CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
NIST CSF v2 Cloud Community Profile - Based on CCM v4 The CSFv2.0 Cloud Community Profile aligns the Cloud Controls Matrix (CCM) version 4.0 with the Cybersecurity Framework (CSF) version 2.0 by mapping equiv... Request to download | |
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2 The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices for securing cloud... Request to download | |
CCM v4.0 Implementation Guidelines This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM cont... Request to download | |
Cloud Controls Matrix and CAIQ v4 The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s... Request to download | |
Requirements for Bodies Providing STAR Certification This document outlines how to conduct STAR certification assessments to the Cloud Controls Matrix (CCM) as part of an ISO 27001 assessment. The STAR certi... Request to download | |
Standardizing Security in Diverse Sectors: A Template for STAR-Aligned Sector-Specific Standards The CSA Security, Trust, Assurance, and Risk (STAR) program encompasses the key principles of transparency, rigorous auditing, and harmonization of cybers... Request to download | |
STAR Attestation Value Proposition | |
Guidelines for CPAs Providing CSA STAR Attestation v4 This document provides guidance for CPAs in conducting a STAR Attestation. It includes relevant information including professional requirements, competenc... Request to download | |
STAR Program Overview The CSA Security, Trust, Assurance, and Risk (STAR) program is the most complete and largest cloud assurance program in the world that constitutes an ecos... Request to download | |
CCM and CAIQ FAQ The Cloud Controls Matrix (CCM) is a framework of controls (policies and procedures) that are essential for cloud computing security. It is created and up... Request to download | |
Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix The download file also contains the following: Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud ... Request to download | |
Deconstructing Application Connectivity Challenges in a Complex Cloud Environment The production and use of SaaS applications in organizations has grown exponentially over the past several years. Application Security has become an integ... Request to download | |
CSA CCM v4.0 Addendum - Spain National Security Framework (ENS) This document is an addendum to the CCM V4.0 that contains controls mapping between the CSA CCM and Spain's National Security Framework (ENS).The document... Request to download | |
CSA CCM v4.0 Addendum - ISMAP This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and Japan's Information System Security Management and Asse... Request to download | |
CSA CCM v4.0 Addendum - CRI FS Profile v1.2 This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t... Request to download | |
CCPA Addendum - PLA CoC v4.1 This document serves as a mapping exercise between the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR) and the CS... Request to download | |
CSA CCM v4.0 Addendum - UAE IA Regulation This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and the UAE Information Assurance (IA) Regulation. The docu... Request to download | |
The Importance of STAR Compliance requires a comprehensive review of services and processes related to cloud infrastructure and how it is managed during a data lifecycle. STAR f... Request to download | |
CCMv4.0 Auditing Guidelines This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework align... Request to download | |
STAR Level 1: Security Questionnaire (CAIQ v4) - Japanese Translation This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |