Cloud 101
Circle
Events
Blog

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)

Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
Release Date: 08/08/2022

In the following illustrative type 2 SOC 2 report, the service auditor is reporting on: The fairness of the presentation of the service organization’s de...

Request to download
Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix

Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix
Release Date: 08/08/2022

The download file also contains the following: Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud...

Request to download
IoT Controls Matrix v3 - Japanese Translation

IoT Controls Matrix v3 - Japanese Translation
Release Date: 07/21/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Guide to the IoT Controls Matrix v3 - Japanese Translation

Guide to the IoT Controls Matrix v3 - Japanese Translation
Release Date: 07/21/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Third-Party Vendor Risk Management in Healthcare

Third-Party Vendor Risk Management in Healthcare
Release Date: 07/19/2022

The increased use of third-party vendors for applications and data processing services is a business model that is likely to continue, especially as HDOs ...

Request to download
CSA CCM v4.0 Addendum - CRI FS Profile v1.2

CSA CCM v4.0 Addendum - CRI FS Profile v1.2
Release Date: 07/15/2022

This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t...

Request to download
Critical Controls Implementation for Oracle Fusion Applications

Critical Controls Implementation for Oracle Fusion Applications
Release Date: 07/12/2022

Framed within the context of the Cloud Security Alliance (CSA)’s ERP Twenty Controls, this document presents the essential and optional security features ...

Request to download
Sensitive Data in the Cloud

Sensitive Data in the Cloud
Release Date: 07/12/2022

Anjuna commissioned CSA to develop a survey to better understand the industry’s knowledge, attitudes, and opinions regarding sensitive data in the cloud. ...

Request to download
State of ICS Security in the Age of Cloud

State of ICS Security in the Age of Cloud
Release Date: 07/05/2022

The goal of this document hopes to create awareness and share insights on the benefits of leveraging Cloud Computing for ICS/OT. It also attempts to stimu...

Request to download
CCPA Addendum - PLA CoC v4.1

CCPA Addendum - PLA CoC v4.1
Release Date: 07/05/2022

This document serves as a mapping exercise between the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR) and the CS...

Request to download
CSA CCM v4.0 Addendum - UAE IA Regulation

CSA CCM v4.0 Addendum - UAE IA Regulation
Release Date: 07/05/2022

This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and the UAE Information Assurance (IA) Regulation. The docu...

Request to download
Measuring Risk and Risk Governance

Measuring Risk and Risk Governance
Release Date: 06/21/2022

Adapting to the cloud presents a new challenge to enterprises. The shared responsibility model, used to distinguish responsibilities between cloud provide...

Request to download
Secure Connection Requirements of Hybrid Cloud - Japanese Translation

Secure Connection Requirements of Hybrid Cloud - Japanese Translation
Release Date: 06/14/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
C-Level Guidance to Securing Serverless Architectures - Japanese Translation

C-Level Guidance to Securing Serverless Architectures - Japanese Translation
Release Date: 06/08/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
The Continuous Audit Metrics Catalog: Towards a Machine-Readable Representation

The Continuous Audit Metrics Catalog: Towards a Machine-Readable Representation
Release Date: 06/07/2022

In October 2021, the Cloud Security Alliance released the first version of the Continuous Audit Metrics catalog which provides a standard reference for th...

Request to download
Top Threats to Cloud Computing Pandemic Eleven

Top Threats to Cloud Computing Pandemic Eleven
Release Date: 06/06/2022

The Top Threats reports have traditionally aimed to raise awareness of threats, risks, and vulnerabilities in the cloud. Such issues are often the result ...

Request to download
CISO Perspectives and Progress in Deploying Zero Trust

CISO Perspectives and Progress in Deploying Zero Trust
Release Date: 06/03/2022

Some of the areas covered in this survey include where Zero Trust falls as a priority in the organization, the percentage of those who have completed rela...

Request to download
Top Threats to Cloud Computing: Egregious Eleven Deep Dive - Arabic Translation

Top Threats to Cloud Computing: Egregious Eleven Deep Dive - Arabic Translation
Release Date: 05/27/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Best Practices for Smart Contract Security Hyperledger Fabric

Best Practices for Smart Contract Security Hyperledger Fabric
Release Date: 05/18/2022

The goal is to establish best practices for using smart contract specifically in Hyperledger Fabric 2.0 environment. This document serves as a guide for S...

Request to download
Serverless Computing Working Group Charter

Serverless Computing Working Group Charter
Release Date: 05/17/2022

Serverless working group charter document.  The Serverless WG seeks to develop best practices to help organizations that want to run their business with a...

Request to download