ChaptersEventsBlog
Card testing is hitting revenue, not just fraud. What should payment companies do now? Register for this March 10 webinar →

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Using Zero Trust to Secure Enterprise Information in LLM Environments

Using Zero Trust to Secure Enterprise Information in LLM Environments

Release Date: 03/02/2026

The rapid adoption of Generative AI (GenAI) is transforming organizational workflows. However, it's also escalating risks related to data privacy, intellectual property protection, confidentiality, integrity, and compliance. Traditional perimeter-based security models are no longer sufficient...
AICMv1.0.3 Auditing Guidelines for Model Providers (MP)

AICMv1.0.3 Auditing Guidelines for Model Providers (MP)

Release Date: 02/23/2026

Model Provider (MP): Develops, trains, and distributes foundational or fine-tuned AI models that create the underlying AI capabilities others build upon, operating at the foundation layer of the AI stack.

About the Resource:
This resource contains assessment guidelines tailored to AICM control...
AICMv1.0.3 Auditing Guidelines for Cloud Service Providers (CSP)

AICMv1.0.3 Auditing Guidelines for Cloud Service Providers (CSP)

Release Date: 02/23/2026

Cloud Service Provider (CSP): Delivers the underlying cloud infrastructure that hosts and supports AI systems and workloads, and is responsible for designing, developing, implementing, and enforcing controls to mitigate security, privacy, and compliance risks in the cloud services they provide.

...