CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | Telehealth Data in the Cloud In the wake of COVID-19 Health Delivery Organizations (HDOs) are rapidly increasing their utilization of telehealth capabilities like Remote Patient Monitori... Request to download |
![]() | Financial Services Stakeholders Platform Working Group Charter Information security plays an integral role in the regulation and protection of customers in the financial industry. Exploring cloud computing and the underl... Request to download |
![]() | SDP: The Most Advanced Zero Trust Architecture Today’s “Zero Trust” implementations are like putting up a wall with multiple doors and allowing people to come and pick a lock on the door. We are then just... Request to download |
![]() | Software-Defined Perimeter (SDP) and Zero Trust A Zero Trust implementation using Software-Defined Perimeter enables organizations to defend new variations of old attack methods that are constantly surfaci... Request to download |
![]() | Privacy Level Agreement Code of Conduct Translation in 10 Languages Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Privacy Level Agreement Code of Conduct (PLA CoC) v3.1 in 10 la... Request to download |
![]() | CCM Translation in 10 Languages Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Cloud Control Matrix (CCM) v3.0.1 in 10 languages in order to f... Request to download |
![]() | CAIQ Translation in 10 Languages Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Consensus Assessments Initiative Questionnaire (CAIQ) v3.0.1 in... Request to download |
![]() | Cloud Industrial Internet of Things (IIoT) - Industrial Control Systems Security Glossary The Industrial Control Systems (ICS) Security Glossary is a reference document that brings together ICS and IT/OT related terms and definitions. Bringing t... Request to download |
![]() | Cloud Incident Response Framework – A Quick Guide What this Quick Guide aims to do is to distill and give readers an overview of key contributions of the work currently undertaken in the CIR WG, towards a co... Request to download |
![]() | CAIQ-Lite CSA and Whistic identified the need for a lighter-weight assessment questionnaire in order to accommodate the shift to cloud procurement models, and to enabl... Request to download |
![]() | Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an ... Request to download |
![]() | Managing the Risk for Medical Devices Connected to the Cloud With the increased number of Internet of Things devices, Healthcare Delivery Organizations are experiencing a digital transformation bigger than anything in ... Request to download |
![]() | PLA Code of Practice Template Annex 1 (Updated - March 2020) CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f... Request to download |
![]() | Software-Defined Perimeter ARCHITECTURE GUIDE - Japanese Translation Software Defined Perimeter (SDP) Architecture Guide is designed to leverage proven, standards-based components to stop network attacks against application in... Request to download |
![]() | Open Certification Framework Working Group Charter The CSA Open Certification Framework (OCF) is an industry initiative to allow global, trusted independent evaluation of cloud providers. It is a program for ... Request to download |
![]() | Best Practices for Implementing a Secure Application Container Architecture - Japanese Translation Application containers and a microservices architecture are being used to design, develop and deploy applications leveraging agile software development appro... Request to download |
![]() | Best Practices in Implementing a Secure Microservices Architecture Application containers and a microservices architecture are being used to design, develop, and deploy applications leveraging agile software development appr... Request to download |
![]() | The Six Pillars of DevSecOps: Collective Responsibility The DevSecOps Working Group identified and defined six focus areas critical to integrating DevSecOps into an organization, in accordance with the six pillars... Request to download |
![]() | Cloud Usage in the Financial Services Sector This survey was created and completed by members of the the Financial Services Stakeholders Platform, a CSA working group whose main objective is to identify... Request to download |
![]() | CSA CCM v3.0.1 Addendum - Cloud OS Security Specifications This document is an addendum to the CCM V3.0.1 and contains a controls mapping and gap analysis between the CSA CCM and CSA's research artifact "Cloud OS Sec... Request to download |