CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
STAR Certification Guidance Document: Auditing the Cloud Controls Matrix (CCM) There are a number of control areas on the CCM that will each be awarded a management capability score on a scale of 1-15. This 2nd version release includes ... Request to download | |
Healthcare Big Data in the Cloud We are living in the information age. There are large and complex data sets generated daily. Data is generated by social media, emails, as well as numerous d... Request to download | |
Mobile Application Security Testing – Sum-Up & Landscape Overview Users place a good deal of trust in mobile app stores’ abilities to review, test, flag and block apps that exhibit undesirable behavior. However, even with t... Request to download | |
Hybrid Cloud and Its Associated Risks Cloud computing is flourishing. Hybrid clouds, especially, have been gaining more traction as cloud customers increasingly understand that using public cloud... Request to download | |
Enterprise Architecture Working Group Charter The Enterprise Architecture Working Group (EAWG) helps cloud customers and providers develop industry-recommended, secure and interoperable identity, access ... Request to download | |
Quantum-Safe Security Working Group Charter The focus of the Quantum‐Safe Security Working Group is on cryptographic methods that will remain safe after the widespread availability of the quantum compu... Request to download | |
The Six Pillars of DevSecOps: Automation Automation is a critical component of DevSecOps because it enables process efficiency, allowing developers, infrastructure, and information security teams to... Request to download | |
Evolution of CASB Survey Report The study on CASB, which queried more than 200 IT and security professionals from a variety of organization sizes and locations, examined the expectations, t... Request to download | |
Blockchain and Distributed Ledger Technology Working Group Charter This Cloud Security Alliance charter outlines the mission, scope and responsibilities, structure, etc. of the Blockchain and Distributed Ledger Technology... Request to download | |
Application Containers and Microservices Working Group Charter This Cloud Security Alliance charter outlines the mission, scope and responsibilities, structure, etc. of the Application Containers and Microservices Wor... Request to download | |
Telehealth Data in the Cloud In the wake of COVID-19 Health Delivery Organizations (HDOs) are rapidly increasing their utilization of telehealth capabilities like Remote Patient Monitori... Request to download | |
Financial Services Stakeholders Platform Working Group Charter Information security plays an integral role in the regulation and protection of customers in the financial industry. Exploring cloud computing and the underl... Request to download | |
SDP: The Most Advanced Zero Trust Architecture Today’s “Zero Trust” implementations are like putting up a wall with multiple doors and allowing people to come and pick a lock on the door. We are then just... Request to download | |
Privacy Level Agreement Code of Conduct Translation in 10 Languages Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Privacy Level Agreement Code of Conduct (PLA CoC) v3.1 in 10 la... Request to download | |
CCM Translation in 10 Languages Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Cloud Control Matrix (CCM) v3.0.1 in 10 languages in order to f... Request to download | |
CAIQ Translation in 10 Languages Cloud Security Alliance (CSA) in the context of an agreement with OneTrust has translated the Consensus Assessments Initiative Questionnaire (CAIQ) v3.0.1 in... Request to download | |
Cloud Industrial Internet of Things (IIoT) - Industrial Control Systems Security Glossary The Industrial Control Systems (ICS) Security Glossary is a reference document that brings together ICS and IT/OT related terms and definitions. Bringing t... Request to download | |
Cloud Incident Response Framework – A Quick Guide What this Quick Guide aims to do is to distill and give readers an overview of key contributions of the work currently undertaken in the CIR WG, towards a co... Request to download | |
Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted] Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an i... Request to download | |
Managing the Risk for Medical Devices Connected to the Cloud With the increased number of Internet of Things devices, Healthcare Delivery Organizations are experiencing a digital transformation bigger than anything in ... Request to download |