Cloud 101CircleEventsBlog
Join AT&T Cybersecurity in Chicago to learn top 2024 resilience tactics on May 21st!

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

International Standardization Council Charter 2023

International Standardization Council Charter 2023
Release Date: 08/23/2023

This charter lays out the scope, responsibilities, and roadmap for the International Standardization Council (ISC). The ISC actively searches mechanisms o...

Request to download
IoT Controls Matrix v3 - Japanese Translation

IoT Controls Matrix v3 - Japanese Translation
Release Date: 07/21/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
IoT Controls Matrix v3

IoT Controls Matrix v3
Release Date: 04/25/2022

The IoT Security Controls Matrix is relevant for enterprise IoT systems that incorporate multiple types of connected devices, cloud services, and networki...

Request to download
Guide to the IoT Controls Matrix v3

Guide to the IoT Controls Matrix v3
Release Date: 04/25/2022

The Guide to the IoT Security Controls Matrix provides instructions for using the companion CSA IoT Security Controls Matrix v3. This guide explains how t...

Request to download
State of Cloud Security Concerns, Challenges, and Incidents - Chinese Translation

State of Cloud Security Concerns, Challenges, and Incidents - Chinese Translation
Release Date: 04/06/2022

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
Top Threats to Cloud Computing: Egregious Eleven - Korean Translation

Top Threats to Cloud Computing: Egregious Eleven - Korean Translation
Release Date: 08/17/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
SecaaS Working Group Charter 2021

SecaaS Working Group Charter 2021
Release Date: 07/09/2021

This charter lays out the scope, responsibilities, and roadmap for the Security as a Service (SecaaS) Working Group. The SecaaS Working Group has been cre...

Request to download
Disaster Recovery as a Service

Disaster Recovery as a Service
Release Date: 05/13/2021

Disaster Recovery as a Service (DRaaS) is a cloud computing service model that allows an organization to back up its data and IT infrastructure in a third...

Request to download
Security Guidelines for Providing and Consuming APIs

Security Guidelines for Providing and Consuming APIs
Release Date: 04/30/2021

In modern application workloads, organizations are often required to integrate their application with other parties such as Software-as-a-Service (SaaS) prov...

Request to download
State of Cloud Security Concerns, Challenges, and Incidents

State of Cloud Security Concerns, Challenges, and Incidents
Release Date: 03/30/2021

The use of cloud services has continued to increase over the past decade. Particularly in the wake of the COVID-19 public health crisis, many enterprises’...

Request to download
Earning Trust in the 21st Century

Earning Trust in the 21st Century
Release Date: 01/26/2021

This paper addresses the technical, social, policy, and regulatory issues associated with creating trust frameworks in a Zero Trust world. Industry and gover...

Request to download
Healthcare Big Data in the Cloud

Healthcare Big Data in the Cloud
Release Date: 07/21/2020

We are living in the information age. There are large and complex data sets generated daily. Data is generated by social media, emails, as well as numerous d...

Request to download
Hybrid Cloud and Its Associated Risks

Hybrid Cloud and Its Associated Risks
Release Date: 07/13/2020

Cloud computing is flourishing. Hybrid clouds, especially, have been gaining more traction as cloud customers increasingly understand that using public cloud...

Request to download
Telehealth Data in the Cloud

Telehealth Data in the Cloud
Release Date: 06/16/2020

In the wake of COVID-19 Health Delivery Organizations (HDOs) are rapidly increasing their utilization of telehealth capabilities like Remote Patient Monitori...

Request to download
Cloud Industrial Internet of Things (IIoT) - Industrial Control Systems Security Glossary

Cloud Industrial Internet of Things (IIoT) - Industrial Control Systems Security Glossary
Release Date: 05/05/2020

The Industrial Control Systems (ICS) Security Glossary is a reference document that brings together ICS and IT/OT related terms and definitions. Bringing t...

Request to download
CSA CCM v3.0.1 Addendum - Cloud OS Security Specifications

CSA CCM v3.0.1 Addendum - Cloud OS Security Specifications
Release Date: 01/29/2020

This document is an addendum to the CCM V3.0.1 and contains a controls mapping and gap analysis between the CSA CCM and CSA's research artifact "Cloud OS Sec...

Request to download
CSA CCM v3.0.1 Addendum to the Reserve Bank of India (RBI)’s Gopala Krishna Committee (GKC) report

CSA CCM v3.0.1 Addendum to the Reserve Bank of India (RBI)’s Gopala Krishna Committee (GKC) report
Release Date: 11/27/2019

This document contains a mapping and gap analysis between the cloud security requirements of CCM V3.0.1 and those of the Reserve Bank of India (RBI)’s Gopala...

Request to download
Top Threats to Cloud Computing: Egregious Eleven

Top Threats to Cloud Computing: Egregious Eleven
Release Date: 08/06/2019

The report provides organizations with an up-to-date, expert-informed understanding of cloud security concerns in order to make educated risk-management deci...

Request to download
Cloud Controls Matrix v3.0.1

Cloud Controls Matrix v3.0.1
Release Date: 08/03/2019

The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations...

Request to download
Cloud Octagon Model

Cloud Octagon Model
Release Date: 06/24/2019

In this document CSA provides an approach to assess risk in SaaS cloud computing. It takes into account the security challenges in a cloud computing environm...

Request to download