Circle
Events
Blog

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

Enterprise Architecture Reference Diagram

Enterprise Architecture Reference Diagram
Release Date: 05/18/2021

The CSA Enterprise Architecture (EA) is both a methodology and a set of tools. It is a framework, a comprehensive approach for the architecture of a secure c...

Request to download
Enterprise Architecture v2 to CCM v3.01 Mapping Guide

Enterprise Architecture v2 to CCM v3.01 Mapping Guide
Release Date: 05/18/2021

The Enterprise Architecture (EA) is the CSA’s standard cloud reference architecture while the Cloud Control Matrix (CCM) is the CSA’s standard control set. T...

Request to download
Enterprise Architecture to CCM v3.01 Reordered Mapping

Enterprise Architecture to CCM v3.01 Reordered Mapping
Release Date: 05/18/2021

The EA v2 to CCM v3.0.1 Mapping is a companion piece with the Enterprise Architecture Reference Guide v2. The peer review for both documents are intended to ...

Request to download
Disaster Recovery as a Service

Disaster Recovery as a Service
Release Date: 05/13/2021

Disaster Recovery as a Service (DRaaS) is a cloud computing service model that allows an organization to back up its data and IT infrastructure in a third...

Request to download
Top Cloud Priorities for CxOs

Top Cloud Priorities for CxOs
Release Date: 05/13/2021

The Top Cloud Priorities for CxOs was created to equip C-level executives with industry guidance to build pragmatic cloud security projects and strategies...

Request to download
CSA CxO Trust Working Group Charter

CSA CxO Trust Working Group Charter
Release Date: 05/11/2021

The CSA CxO Trust Working Group will conduct research consisting of best practices, metrics, surveys, C-level presentations, and other tools in support of...

Request to download
STAR Enabled Solution | CAIQ-Lite

STAR Enabled Solution | CAIQ-Lite
Release Date: 05/05/2021

CSA and Whistic identified the need for a lighter-weight assessment questionnaire in order to accommodate the shift to cloud procurement models, and to enabl...

Request to download
Cloud Incident Response Framework

Cloud Incident Response Framework
Release Date: 05/04/2021

This document aims to provide a Cloud Incident Response (CIR) framework that serves as a go-to guide for a CSC to effectively prepare for and manage cloud in...

Request to download
Security Guidelines for Providing and Consuming APIs

Security Guidelines for Providing and Consuming APIs
Release Date: 04/30/2021

In modern application workloads, organizations are often required to integrate their application with other parties such as Software-as-a-Service (SaaS) prov...

Request to download
Crypto-Asset Exchange Security Guidelines

Crypto-Asset Exchange Security Guidelines
Release Date: 04/13/2021

Thanks to the blockchain technology that makes them possible, crypto-assets are becoming massively successful. As with any successful industry, a multitud...

Request to download
Critical Controls Implementation for Oracle E-Business Suite

Critical Controls Implementation for Oracle E-Business Suite
Release Date: 04/05/2021

This paper will help an organization determine what security changes are needed when deploying Oracle E-Business Suite (EBS) in the Cloud. For clarity, this ...

Request to download
Cloud Penetration Testing Playbook: Korean Translation

Cloud Penetration Testing Playbook: Korean Translation
Release Date: 04/02/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Software Defined Perimeter Architecture Guide: Korean Translation

Software Defined Perimeter Architecture Guide: Korean Translation
Release Date: 04/01/2021

This localized version of this publication was produced from the original source (link to original) material through the efforts of chapters and volunteer...

Request to download
State of Cloud Security Concerns, Challenges, and Incidents

State of Cloud Security Concerns, Challenges, and Incidents
Release Date: 03/30/2021

The use of cloud services has continued to increase over the past decade. Particularly in the wake of the COVID-19 public health crisis, many enterprises’...

Request to download
Key Management when using Cloud Services - Japanese Translation

Key Management when using Cloud Services - Japanese Translation
Release Date: 03/01/2021

The purpose of this document is to provide guidance for using Key Management Systems (KMS) with cloud services, whether the key management system is native t...

Request to download
Confidence in Post Quantum Algorithms

Confidence in Post Quantum Algorithms
Release Date: 02/25/2021

NIST made the recent announcement of its Round 3 candidates for future post-quantum cryptography or quantum safe standards. As the world prepares to transiti...

Request to download
Cloud Incident Response Working Group Charter

Cloud Incident Response Working Group Charter
Release Date: 02/14/2021

In today’s connected era, a comprehensive incident response strategy is an integral aspect of any organization aiming to manage and lower their risk profile....

Request to download
Blockchains in the Quantum Era

Blockchains in the Quantum Era
Release Date: 02/05/2021

Digital Ledger Technologies (DLT) such as blockchain are being deployed as part of diverse applications that span multiple market segments. Application devel...

Request to download
CSA IoT Security Controls Framework v2

CSA IoT Security Controls Framework v2
Release Date: 01/28/2021

The IoT Security Controls Framework is relevant for enterprise IoT systems that incorporate multiple types of connected devices, cloud services, and networki...

Request to download
Guide to the Internet of Things (IoT) Security Controls Framework v2

Guide to the Internet of Things (IoT) Security Controls Framework v2
Release Date: 01/28/2021

The Guide to the IoT Security Controls Framework provides instructions for using the companion CSA IoT Security Controls Framework v2 spreadsheet. This guide...

Request to download