ChaptersEventsBlog
Register now for NHIcon 2026, a half-day online event, to learn what the future of AI security requires.

Working Group

Open API

Enterprises are moving towards an IT model in which most business applications are delivered as Software as a Service (SaaS) from Cloud Service Providers (CSPs). The emerging tools and products used to secure these business applications are categorized as Cloud Access Security Brokers (CASB) by leading analysts. The goal of the Cloud Security Open Application Programming Interface (Open API) Working Group is to provide guidance for Enterprises and CSPs on functionality and interoperability with CASBs. As well as to enable rapid adoption of cloud services in a secure manner, and to protect Personally Identifiable Information (PII) and sensitive data across multiple clouds.
Working Group
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

SSCF Implementation Guidelines

Open Until: 12/25/2025

The Cloud Security Alliance (CSA), in collaboration with the SaaS Security Capability Framework (SSCF) Working Group, is pl...

SSCF-CAIQ

Open Until: 12/25/2025

The Cloud Security Alliance (CSA), in collaboration with the SaaS Security Capability Framework (SSCF) Working Group, is pl...

DLP and DSPM inHealthcare: AI-EnhancedSecurity and Privacy

Open Until: 12/26/2025

Healthcare organizations face growing risks of data exposure as they adopt cloud platforms, AI tools, and connected technol...

AICM to AIUC-1 Mapping

Open Until: 12/28/2025

This document is an addendum to the 'AICM' that contains controls mapping between the CSA's AI Controls Matrix v1.0 and 'AI...