Register for CSA’s SECtember conference and trainings today




Circle
Events
Blog

Download Publication

The Continuous Audit Metrics Catalog
The Continuous Audit Metrics Catalog
Who it's for:
Compliance managers

The Continuous Audit Metrics Catalog

Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evolving with continuous integration and deployment. Therefore, a certification obtained once a year after a third-party audit is not a
sufficient source of assurance anymore. It’s time to move from “point-in-time” assurance to continuous assurance. This change requires moving away from manual audits and instead building automated tools that continuously assess the effectiveness of an information system. In other words, it’s time to move to the world of security metrics.

There is no standard reference for the continuous auditing of cloud services that supports security metrics in a way that is comparable to what the CSA CCM or ISO/IEC 27002 does for security controls. To address this gap, CSA launched the Continuous Audit Metrics Working Group in early 2020 to build the first catalog of security metrics for the cloud. We have released the first version of this catalog that contains an initial set of 34 security metrics, each mapped to the CCM v4. These metrics aim to support internal CSP governance, risk, and compliance (GRC) activities and provide a helpful baseline for service-level agreement transparency. 

Topics covered: 
  • Explanation of security metrics
  • How to measure the effectiveness of an information system
  • How to enable continuous auditing
  • Catalog listing the 34 metrics

Included in this zip file:
  • Continuous Audit Metrics Catalog
  • Code of Practice for Implementing and Maintaining Key Metrics

Download this Resource

LoginCreate Account

Prefer to access this resource without an account? Download it now.

Acknowledgements

Daniele Catteddu Headshot
Daniele Catteddu
Chief Technology Officer, CSA

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Alain Pannetrat Headshot
Alain Pannetrat
Senior Researcher, STAR Product Manager, CSA

Alain Pannetrat

Senior Researcher, STAR Product Manager, CSA

This person does not have a biography listed with CSA.

John DiMaria Headshot
John DiMaria
Assurance Investigatory Fellow, CSA

John DiMaria

Assurance Investigatory Fellow, CSA

This person does not have a biography listed with CSA.

Max Pritikin Headshot
Max Pritikin
Principal Engineer, Cisco

Max Pritikin

Principal Engineer, Cisco

This person does not have a biography listed with CSA.

Jonathan Lewis Christopherson Headshot
Jonathan Lewis Christopherson

Jonathan Lewis Christopherson

This person does not have a biography listed with CSA.

Raj Krishnamurthy Headshot
Raj Krishnamurthy

Raj Krishnamurthy

Raj has experience engineering next generation security and compliance systems. He is a volunteer for the Continuous Audit Metrics working group.

Read more

Dili Origbo Headshot
Dili Origbo
Technology Audit & Project Assurance U.K.

Dili Origbo

Technology Audit & Project Assurance U.K.

This person does not have a biography listed with CSA.

Mosi Platt Headshot
Mosi Platt

Mosi Platt

This person does not have a biography listed with CSA.

Carlos Victoria Headshot
Carlos Victoria

Carlos Victoria

Carlos is a cybersecurity governance, risk, audit and compliance professional with over 12 years of experience. Carlos is CISSP, CISA, and CCSK certified. https://www.linkedin.com/in/carlosevictoria/

Read more

Bowen Close Headshot Missing
Bowen Close

Bowen Close

This person does not have a biography listed with CSA.

Michaela Iorga Headshot
Michaela Iorga
Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

Michaela Iorga

Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

This person does not have a biography listed with CSA.

Massimiliano Rak Headshot Missing
Massimiliano Rak

Massimiliano Rak

This person does not have a biography listed with CSA.

Willy Fabritius Headshot Missing
Willy Fabritius

Willy Fabritius

This person does not have a biography listed with CSA.

Kevin Murphy Headshot Missing
Kevin Murphy

Kevin Murphy

This person does not have a biography listed with CSA.

Chris Pedigo Headshot
Chris Pedigo
Global Field CTO at Lacework

Chris Pedigo

Global Field CTO at Lacework

This person does not have a biography listed with CSA.

Anthony Scarfe Headshot Missing
Anthony Scarfe

Anthony Scarfe

This person does not have a biography listed with CSA.

James Condon Headshot Missing
James Condon

James Condon

This person does not have a biography listed with CSA.

Julien Mauvieux Headshot Missing
Julien Mauvieux

Julien Mauvieux

This person does not have a biography listed with CSA.

Carlos Victoria Headshot
Carlos Victoria

Carlos Victoria

Carlos is a cybersecurity governance, risk, audit and compliance professional with over 12 years of experience. Carlos is CISSP, CISA, and CCSK certified. https://www.linkedin.com/in/carlosevictoria/

Read more

Louis Seefried Headshot Missing
Louis Seefried

Louis Seefried

This person does not have a biography listed with CSA.

Jonathan Villa Headshot Missing
Jonathan Villa

Jonathan Villa

This person does not have a biography listed with CSA.

Christian Banse Headshot
Christian Banse
Head of Department "Service & Application Security"

Christian Banse

Head of Department "Service & Application Security"

This person does not have a biography listed with CSA.

Michael Bently Headshot Missing
Michael Bently

Michael Bently

This person does not have a biography listed with CSA.

Amanda King Headshot Missing
Amanda King

Amanda King

This person does not have a biography listed with CSA.

Tinsae Erkailo Headshot Missing
Tinsae Erkailo

Tinsae Erkailo

This person does not have a biography listed with CSA.

Alexandre Higuchi Headshot Missing
Alexandre Higuchi

Alexandre Higuchi

This person does not have a biography listed with CSA.

Judy Owen Headshot Missing
Judy Owen

Judy Owen

This person does not have a biography listed with CSA.

Brian Milbier Headshot Missing
Brian Milbier

Brian Milbier

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.