CSAIChaptersEventsBlog
On April 2, CSA will offer 50% off online training and certificate exams. Get ready for CSA Day →

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Identity and Access Gaps in the Age of Autonomous AI

Identity and Access Gaps in the Age of Autonomous AI

Release Date: 03/23/2026

Enterprises are embedding agentic AI across their environments, allowing agents to interact with applications, infrastructure, and data systems. They are no longer experimental tools, but operational actors. This survey report examines how organizations are contending with the challenges of...
Decision Tree Workflow for ISO 27001 and ISO 42001 Paths

Decision Tree Workflow for ISO 27001 and ISO 42001 Paths

Release Date: 03/05/2026

This diagram provides a visual overview of the steps an organization can follow to obtain STAR for AI certification, illustrating the certification pathway and key requirements involved in the process.

Guidelines for CPAs Providing CSA STAR or STAR for AI Attestation Program

Guidelines for CPAs Providing CSA STAR or STAR for AI Attestation Program

Release Date: 03/05/2026

This document provides guidance for CPAs in conducting a CSA STAR Attestation or STAR for AI Attestation. It includes relevant information such as professional requirements, CPA competency and ethical standards, the scope and criteria for SOC 2+ attestation engagements, and guidelines for...