CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
Accedere: Using a SOC 2 Approach to Help Organizations Achieve CSA STAR Level 2 Release Date: 09/19/2022 Cybersecurity frameworks, standards and certifications can be quite complicated to understand, making it difficult to identify which standard an organizat... Request to download | |
Cloud and Web Security Challenges in 2022 Release Date: 08/16/2022 Organizations’ work environments have undergone rapid but lasting changes in the face of the recent health crisis. Remote work became a necessity and many... Request to download | |
![]() | Top Threats Working Group Charter 2022 Release Date: 08/11/2022 The Top Threats Working Group aims to provide up-to-date, industry-informed expert insights on cloud security risks, threats, and vulnerabilities to help ... Request to download |
![]() | Enterprise Architecture Working Group Charter 2022 Release Date: 08/11/2022 This is the 2022 Charter for the Enterprise Architecture Working Group to promote research, development, and education of best practices and methodologies... Request to download |
![]() | Third-Party Vendor Risk Management in Healthcare Release Date: 07/19/2022 The increased use of third-party vendors for applications and data processing services is a business model that is likely to continue, especially as HDOs ... Request to download |
![]() | CSA CCM v4.0 Addendum - CRI FS Profile v1.2 Release Date: 07/15/2022 This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t... Request to download |
Critical Controls Implementation for Oracle Fusion Applications Release Date: 07/12/2022 Framed within the context of the Cloud Security Alliance (CSA)’s ERP Twenty Controls, this document presents the essential and optional security features ... Request to download | |
![]() | State of ICS Security in the Age of Cloud Release Date: 07/05/2022 The goal of this document hopes to create awareness and share insights on the benefits of leveraging Cloud Computing for ICS/OT. It also attempts to stimu... Request to download |
![]() | Measuring Risk and Risk Governance Release Date: 06/21/2022 Adapting to the cloud presents a new challenge to enterprises. The shared responsibility model, used to distinguish responsibilities between cloud provide... Request to download |
![]() | The Continuous Audit Metrics Catalog: Towards a Machine-Readable Representation Release Date: 06/07/2022 In October 2021, the Cloud Security Alliance released the first version of the Continuous Audit Metrics catalog which provides a standard reference for th... Request to download |
![]() | Top Threats to Cloud Computing Pandemic Eleven Release Date: 06/06/2022 The Top Threats reports have traditionally aimed to raise awareness of threats, risks, and vulnerabilities in the cloud. Such issues are often the result ... Request to download |
CISO Perspectives and Progress in Deploying Zero Trust Release Date: 06/03/2022 Some of the areas covered in this survey include where Zero Trust falls as a priority in the organization, the percentage of those who have completed rela... Request to download | |
![]() | Best Practices for Smart Contract Security Hyperledger Fabric Release Date: 05/18/2022 The goal is to establish best practices for using smart contract specifically in Hyperledger Fabric 2.0 environment. This document serves as a guide for S... Request to download |
![]() | Serverless Computing Working Group Charter Release Date: 05/17/2022 Serverless working group charter document. The Serverless WG seeks to develop best practices to help organizations that want to run their business wi... Request to download |
![]() | HPC Cloud Services Onboarding Guide Release Date: 05/16/2022 This paper aims to present an overview of what to consider to ensure the proper selection, design, and implementation of an HPC solution that will satisfy... Request to download |
![]() | Healthcare Supply Chain Cybersecurity Risk Management Release Date: 05/11/2022 It is essential for Healthcare Delivery Organizations to conduct proper risk management practices and risk assessments of suppliers and third-party servic... Request to download |
![]() | Cloud Key Management Working Group Charter Release Date: 05/04/2022 Cloud services are becoming ubiquitous in all sizes, and customers encounter many obligations and opportunities for using key management systems with thos... Request to download |
![]() | Release Date: 04/25/2022 The IoT Security Controls Matrix is relevant for enterprise IoT systems that incorporate multiple types of connected devices, cloud services, and networki... Request to download |
![]() | Guide to the IoT Controls Matrix v3 Release Date: 04/25/2022 The Guide to the IoT Security Controls Matrix provides instructions for using the companion CSA IoT Security Controls Matrix v3. This guide explains how t... Request to download |
![]() | Identity Access Management Working Group Charter Release Date: 04/22/2022 Cloud services are becoming ubiquitous in all sizes, and customers encounter many obligations and opportunities for using Identity Access Management (IAM)... Request to download |

-01.png)













