CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
CCM v4 - Turkish Translation This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download | |
CCM and CAIQ v4 - Chinese Translations This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of local organizations and the C... Request to download | |
CCM and CAIQ v4 -Japanese Translations This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t... Request to download | |
CCM v4 - Spanish Translation This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download | |
CCM v4 Chinese Translation This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of local organizations and the C... Request to download | |
The Continuous Audit Metrics Catalog Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo... Request to download | |
CCM v4 - Hungarian Translation This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download | |
The Evolution of STAR: Introducing Continuous Auditing The CSA Continuous Auditing Certification (aka STAR Level 3) is the most rigorous assurance tier in the STAR program. Level 3 certified services providers... Request to download | |
Code of Practice for Implementing STAR Level 2 This Code of Practice shows how you can apply the CCM control set in your organization to reach STAR Level 2 third party certification/attestation and als... Request to download | |
STAR Level 1: Security Questionnaire (CAIQ v4) The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,... Request to download | |
STAR Enabled Solution | CSA - OneTrust VRM Tool The CSA-OneTrust Vendor Risk Management (VRM) tool automates the entire vendor management lifecycle, including onboarding and offboarding vendors, triaging v... Request to download | |
CSA STAR Level 3 Focus Group Charter The CSA STAR Level 3 Focus Group will advise on the scope, objectives, structure, go-to-market (GTM) strategy and value proposition for STAR Level 3... Request to download | |
STAR Certification Guidance Document: Auditing the Cloud Controls Matrix (CCM) There are a number of control areas on the CCM that will each be awarded a management capability score on a scale of 1-15. This 2nd version release includes ... Request to download | |
Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted] Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an i... Request to download | |
PLA Code of Conduct (CoC): Statement of Adherence Self-Assessment CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f... Request to download | |
Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment The CSA CoC for GDPR Compliance Self-Assessment is the voluntary publication of a CSP’s self-assessment results based on the requirements specified in the PL... Request to download | |
Cloud Controls Matrix v3.0.1 The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations... Request to download | |
CCM and CAIQ v3 (Japanese Translations) This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t... Request to download | |
STAR Continuous Technical Guidance STAR Continuous specifies the necessary activities and conditions for the continuous auditing of the cloud service over a defined set of security requirement... Request to download | |
CSA STAR Program & Open Certification Framework in 2016 and Beyond The Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR) program is the industry’s leading trust mark for cloud security. The CSA Open... Request to download |