Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Prepare for machine-speed cybersecurity with CSA Corporate Membership + Frontier Ready Support for $9,000. Offer ends September 30 →

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Zero Trust Program Management Guidance

Zero Trust Program Management Guidance

Release Date: 09/08/2026

Effective program management is a foundational enabler of a successful Zero Trust strategy. It provides the structure, accountability, and alignment required to translate security vision into measurable outcomes. Rather than isolated initiatives, cybersecurity efforts must operate as a...
Zero Trust Microsegmentation Guidance

Zero Trust Microsegmentation Guidance

Release Date: 09/08/2026

Microsegmentation is a foundational Zero Trust strategy that enforces explicit, fine-grained communication controls between systems. By reducing unnecessary reachability, it aids with lateral movement prevention, contains threats, and minimizes blast radius.

This guide provides a technical and...
Cryptographic Context Injection: When Encryption Defeats AI Guardrails

Cryptographic Context Injection: When Encryption Defeats AI Guardrails

Release Date: 08/22/2026

Key Takeaways A new attack technique called cryptographic context injection encrypts malicious instructions with a strong cipher — AES-256-GCM with PBKDF2-derived keys — so that static content classifiers cannot read them before they reach the model. The AI system then decrypts the payload...