that is comparable to what the CSA CCM or ISO/IEC 27002 does for security controls. To address this gap, CSA launched the Continuous Audit Metrics Working Group in early 2020 to build the first catalog of security metrics for the cloud. We have released the first version of this catalog that contains an initial set of 34 security metrics, each mapped to the CCM v4. These metrics aim to support internal CSP governance, risk, and compliance (GRC) activities and provide a helpful baseline for service-level agreement transparency. 

Topics covered: 
  • Explanation of security metrics
  • How to measure the effectiveness of an information system
  • How to enable continuous auditing
  • Catalog listing the 34 metrics

Included in this zip file:
  • Continuous Audit Metrics Catalog
  • Code of Practice for Implementing and Maintaining Key Metrics

Help CSA better understand how we can support the cloud community. Answer a couple of questions to download this resource.

In my current job I work in:

CSA is a community driven organization. We would like to send you updates about our ongoing initiatives and opportunities to participate.

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).

You’ve made safer cloud computing possible.

Download
Provide feedback on this form

CSA is a community driven organization. We would like to send you updates about our ongoing initiatives and opportunities to participate.

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).

Download
Provide feedback on this form

Acknowledgements

Daniele Catteddu Headshot
Daniele Catteddu
Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Alain Pannetrat Headshot
Alain Pannetrat
Alain Pannetrat

Senior Researcher & Product Manager, CSA

This person does not have a biography listed with CSA.

John DiMaria Headshot
John DiMaria
John DiMaria

Assurance Investigatory Fellow, CSA

This person does not have a biography listed with CSA.

Max Pritikin Headshot
Max Pritikin
Max Pritikin

Principal Engineer, Cisco

This person does not have a biography listed with CSA.

Jonathan Lewis Christopherson Headshot
Jonathan Lewis Christopherson
Jonathan Lewis Christopherson

This person does not have a biography listed with CSA.

Raj Krishnamurthy Headshot
Raj Krishnamurthy
Raj Krishnamurthy

Raj has experience engineering next generation security and compliance systems. He is a volunteer for the Continuous Audit Metrics working group.

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.