CSA Research Artifacts

Whitepapers, Reports and Other Resources

Home
Research Artifacts

Browse Research Artifacts

Critical Controls Implementation for SAP

Critical Controls Implementation for SAP
Release Date: 01/06/2020

The Critical Controls Implementation for SAP is the first in a series of implementation documents that the CSA ERP Security Working Group aims to develop. Th...

Request to download

CSA CCM v3.0.1 Addendum to the Reserve Bank of India (RBI)’s Gopala Krishna Committee (GKC) report
Release Date: 11/27/2019

This document contains a mapping and gap analysis between the cloud security requirements of CCM V3.0.1 and those of the Reserve Bank of India (RBI)’s Gopala...

Request to download

Beyond the General Data Protection Regulation (GDPR)
Release Date: 11/19/2019

Data residency insights from around the world. This study reveals the top data protection concerns and strategies of more than 800 senior business profession...

Request to download

Code of Conduct (CoC): Statement of Adherence 3rd Party Certification
Release Date: 11/19/2019

CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f...

Request to download

PLA Code of Conduct (CoC): Statement of Adherence Self-Assessment
Release Date: 11/19/2019

CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f...

Request to download

Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment
Release Date: 11/19/2019

The CSA CoC for GDPR Compliance Self-Assessment is the voluntary publication of a CSP’s self-assessment results based on the requirements specified in the PL...

Request to download
Guideline on Effectively Managing Security Service in the Cloud - Japanese Translation

Guideline on Effectively Managing Security Service in the Cloud - Japanese Translation
Release Date: 11/18/2019

Request to download
Top Threats to Cloud Computing: Egregious Eleven - Japanese Translation

Top Threats to Cloud Computing: Egregious Eleven - Japanese Translation
Release Date: 11/18/2019

Request to download

Consensus Assessment Initiative Questionnaire (CAIQ) v3.1
Release Date: 11/15/2019

Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers a...

Request to download
Requirements for Bodies Providing STAR Certification

Requirements for Bodies Providing STAR Certification
Release Date: 10/28/2019

This document outlines how to conduct a STAR certification assessments to the Cloud Controls Matrix (CCM) as part of an ISO 27001 assessment.

Request to download
Software-Defined Perimeter as a DDoS Prevention Mechanism

Software-Defined Perimeter as a DDoS Prevention Mechanism
Release Date: 10/27/2019

The primary goal of this document is to increase the awareness and understanding of SDP as a tool to prevent DDoS attacks by demonstrating its efficiency and...

Request to download
Guidelines for CPAs Providing CSA STAR Attestation v2

Guidelines for CPAs Providing CSA STAR Attestation v2
Release Date: 09/20/2019

Request to download

Mapping of 'The Guidelines' Security Recommendations to CCM
Release Date: 09/05/2019

This document contains the additional controls that serves to bridge the gap between CCM V3.0.1 and the controls within 'Guideline on Effectively Managing Se...

Request to download
Gap Analysis Report on Mapping CSA’s Cloud Controls Matrix to ‘Guideline on Effectively Managing Security Service in the Cloud’

Gap Analysis Report on Mapping CSA’s Cloud Controls Matrix to ‘Guideline on Effectively Managing Security Service in the Cloud’
Release Date: 09/05/2019

The report summarizes the mapping of CCM v3.0.1 to 'Guideline on Effectively Managing Security Services in the Cloud' and provides gap analysis on the results.

Request to download
Six Pillars of DevSecOps

Six Pillars of DevSecOps
Release Date: 08/07/2019

In our current state of cyber security, there has been a large growth of application flaws that bypass the continuing addition of security frameworks to ensu...

Request to download
Top Threats to Cloud Computing: Egregious Eleven

Top Threats to Cloud Computing: Egregious Eleven
Release Date: 08/06/2019

The report provides organizations with an up-to-date, expert-informed understanding of cloud security concerns in order to make educated risk-management deci...

Request to download
Cloud Controls Matrix v3.0.1

Cloud Controls Matrix v3.0.1
Release Date: 08/03/2019

Description: The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regula...

Request to download

CSA CCM v3.0.1 Addendum - NIST 800-53 Rev 4 Moderate
Release Date: 08/03/2019

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the NIST 800-53 R4 Moderate Baseline. The document aims ...

Request to download

CCM v3.0.1 Addendum - FedRAMP Moderate
Release Date: 08/03/2019

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the FedRAMP R4 Moderate Baseline. The document aims t...

Request to download

CCM v3.0.1-080319
Release Date: 08/03/2019

The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations...

Request to download