CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

State of Cloud Security Risk, Compliance, and Misconfigurations

State of Cloud Security Risk, Compliance, and Misconfigurations
Release Date: 09/17/2021

Current state of cloud security programs, including top risks and usage of security tools • Cloud Security Posture Management (CSPM) challenges faced by o...

Request to download
Ransomware in the Healthcare Cloud

Ransomware in the Healthcare Cloud
Release Date: 09/15/2021

Ransomware is the fastest-growing malware threat today. Over the last few years, it has risen to epidemic proportions, quickly becoming a significant reve...

Request to download
How to Design a Secure Serverless Architecture

How to Design a Secure Serverless Architecture
Release Date: 09/14/2021

Like any solution, serverless computing brings with it a variety of cyber risks. This paper covers security for serverless applications, focusing on best pra...

Request to download
Recommendations for Adopting a Cloud-Native Key Management Service

Recommendations for Adopting a Cloud-Native Key Management Service
Release Date: 09/14/2021

The purpose of this document is to provide general guidance for choosing, planning, and deploying cloud-native Key Management Systems (KMS). The guidance ...

Request to download
CCM v4.0 Implementation Guidelines

CCM v4.0 Implementation Guidelines
Release Date: 09/13/2021

This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM cont...

Request to download
Microservices Architecture Pattern

Microservices Architecture Pattern
Release Date: 08/31/2021

This document serves to propose a repeatable approach to architecting, developing and deploying Microservices as a “MAP” (Microservices Architecture Patte...

Request to download
Top Threats to Cloud Computing: Egregious Eleven - Korean Translation

Top Threats to Cloud Computing: Egregious Eleven - Korean Translation
Release Date: 08/17/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Protecting the Privacy of Healthcare Data in the Cloud

Protecting the Privacy of Healthcare Data in the Cloud
Release Date: 08/10/2021

The Health Delivery Organization (HDO) needs to understand the relationship between privacy and security, particularly the differences. This understanding...

Request to download
Cloud Threat Modeling

Cloud Threat Modeling
Release Date: 07/29/2021

The purpose of this document is to enable, encourage cloud and security practitioners to apply threat modeling for cloud applications, services, and security...

Request to download
Cloud Key Management Working Group Charter

Cloud Key Management Working Group Charter
Release Date: 07/20/2021

Cloud services are becoming ubiquitous in all sizes, and customers encounter many obligations and opportunities for using key management systems with thos...

Request to download
The Use of Blockchain in Healthcare

The Use of Blockchain in Healthcare
Release Date: 07/15/2021

Healthcare is a large and heavily regulated industry. US and EU privacy and security laws require healthcare organizations to protect personal information...

Request to download
Healthcare Cybersecurity Playbook - An Evolving Landscape

Healthcare Cybersecurity Playbook - An Evolving Landscape
Release Date: 07/14/2021

One aspect of healthcare that has increased significantly during the COVID-19 pandemic is the use of telehealth. Telehealth is used for everything from re...

Request to download
SecaaS Working Group Charter 2021

SecaaS Working Group Charter 2021
Release Date: 07/09/2021

This charter lays out the scope, responsibilities, and roadmap for the Security as a Service (SecaaS) Working Group. The SecaaS Working Group has been cre...

Request to download
International Standardization Council Charter 2021

International Standardization Council Charter 2021
Release Date: 07/09/2021

This charter lays out the scope, responsibilities, and roadmap for the International Standardization Council (ISC). The ISC actively searches mechanisms o...

Request to download
Hyperledger Fabric 2.0 Architecture Security Report

Hyperledger Fabric 2.0 Architecture Security Report
Release Date: 06/28/2021

Blockchain technology is being rapidly adopted by enterprises to bring traceability and transparency to external business workflows. Considering that many...

Request to download
Hyperledger Fabric 2.0 Architecture Security Controls Checklist

Hyperledger Fabric 2.0 Architecture Security Controls Checklist
Release Date: 06/28/2021

Blockchain technology is being rapidly adopted by enterprises to bring traceability and transparency to external business workflows. Considering that many...

Request to download
Critical Controls Implementation for Salesforce

Critical Controls Implementation for Salesforce
Release Date: 06/15/2021

The Salesforce Platform can be a valuable tool for organizations to build and test applications. However, certain security changes are needed when an orga...

Request to download
Telehealth Risk Management

Telehealth Risk Management
Release Date: 06/10/2021

The recent COVID-19 pandemic has increased the demand for data and accelerated the use of telehealth. The Health Resources and Services Administration (HRSA)...

Request to download
Cloud Controls Matrix and CAIQ v4

Cloud Controls Matrix and CAIQ v4
Release Date: 06/07/2021

The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s...

Request to download
Cloud Incident Response Framework - Japanese Translation

Cloud Incident Response Framework - Japanese Translation
Release Date: 06/04/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download