CSAIChaptersEventsBlog
Join the Tenable Exposure Management Conference in Boston from May 19–21 to explore modern exposure management and AI risk. Register for EXPOSURE 2026 →

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Autonomous but Not Controlled

Autonomous but Not Controlled

Release Date: 04/20/2026

AI agents are rapidly becoming embedded across enterprise environments. They span cloud platforms, SaaS applications, internal systems, and LLM-driven workflows. As these systems take on more autonomous roles, organizations are shifting from experimentation to governance. They're redefining how...
Enterprise AI Security Starts with AI Agents

Enterprise AI Security Starts with AI Agents

Release Date: 04/15/2026

This survey report explores the rise of AI agents in enterprises, as well as the reality of autonomous AI risks. Commissioned by Zenity, the report reveals that autonomous systems are already operating at scale. They often exceed intended permissions and act outside defined boundaries as part of...
SaaS Security Capability Framework (SSCF)

SaaS Security Capability Framework (SSCF)

Release Date: 04/08/2026

Now includes a security questionnaire, implementation guidelines, and machine-readable versions!

The SaaS Security Capability Framework (SSCF) defines configurable, consumable, and customer-facing security controls provided by SaaS vendors to their customers. 

The SSCF represents a...