Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

Map the Transaction Flows for Zero Trust

Map the Transaction Flows for Zero Trust
Release Date: 11/18/2024

The NSTAC Report to the President on Zero Trust defines five steps to implementing a Zero Trust security strategy. This publication provides guidance on e...

Request to download
AI Risk Management: Thinking Beyond Regulatory Boundaries

AI Risk Management: Thinking Beyond Regulatory Boundaries
Release Date: 11/13/2024

While artificial intelligence (AI) offers tremendous benefits, it also introduces significant risks and challenges that remain unaddressed. A comprehensiv...

Request to download
AI Organizational Responsibilities - Governance, Risk Management, Compliance and Cultural Aspects

AI Organizational Responsibilities - Governance, Risk Management, Compliance and Cultural Aspects
Release Date: 10/21/2024

Continuing CSA's efforts to address the evolving AI landscape, this latest publication covers AI governance, risk management, and culture. Understand vari...

Request to download
AI in Medical Research: Applications & Considerations

AI in Medical Research: Applications & Considerations
Release Date: 09/25/2024

The advent of artificial intelligence (AI) has brought about a paradigm shift in numerous fields. AI technologies can process vast amounts of data, recogn...

Request to download
Don’t Panic! Getting Real about AI Governance

Don’t Panic! Getting Real about AI Governance
Release Date: 09/18/2024

The excitement around Generative AI and its potential business value continues to grow. A major factor is AI systems' emerging capability to mimic human-l...

Request to download
Fully Homomorphic Encryption Working Group Charter 2024

Fully Homomorphic Encryption Working Group Charter 2024
Release Date: 08/29/2024

Through the use and deployment of cryptographic libraries, specialist software toolchains, and dedicated hardware and infrastructure, Fully Homomorphic En...

Request to download
Using AI for Offensive Security

Using AI for Offensive Security
Release Date: 08/06/2024

Offensive security involves proactively simulating an attacker’s behavior by using tactics and techniques similar to those of an adversary to identify sys...

Request to download
AI Model Risk Management Framework

AI Model Risk Management Framework
Release Date: 07/23/2024

Sophisticated machine learning (ML) models present exciting opportunities in fields such as predictive maintenance and smart supply chain management. Whil...

Request to download
Defining the Zero Trust Protect Surface

Defining the Zero Trust Protect Surface
Release Date: 03/05/2024

Enterprise adoption and implementation of Zero Trust is broad and growing. Venture Beat reports that 90% of organizations moving to the cloud are adopting...

Request to download
Beyond Passwords: The Role of Passkeys in Modern Web Security

Beyond Passwords: The Role of Passkeys in Modern Web Security
Release Date: 11/12/2023

Web authentication methods have evolved significantly over the years to improve security and the user experience. In the early days of the internet, usern...

Request to download
Cloud Native Application Protection Platform Survey Report

Cloud Native Application Protection Platform Survey Report
Release Date: 08/23/2023

Cloud Native Application Protection Platforms (CNAPPs) have emerged as a critical category of security tooling in recent years due to the complexity of co...

Request to download
How to Design a Secure Serverless Architecture (2023 Version) - Japanese Translation

How to Design a Secure Serverless Architecture (2023 Version) - Japanese Translation
Release Date: 05/12/2023

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
An Agile Data Doctrine for a Secure Data Lake

An Agile Data Doctrine for a Secure Data Lake
Release Date: 04/25/2023

Data is now a significant asset in most organizations around the globe, whether government, business, or not-for-profit; the inevitable shift toward its u...

Request to download
Secure Connection Requirements of Hybrid Cloud - Japanese Translation

Secure Connection Requirements of Hybrid Cloud - Japanese Translation
Release Date: 06/14/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Software-Defined Perimeter (SDP) Specification v2.0

Software-Defined Perimeter (SDP) Specification v2.0
Release Date: 03/10/2022

The Software-Defined Perimeter (SDP) architecture is an effective way to implement the principles of Zero Trust. SDP aims to give enterprise security arch...

Request to download
How to Design a Secure Serverless Architecture - Chinese Translation

How to Design a Secure Serverless Architecture - Chinese Translation
Release Date: 02/07/2022

Like any solution, serverless computing brings with it a variety of cyber risks. This paper covers security for serverless applications, focusing on best pra...

Request to download
Blockchains in the Quantum Era - Chinese Translation

Blockchains in the Quantum Era - Chinese Translation
Release Date: 02/06/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Secure Connection Requirements of Hybrid Cloud

Secure Connection Requirements of Hybrid Cloud
Release Date: 11/05/2021

The National Institute of Standards and Technology (NIST) defines hybrid cloud infrastructure as a composition of distinct cloud infrastructures (pri...

Request to download
The Continuous Audit Metrics Catalog

The Continuous Audit Metrics Catalog
Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo...

Request to download
How to Design a Secure Serverless Architecture 2021

How to Design a Secure Serverless Architecture 2021
Release Date: 09/14/2021

Like any solution, serverless computing brings with it a variety of cyber risks. This paper covers security for serverless applications, focusing on best pra...

Request to download