Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

Six Pillars of DevSecOps

Six Pillars of DevSecOps
Release Date: 08/07/2019

In our current state of cyber security, there has been a large growth of application flaws that bypass the continuing addition of security frameworks to ensu...

Request to download
Top Threats to Cloud Computing: Egregious Eleven

Top Threats to Cloud Computing: Egregious Eleven
Release Date: 08/06/2019

The report provides organizations with an up-to-date, expert-informed understanding of cloud security concerns in order to make educated risk-management deci...

Request to download
Cloud Controls Matrix v3.0.1

Cloud Controls Matrix v3.0.1
Release Date: 08/03/2019

The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations...

Request to download
CCM v3.0.1 Addendum - FedRAMP Moderate

CCM v3.0.1 Addendum - FedRAMP Moderate
Release Date: 08/03/2019

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the FedRAMP R4 Moderate Baseline. The document aims to ...

Request to download
CSA CCM v3.0.1 Addendum - NIST 800-53 Rev 4 Moderate

CSA CCM v3.0.1 Addendum - NIST 800-53 Rev 4 Moderate
Release Date: 08/03/2019

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the NIST 800-53 R4 Moderate Baseline. The document aims ...

Request to download
CSA CCM v3.0.1 Addendum - AICPA TSC 2017

CSA CCM v3.0.1 Addendum - AICPA TSC 2017
Release Date: 08/03/2019

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the AICPA TSC 2017. The document aims to help AICPA TSC ...

Request to download
CCM v3.0.1-080319

CCM v3.0.1-080319
Release Date: 08/03/2019

The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations...

Request to download
Information Security Management through Reflexive Security

Information Security Management through Reflexive Security
Release Date: 08/01/2019

This document defines “Reflexive Security” as a new security management approach that is built upon the interrelationships between security, development and ...

Request to download
Documentation of Relevant Distributed Ledger Technology and Blockchain Use Cases v2

Documentation of Relevant Distributed Ledger Technology and Blockchain Use Cases v2
Release Date: 07/31/2019

Thanks to the rise in popularity of Bitcoin cryptocurrency, the innovative technologies of Blockchain and other systems of distributed ledger technology (DLT...

Request to download
Best Practices for Implementing a Secure Application Container Architecture

Best Practices for Implementing a Secure Application Container Architecture
Release Date: 07/26/2019

Application containers and a microservices architecture are being used to design, develop and deploy applications leveraging agile software development appro...

Request to download
Takedown Tools and Services

Takedown Tools and Services
Release Date: 07/25/2019

New Services and Tools for Cyber-Crime. The H2020 EU funded project, Takedown, in which CSA participated along with 18 other partners-organisations, deliver...

Request to download
Challenges in Securing Application Containers and Microservices

Challenges in Securing Application Containers and Microservices
Release Date: 07/16/2019

Application containers and a microservices architecture are being used to design, develop and deploy applications leveraging agile software development appro...

Request to download
Cloud Penetration Testing Playbook

Cloud Penetration Testing Playbook
Release Date: 07/12/2019

As cloud services continue to enable new technologies and see massive adoption there is a need to extend the scope of penetration testing into public cloud s...

Request to download
CCM and CAIQ v3 (Japanese Translations)

CCM and CAIQ v3 (Japanese Translations)
Release Date: 07/10/2019

This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t...

Request to download
Software Defined Perimeter (SDP): Awareness and Adoption Infographic

Software Defined Perimeter (SDP): Awareness and Adoption Infographic
Release Date: 07/01/2019

A majority of organizations recognize the need to change their approach to user access control. SDP is seeing early market adoption and awareness, with under...

Request to download
Guide to IoT Framework: Chinese Translation

Guide to IoT Framework: Chinese Translation
Release Date: 06/24/2019

The Guide to the IoT Security Controls Framework provides instructions for using the companion CSA IoT Security Controls Framework spreadsheet. This guide ex...

Request to download
Software Defined Perimeter for Infrastructure as a Service: Chinese Translation

Software Defined Perimeter for Infrastructure as a Service: Chinese Translation
Release Date: 06/24/2019

Obtain a clear sense of the security challenges facing enterprise users of IaaS, understand the problems that arise from combining native IaaS access control...

Request to download
IoT Controls Framework: Chinese Translation

IoT Controls Framework: Chinese Translation
Release Date: 06/24/2019

The Internet of Things (IoT) Security Controls Framework introduces the base-level security controls required to mitigate many of the risks associated with a...

Request to download
Cloud Octagon Model

Cloud Octagon Model
Release Date: 06/24/2019

In this document CSA provides an approach to assess risk in SaaS cloud computing. It takes into account the security challenges in a cloud computing environm...

Request to download
Software Defined Perimeter for Infrastructure as a Service: Japanese Translation

Software Defined Perimeter for Infrastructure as a Service: Japanese Translation
Release Date: 06/23/2019

Obtain a clear sense of the security challenges facing enterprise users of IaaS, understand the problems that arise from combining native IaaS access control...

Request to download