Cloud 101
Circle
Events
Blog

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

CSA CCM v4.0 Addendum - ISMAP

CSA CCM v4.0 Addendum - ISMAP
Release Date: 10/04/2022

This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and Japan's Information System Security Management and Asse...

Request to download
Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix

Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix
Release Date: 08/08/2022

The download file also contains the following: Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud...

Request to download
CSA CCM v4.0 Addendum - CRI FS Profile v1.2

CSA CCM v4.0 Addendum - CRI FS Profile v1.2
Release Date: 07/15/2022

This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t...

Request to download
CCPA Addendum - PLA CoC v4.1

CCPA Addendum - PLA CoC v4.1
Release Date: 07/05/2022

This document serves as a mapping exercise between the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR) and the CS...

Request to download
CSA CCM v4.0 Addendum - UAE IA Regulation

CSA CCM v4.0 Addendum - UAE IA Regulation
Release Date: 07/05/2022

This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and the UAE Information Assurance (IA) Regulation. The docu...

Request to download
The Importance of STAR

The Importance of STAR
Release Date: 03/17/2022

Compliance requires a comprehensive review of services and processes related to cloud infrastructure and how it is managed during a data lifecycle. STAR f...

Request to download
CCMv4.0 Auditing Guidelines

CCMv4.0 Auditing Guidelines
Release Date: 12/08/2021

This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework align...

Request to download
STAR Level 1: Security Questionnaire (CAIQ v4) - Japanese Translation

STAR Level 1: Security Questionnaire (CAIQ v4) - Japanese Translation
Release Date: 11/02/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
CCM v4 - Turkish Translation

CCM v4 - Turkish Translation
Release Date: 10/26/2021

Bu yayının bu yerel dile çevrilmiş versiyonu, bölümlerin ve gönüllülerin çabalarıyla [orijinal kaynak](https://cloudsecurityalliance.org/artifacts/cloud-c...

Request to download
CCM and CAIQ v4 -Japanese Translations

CCM and CAIQ v4 -Japanese Translations
Release Date: 10/26/2021

This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t...

Request to download
CCM v4 - Spanish Translation

CCM v4 - Spanish Translation
Release Date: 10/26/2021

Esta versión traducida de esta publicación se produjo a partir de la fuente original del material gracias al esfuerzo de los capítulos y voluntarios, pero...

Request to download
CCM v4 - Chinese Translation

CCM v4 - Chinese Translation
Release Date: 10/26/2021

该中文版本的出版物是根据[原文](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4/)进行汉化,由CSA大中华区及其志愿者翻译完成,但翻译的内容不属于[CSA研究院生命周期](https://cloudsecuritya...

Request to download
The Continuous Audit Metrics Catalog

The Continuous Audit Metrics Catalog
Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo...

Request to download
CCM v4 - Hungarian Translation

CCM v4 - Hungarian Translation
Release Date: 10/19/2021

A kiadvány e honosított változata az eredeti forrásanyagból készült, helyi szervezetek és önkéntesek erőfeszítései révén, de a lefordított tartalom kívül ...

Request to download
The Evolution of STAR: Introducing Continuous Auditing

The Evolution of STAR: Introducing Continuous Auditing
Release Date: 09/14/2021

The CSA Continuous Auditing Certification (aka STAR Level 3) is the most rigorous assurance tier in the STAR program. Level 3 certified services providers...

Request to download
CCM v4.0 Implementation Guidelines

CCM v4.0 Implementation Guidelines
Release Date: 09/13/2021

This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM cont...

Request to download
Code of Practice for Implementing STAR Level 2

Code of Practice for Implementing STAR Level 2
Release Date: 06/23/2021

This Code of Practice shows how you can apply the CCM control set in your organization to reach STAR Level 2 third party certification/attestation and als...

Request to download
Cloud Controls Matrix and CAIQ v4

Cloud Controls Matrix and CAIQ v4
Release Date: 06/07/2021

The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s...

Request to download
STAR Level 1: Security Questionnaire (CAIQ v4)

STAR Level 1: Security Questionnaire (CAIQ v4)
Release Date: 06/07/2021

The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,...

Request to download
Guidelines for CPAs Providing CSA STAR Attestation v3

Guidelines for CPAs Providing CSA STAR Attestation v3
Release Date: 05/27/2021

This document provides guidance for CPAs in conducting a STAR Attestation. It includes relevant information including: professional requirements, competency ...

Request to download