CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
The Continuous Audit Metrics Catalog Release Date: 01/28/2026 Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo... Request to download | |
Cloud Controls Matrix and CAIQ v4.1 Release Date: 01/27/2026 The Cloud Controls Matrix (CCM) is a cybersecurity control framework made up of 207 controls across 17 security domains. The CCM maps to industry best pra... Request to download | |
Release Date: 01/27/2026 The Cloud Security Alliance, in collaboration with the CCM Working Group, proudly presents the CCM-Lite and CAIQ-Lite File Bundle. These tools offer a str... Request to download | |
The State of Non-Human Identity and AI Security Release Date: 01/26/2026 Based on a comprehensive survey of IT and security professionals, this report explores how rapid AI adoption amplifies long-standing Identity and Access M... Request to download | |
![]() | Release Date: 01/26/2026 This charter establishes the mission, scope and responsibilities, goals and objectives, and operational procedures for the SCC WG. The goal of the SCC WG is... Request to download |
The State of AI Security and Governance Release Date: 12/17/2025 Organizations are rapidly moving from AI experimentation to operational deployment, yet their abilities to secure this transformation vary widely. Commiss... Request to download | |
Release Date: 12/10/2025 This infographic offers a clear understanding of how cloud service providers and customers share responsibilities for cloud key management.Cloud key manag... Request to download | |
Key Management in Cloud Services This document is an updated edition of the original “Key Management in Cloud Services” paper, first published in 2020. To ensure the accuracy, completeness, ... Request to download | |
Data Security within AI Environments Release Date: 12/03/2025 As organizations adopt large language models, multi-modal AI systems, and agentic AI, traditional safeguards must evolve. This publication provides a comp... Request to download | |
Managing Privileged Access in a Cloud-First World Release Date: 11/24/2025 Organizations are shifting to cloud-first architectures, distributed workforces, and identity-centric security models. This means that Privileged Access M... Request to download | |
Release Date: 11/19/2025 The AI Controls Matrix (AICM) provides a foundational security and governance framework for AI service providers and customers. It helps them securely imp... Request to download | |
Release Date: 11/17/2025 This publication enables and encourages effective threat modeling for cloud applications, services, and security decisions. It offers practical guidance to h... Request to download | |
Capabilities-Based Risk Assessment (CBRA) for AI Systems Release Date: 11/12/2025 This publication introduces the Capabilities-Based Risk Assessment (CBRA), a structured, scalable approach to evaluating AI risk in enterprise environment... Request to download | |
A Practitioner’s Guide to Post-Quantum Cryptography Release Date: 11/10/2025 Cryptographically relevant quantum computers are projected to emerge as early as the 2030s. Traditional cryptographic systems like RSA, Diffie-Hellman, an... Request to download | |
Release Date: 07/09/2025 The AI Controls Matrix (AICM) is a first-of-its-kind vendor-agnostic framework for cloud-based AI systems. Organizations can use the AICM to develop, impl... Request to download | |
AICM Implementation & Auditing Guidelines (Frameworks) Release Date: 10/22/2025 The Cloud Security Alliance (CSA) AI Controls Matrix (AICM) Implementation and Auditing Guidelines Bundle provides comprehensive direction for both implem... Request to download | |
Beyond the Hype: A Benchmark Study of AI Agents in the SOC Release Date: 10/06/2025 CSA experts conducted a benchmarking study that evaluated how AI can transform alert investigations in Security Operations Centers (SOCs). Using simulated... Request to download | |
![]() | Release Date: 10/03/2025 The CSA Research Lifecycle graphic illustrates how research moves from proposal to approval, execution, peer review, publication, and dissemination. This res... Request to download |
SaaS Security Capability Framework (SSCF) Release Date: 09/23/2025 The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls pr... Request to download | |
Release Date: 08/27/2025 Machine learning (ML) is becoming increasingly central to business operations, making the security of ML pipelines essential rather than optional. Machine... Request to download |
