CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
Capabilities-Based Risk Assessment (CBRA) for AI Systems Release Date: 11/12/2025 This publication introduces the Capabilities-Based Risk Assessment (CBRA), a structured, scalable approach to evaluating AI risk in enterprise environment... Request to download | |
A Practitioner’s Guide to Post-Quantum Cryptography Release Date: 11/10/2025 Cryptographically relevant quantum computers are projected to emerge as early as the 2030s. Traditional cryptographic systems like RSA, Diffie-Hellman, an... Request to download | |
Release Date: 07/09/2025 The AI Controls Matrix (AICM) is a first-of-its-kind vendor-agnostic framework for cloud-based AI systems. Organizations can use the AICM to develop, impl... Request to download | |
AICM Implementation & Auditing Guidelines (Frameworks) Release Date: 10/22/2025 The Cloud Security Alliance (CSA) AI Controls Matrix (AICM) Implementation and Auditing Guidelines Bundle provides comprehensive direction for both implem... Request to download | |
Beyond the Hype: A Benchmark Study of AI Agents in the SOC Release Date: 10/06/2025 CSA experts conducted a benchmarking study that evaluated how AI can transform alert investigations in Security Operations Centers (SOCs). Using simulated... Request to download | |
![]() | Release Date: 10/03/2025 The CSA Research Lifecycle graphic illustrates how research moves from proposal to approval, execution, peer review, publication, and dissemination. This res... Request to download |
SaaS Security Capability Framework (SSCF) Release Date: 09/23/2025 The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls pr... Request to download | |
Release Date: 08/27/2025 Machine learning (ML) is becoming increasingly central to business operations, making the security of ML pipelines essential rather than optional. Machine... Request to download | |
Analyzing Log Data with AI Models to Meet Zero Trust Principles Release Date: 09/15/2025 Logs are fundamental to Zero Trust. They capture critical details about user activity, device behavior, network traffic, and application access. However, ... Request to download | |
The State of Cloud and AI Security 2025 Release Date: 09/09/2025 This global survey report, developed in partnership with Tenable, examines how organizations are adapting security strategies for hybrid, multi-cloud, and... Request to download | |
![]() | Security Guidance for Critical Areas of Focus in Cloud Computing v5 Release Date: 07/15/2024 Cloud computing has firmly cemented its place as the foundation of the information security industry. The Cloud Security Alliance’s Security Guidance v5 i... Request to download |
Agentic AI Identity and Access Management: A New Approach Release Date: 08/18/2025 Agentic AI is pushing the boundaries of automation, autonomy, and decision-making at machine speed. But traditional identity and access management (IAM) p... Request to download | |
Secure Agentic System Design: A Trait-Based Approach Release Date: 07/30/2025 Thanks to powerful reasoning models, AI agents are making more nuanced decisions and interacting more effectively with their environments. At the same tim... Request to download | |
![]() | Release Date: 07/28/2025 The CCM Working Group is responsible for maintaining and evolving the Cloud Security Alliance’s foundational framework for cloud security assurance, the C... Request to download |
![]() | Healthcare Confidential Computing and the Trusted Execution Environment Release Date: 07/14/2025 Healthcare Delivery Organizations (HDOs) routinely process Protected Health Information (PHI), Personally Identifiable Information (PII), and financial da... Request to download |
![]() | CAVEaT Working Group Charter 2025 Release Date: 06/26/2025 The Cloud Security Alliance (CSA), in collaboration with the MITRE Corporation, established the Cloud Adversarial Vectors, Exploits, and Threats (CAVEaT™)... Request to download |
Navigating the Human Factor: Addressing Employee Resistance to AI Adoption Release Date: 06/25/2025 In boardrooms around the world, leaders are hailing artificial intelligence (AI) as a game-changer for efficiency and innovation. Many organizations have ... Request to download | |
Zero Trust Automation & Orchestration and Visibility & Analytics Overview Release Date: 06/04/2025 Visibility & Analytics and Automation & Orchestration are foundational, cross-cutting capabilities within the Zero Trust paradigm. They enable con... Request to download | |
Dynamic Process Landscape: A Strategic Guide to Successful AI Implementation Release Date: 06/02/2025 Artificial Intelligence (AI) adoption in business and manufacturing is failing at least twice as often as it succeeds. Companies are trying to integrate A... Request to download | |
Release Date: 05/28/2025 Agentic AI systems represent a significant leap forward for AI. Their ability to plan, reason, act, and adapt autonomously introduces new capabilities and... Request to download |




