Circle
Events
Blog

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

CCMv4.0 Auditing Guidelines

CCMv4.0 Auditing Guidelines
Release Date: 12/08/2021

This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework align...

Request to download
Cloud Key Management System with External Origin Key

Cloud Key Management System with External Origin Key
Release Date: 12/02/2021

The purpose of this document is to provide general guidance for choosing, planning, and deploying cloud-native key management systems (KMS) where there is...

Request to download
Roles and Responsibilities of Third Party Security Services

Roles and Responsibilities of Third Party Security Services
Release Date: 11/30/2021

As we witness the broader adoption of cloud services, it is no surprise that third-party outsourced services are also on the rise. The security responsibi...

Request to download
Secure DevOps and Misconfigurations Survey Report

Secure DevOps and Misconfigurations Survey Report
Release Date: 11/18/2021

Secure DevOps, DevSecOps, and “shifting left” have become increasingly popular terms in cybersecurity. With the rapid increase both in volume and speed to...

Request to download
CSA Medical Device Incident Response Playbook

CSA Medical Device Incident Response Playbook
Release Date: 11/08/2021

This document presents a best-practices medical device incident response playbook that incorporates clinical aspects of medical device IR. As such, this g...

Request to download
Secure Connection Requirements of Hybrid Cloud

Secure Connection Requirements of Hybrid Cloud
Release Date: 11/05/2021

The National Institute of Standards and Technology (NIST) defines hybrid cloud infrastructure as a composition of distinct cloud infrastructures (private,...

Request to download
STAR Level 1: Security Questionnaire (CAIQ v4) - Japanese Translation

STAR Level 1: Security Questionnaire (CAIQ v4) - Japanese Translation
Release Date: 11/02/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Cloud Threat Modeling - Japanese Translation

Cloud Threat Modeling - Japanese Translation
Release Date: 11/01/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Towards a Zero Trust Architecture

Towards a Zero Trust Architecture
Release Date: 10/27/2021

Enterprise stakeholders must consider the challenges of increased real-time system complexity, the need for new cybersecurity policy and strong cultural s...

Request to download
CCM v4 - Turkish Translation

CCM v4 - Turkish Translation
Release Date: 10/26/2021

Bu yayının bu yerel dile çevrilmiş versiyonu, bölümlerin ve gönüllülerin çabalarıyla [orijinal kaynak](https://cloudsecurityalliance.org/artifacts/cloud-c...

Request to download
CCM and CAIQ v4 -Japanese Translations

CCM and CAIQ v4 -Japanese Translations
Release Date: 10/26/2021

This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t...

Request to download
CCM v4 - Spanish Translation

CCM v4 - Spanish Translation
Release Date: 10/26/2021

Esta versión traducida de esta publicación se produjo a partir de la fuente original del material gracias al esfuerzo de los capítulos y voluntarios, pero...

Request to download
CCM v4 - Chinese Translation

CCM v4 - Chinese Translation
Release Date: 10/26/2021

该中文版本的出版物是根据[原文](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4/)进行汉化,由CSA大中华区及其志愿者翻译完成,但翻译的内容不属于[CSA研究院生命周期](https://cloudsecuritya...

Request to download
Software-Defined Perimeter (SDP) and Zero Trust - Korean Translation

Software-Defined Perimeter (SDP) and Zero Trust - Korean Translation
Release Date: 10/25/2021

소프트웨어 정의 경계(Software-Defined Perimeter)로 구현한 제로 트러스트는 조직이 기존 네트워크 및 인프라 경계 중심의 네트워크 모델에서 지속적으로 등장하는 기존 공격 방법의 새로운 유형을 방어할 수 있도록 지원한다. SDP를 구현할 경우 점점 더 복잡해...

Request to download
The Continuous Audit Metrics Catalog

The Continuous Audit Metrics Catalog
Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo...

Request to download
CCM v4 - Hungarian Translation

CCM v4 - Hungarian Translation
Release Date: 10/19/2021

A kiadvány e honosított változata az eredeti forrásanyagból készült, helyi szervezetek és önkéntesek erőfeszítései révén, de a lefordított tartalom kívül ...

Request to download
Practical Preparations for the Post-Quantum World

Practical Preparations for the Post-Quantum World
Release Date: 10/19/2021

This document discusses the cybersecurity challenges and recommended steps to reduce likely new risks due to quantum information sciences. This paper was ...

Request to download
Information Technology Governance, Risk and Compliance in Healthcare

Information Technology Governance, Risk and Compliance in Healthcare
Release Date: 10/15/2021

Information Technology (IT) Governance, Risk, and Compliance (GRC), are three words that have a significant impact on organizations. While each term seems...

Request to download
Top 10 Blockchain Attacks, Vulnerabilities & Weaknesses

Top 10 Blockchain Attacks, Vulnerabilities & Weaknesses
Release Date: 09/27/2021

Cryptocurrencies and other blockchain virtual assets have been the target of the majority of Distributed Ledger Technology (DLT) attacks and a variety of ...

Request to download
State of Cloud Security Risk, Compliance, and Misconfigurations

State of Cloud Security Risk, Compliance, and Misconfigurations
Release Date: 09/17/2021

Cloud misconfigurations consistently are a top concern for organizations utilizing public cloud. Such errors lead to data breaches, allow the deletion or ...

Request to download