Cloud 101CircleEventsBlog
Register for CSA's AI Summit at RSAC on May 6!

Download Publication

Security Guidance for Critical Areas of Focus in Cloud Computing v4.0
Security Guidance for Critical Areas of Focus in Cloud Computing v4.0

Security Guidance for Critical Areas of Focus in Cloud Computing v4.0

Release Date: 07/26/2017

Working Group: Security Guidance

The rise of cloud computing as an ever-evolving technology brings with it a number of opportunities and challenges. Cloud is now becoming the back end for all forms of computing, including the ubiquitous Internet of Things. Cloud computing is the foundation for the information security industry. New ways of organizing compute, such as containerization and DevOps are inseparable from cloud and accelerating our revolution. With this document, we aim to provide both guidance and inspiration to support business goals while managing and mitigating the risks associated with the adoption of cloud computing technology. 

The Cloud Security Alliance promotes implementing best practices for providing security assurance within the domain of cloud computing and has delivered a practical, actionable roadmap for organizations seeking to adopt the cloud paradigm. The fourth version of the Security Guidance for Critical Areas of Focus in Cloud Computing is built on previous iterations of the security guidance, dedicated research, and public participation from the Cloud Security Alliance members, working groups, and the industry experts within our community. This version incorporates advances in cloud, security, and supporting technologies; reflects on real-world cloud security practices; integrates the latest Cloud Security Alliance research projects; and offers guidance for related technologies.
  • Cloud Computing Concepts and Architectures
  • Governance and Enterprise Risk Management
  • Legal Issues, Contracts and Electronic Discovery
  • Compliance and Audit Management
  • Information Governance
  • Management Plane and Business Continuity
  • Infrastructure Security
  • Virtualization and Containers
  • Incident Response
  • Application Security
  • Data Security and Encryption
  • Identity, Entitlement and Access Management
  • Security as a Service
  • Related Cloud Technologies
Download this Resource

Bookmark
Share
View translations
Related resources
Security Guidance v4.0 Info Sheet
Security Guidance v4.0 Info Sheet
Justify Your Investment in CCSK Training
Justify Your Investment in CCSK Training
FedRAMP Cloud Controls Matrix v3.0.1 Candidate Mapping
FedRAMP Cloud Controls Matrix v3.0.1 Candidate ...
CSA Community Spotlight: Propelling the Industry Forward with Larry Whiteside Jr.
CSA Community Spotlight: Propelling the Industry Forward with Larry...
Published: 03/12/2024
The Implications of AI in Cybersecurity - A Transformative Journey
The Implications of AI in Cybersecurity - A Transformative Journey
Published: 03/11/2024
New Year, New Security Awareness Training—How to Implement a Role-Based Training Program
New Year, New Security Awareness Training—How to Implement a Role-B...
Published: 02/08/2024
What is the Shared Responsibility Model in the Cloud?
What is the Shared Responsibility Model in the Cloud?
Published: 01/25/2024

Acknowledgements

Gunnar Peterson Headshot Missing
Gunnar Peterson

Gunnar Peterson

This person does not have a biography listed with CSA.

David Mortman Headshot Missing
David Mortman

David Mortman

This person does not have a biography listed with CSA.

Rich Mogull
Rich Mogull
CEO at Securosis

Rich Mogull

CEO at Securosis

Rich is the VP of Product for DisruptOPS and Analyst and CEO of Securosis. With twenty years of experience in information security, physical security, and risk management, Rich is one of the foremost experts on cloud security, having driven development of the Cloud Security Alliance’s V4 Guidance and the associated CCSK training curriculum. He is a prolific writer and fe...

Read more

John Yeoh
John Yeoh
Global Vice President of Research, CSA

John Yeoh

Global Vice President of Research, CSA

With over 15 years of experience in research and technology, John excels at executive-level leadership, relationship management, and strategy development. He is a published author, technologist, and researcher with areas of expertise in cybersecurity, cloud computing, information security, and next generation technology (IoT, Big Data, SecaaS, Quantum). John specializes in risk management, third party assessment, GRC, data protection, incid...

Read more

Luciano (J.R.) Santos
Luciano (J.R.) Santos
Chief Customer Officer, CSA

Luciano (J.R.) Santos

Chief Customer Officer, CSA

J.R. Santos serves as the Chief Customer Officer for the Cloud Security Alliance. In this role, J.R. serves as a CSA Member advocate, partnering with leaders across all business units to transform the member experience and ensure that members are the center of every business decision. J.R. leads the Experience Services organization that includes the CSA Membership and Sales team, who work collaboratively to promote a consistent experience f...

Read more

Hillary Baron
Hillary Baron
Senior Technical Director - Research, CSA

Hillary Baron

Senior Technical Director - Research, CSA

This person does not have a biography listed with CSA.

Jim Reavis
Jim Reavis
Co-founder and Chief Executive Officer, CSA

Jim Reavis

Co-founder and Chief Executive Officer, CSA

For many years, Jim Reavis has worked in the information security industry as an entrepreneur, writer, speaker, technologist and business strategist. Jim’s innovative thinking about emerging security trends have been published and presented widely throughout the industry and have influenced many. Jim is helping shape the future of information security and related technology industries as co-founder, CEO and driving force of the Cloud Secur...

Read more

Francoise Gilbert Headshot Missing
Francoise Gilbert

Francoise Gilbert

This person does not have a biography listed with CSA.

Adrian Lane Headshot Missing
Adrian Lane

Adrian Lane

Adrian Lane is a principle with research firm Securosis, and developer with cloud security firm DisruptOps. Adrian has over 25 years experience in data security and software development. Prior to joining Securosis, Adrian served as the CTO/VP at companies such as IPLocks, Touchpoint, CPMi and Transactor/Brodia. Presently Adrian focuses DevSecOps and Cloud security, performing cloud security audits, training and building solutions for secure...

Read more

James Arlen Headshot Missing
James Arlen

James Arlen

James Arlen is Aiven.io’s CISO bringing a mix of security and engineering background to DBaaS (database as a service). Over the past twenty plus years, James has been delivering information security solutions to Fortune 500, TSE 100, and major public-sector organizations.

James is best described as: “Infosec geek, hacker, social activist, author, speaker, and parent.” His areas of interest include organizational change, social enginee...

Read more

Victor Chin Headshot Missing
Victor Chin

Victor Chin

This person does not have a biography listed with CSA.

Evan Scoboria Headshot Missing
Evan Scoboria
Technology Director, CSA

Evan Scoboria

Technology Director, CSA

This person does not have a biography listed with CSA.

Mike Rothman Headshot Missing
Mike Rothman

Mike Rothman

Mike Rothman is the President of both cloud security automation company DisruptOps and information security research firm Securosis. His bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape and the evolution to the cloud. Mike is one of the most sought-after speakers and commentators in the security business and published the “Pragmatic CSO” in 200...

Read more

Frank Guanco
Frank Guanco
Research Program Manager, CSA

Frank Guanco

Research Program Manager, CSA

This person does not have a biography listed with CSA.

Daniele Catteddu
Daniele Catteddu
Chief Technology Officer, CSA

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Ryan Bergsma
Ryan Bergsma
Technology Director and Security Manager, CSA

Ryan Bergsma

Technology Director and Security Manager, CSA

This person does not have a biography listed with CSA.

Dan Moren Headshot Missing
Dan Moren

Dan Moren

This person does not have a biography listed with CSA.

John Moltz Headshot Missing
John Moltz

John Moltz

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.
Learn about CSA's Trusted Cloud Consultant Program

Interested in helping develop research with CSA?

Related Certificates & Training