CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

Cloud Penetration Testing Playbook

Cloud Penetration Testing Playbook
Release Date: 07/12/2019

This work focuses on testing systems and services hosted in public cloud environments. This refers to customer-controlled or customer-managed systems and ser...

Request to download
CCM and CAIQ (Japanese Translations)

CCM and CAIQ (Japanese Translations)
Release Date: 07/10/2019

Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Cloud Control Matrix (CCM) v3.0.1 and CAIQ in Japanese

Request to download
Software Defined Perimeter (SDP): Awareness and Adoption Infographic

Software Defined Perimeter (SDP): Awareness and Adoption Infographic
Release Date: 07/01/2019

A majority of organizations recognize the need to change their approach to user access control. SDP is seeing early market adoption and awareness, with under...

Request to download
Guide to IoT Framework: Chinese Translation

Guide to IoT Framework: Chinese Translation
Release Date: 06/24/2019

The Guide to the IoT Security Controls Framework provides instructions for using the companion CSA IoT Security Controls Framework spreadsheet. This guide ex...

Request to download
Software Defined Perimeter for Infrastructure as a Service: Chinese Translation

Software Defined Perimeter for Infrastructure as a Service: Chinese Translation
Release Date: 06/24/2019

Obtain a clear sense of the security challenges facing enterprise users of IaaS, understand the problems that arise from combining native IaaS access control...

Request to download

IoT Controls Framework: Chinese Translation
Release Date: 06/24/2019

The Internet of Things (IoT) Security Controls Framework introduces the base-level security controls required to mitigate many of the risks associated with a...

Request to download
Cloud Octagon Model

Cloud Octagon Model
Release Date: 06/24/2019

In this document CSA provides an approach to assess risk in SaaS cloud computing. It takes into account the security challenges in a cloud computing environm...

Request to download

Software Defined Perimeter for Infrastructure as a Service: Japanese Translation
Release Date: 06/23/2019

Obtain a clear sense of the security challenges facing enterprise users of IaaS, understand the problems that arise from combining native IaaS access control...

Request to download
Mitigating the Quantum Threat with Hybrid Cryptography

Mitigating the Quantum Threat with Hybrid Cryptography
Release Date: 06/17/2019

Focus of this document is on four hybrid cryptographic schemes which provide both classical security of classical crypto and the quantum security of a quantu...

Request to download
Top 20 Critical Controls for Cloud ERP Customers

Top 20 Critical Controls for Cloud ERP Customers
Release Date: 06/10/2019

This document aims to be a guide for assessing and prioritizing the most critical controls that organizations should take into account when trying to secur...

Request to download

Cloud Penetration Testing Guidance
Release Date: 06/07/2019

This document aims to be a guide for conducting penetration testing on cloud services. The document outlines important aspects such as the scoping of cloud p...

Request to download
Cloud Security Alliance Code of Conduct for GDPR Compliance (Updated - May 2019)

Cloud Security Alliance Code of Conduct for GDPR Compliance (Updated - May 2019)
Release Date: 06/03/2019

The CSA Code of Conduct is designed to offer both a compliance tool for GDPR compliance and transparency guidelines regarding the level of data protection o...

Request to download
Preparing Enterprises for the Quantum Computing Cybersecurity Threats

Preparing Enterprises for the Quantum Computing Cybersecurity Threats
Release Date: 05/23/2019

Quantum computing, while expected to help make many advancements, will also break the existing asymmetric-key cryptosystems, thus endangering our security ...

Request to download
Cloud Security Complexity

Cloud Security Complexity
Release Date: 05/21/2019

CSA’s latest survey examines information security concerns in complex cloud environment. The survey of 700 IT and security professionals aims to analyze and ...

Request to download
Cloud OS Security Specification

Cloud OS Security Specification
Release Date: 05/07/2019

This document builds on the foundation provided by ISO/IEC 17788, ISO/IEC 19941, ISO/IEC 27000, NIST SP 500-299, and NIST SP 800-144 in the context of cloud...

Request to download
SDP Architecture Guide v2

SDP Architecture Guide v2
Release Date: 05/07/2019

Software Defined Perimeter (SDP) Architecture Guide is designed to leverage proven, standards-based components to stop network attacks against application in...

Request to download

Hybrid Cloud Security Services Charter
Release Date: 04/25/2019

This initiative aims to develop a security white paper specifying hybrid cloud security risks and countermeasures, helping users identify and reduce the risk...

Request to download

Cloud Key Management Charter
Release Date: 04/09/2019

The Cloud Key Management Working Group will facilitate the standards for seamless integration between CSPs and Key Broker vendor platforms. It will ensure th...

Request to download

SecaaS Working Group Charter
Release Date: 04/09/2019

In order to improve understanding, perception, and thus reputation, Security as a Service requires a clear definition and direction to ensure it is understo...

Request to download
Lessons From the Cloud

Lessons From the Cloud
Release Date: 03/05/2019

Lessons from the Cloud - David Cass, Chief Information Security Officer Cloud and SaaS Operations & Global Partner Cloud Security Services, IBM

Request to download