CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | Code of Practice for Implementing STAR Level 2 Release Date: 06/23/2021 This Code of Practice shows how you can apply the CCM control set in your organization to reach STAR Level 2 third party certification/attestation and als... Request to download |
![]() | Critical Controls Implementation for Salesforce Release Date: 06/15/2021 The Salesforce Platform can be a valuable tool for organizations to build and test applications. However, certain security changes are needed when an orga... Request to download |
![]() | Release Date: 06/10/2021 The recent COVID-19 pandemic has increased the demand for data and accelerated the use of telehealth. The Health Resources and Services Administration (HRSA)... Request to download |
Cloud Controls Matrix and CAIQ v4.0 Release Date: 06/07/2021 The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s... Request to download | |
STAR Level 1: Security Questionnaire (CAIQ v4) Release Date: 06/07/2021 The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,... Request to download | |
Cloud Solution Data Science COVID-19 Dashboard Release Date: 05/27/2021 This publication was produced through the efforts of chapters and volunteers but the content development falls outside of the CSA Research Lifecycle. For ... Request to download | |
CSA Enterprise Architecture Reference Guide Release Date: 05/18/2021 The Enterprise Architecture Reference Guide v2 is a companion piece with the EA v2 to CCM v3.0.1 Mapping. The peer review for both documents are intended to ... Request to download | |
![]() | Enterprise Architecture Reference Diagram Release Date: 05/18/2021 The CSA Enterprise Architecture (EA) is both a methodology and a set of tools. It is a framework, a comprehensive approach for the architecture of a secure c... Request to download |
Enterprise Architecture v2 to CCM v3.01 Mapping Guide Release Date: 05/18/2021 The Enterprise Architecture (EA) is the CSA’s standard cloud reference architecture while the Cloud Control Matrix (CCM) is the CSA’s standard control set. T... Request to download | |
![]() | Enterprise Architecture to CCM v3.01 Reordered Mapping Release Date: 05/18/2021 The EA v2 to CCM v3.0.1 Mapping is a companion piece with the Enterprise Architecture Reference Guide v2. The peer review for both documents are intended to ... Request to download |
Disaster Recovery as a Service Release Date: 05/13/2021 Disaster Recovery as a Service (DRaaS) is a cloud computing service model that allows an organization to back up its data and IT infrastructure in a third... Request to download | |
![]() | Release Date: 05/13/2021 The Top Cloud Priorities for CxOs was created to equip C-level executives with industry guidance to build pragmatic cloud security projects and strategies... Request to download |
![]() | CSA CxO Trust Working Group Charter Release Date: 05/11/2021 The CSA CxO Trust Working Group will conduct research consisting of best practices, metrics, surveys, C-level presentations, and other tools in support of... Request to download |
![]() | STAR Enabled Solution | CSA - OneTrust VRM Tool Release Date: 05/05/2021 The CSA-OneTrust Vendor Risk Management (VRM) tool automates the entire vendor management lifecycle, including onboarding and offboarding vendors, triaging v... Request to download |
![]() | Cloud Incident Response Framework Release Date: 05/04/2021 This document aims to provide a Cloud Incident Response (CIR) framework that serves as a go-to guide for a CSC to effectively prepare for and manage cloud in... Request to download |
![]() | Security Guidelines for Providing and Consuming APIs Release Date: 04/30/2021 In modern application workloads, organizations are often required to integrate their application with other parties such as Software-as-a-Service (SaaS) prov... Request to download |
![]() | Crypto-Asset Exchange Security Guidelines Release Date: 04/13/2021 Thanks to the blockchain technology that makes them possible, crypto-assets are becoming massively successful. As with any successful industry, a multitud... Request to download |
![]() | Zero Trust Architecture Expert Group Charter Release Date: 04/08/2021 The CSA Zero Trust Architecture Expert Group will review and advise on the scope, curriculum, objectives, structure, go-to-market (GTM) strategy and value pr... Request to download |
![]() | Critical Controls Implementation for Oracle E-Business Suite Release Date: 04/05/2021 This paper will help an organization determine what security changes are needed when deploying Oracle E-Business Suite (EBS) in the Cloud. For clarity, this ... Request to download |
![]() | CSA STAR Level 3 Focus Group Charter Release Date: 04/02/2021 The CSA STAR Level 3 Focus Group will advise on the scope, objectives, structure, go-to-market (GTM) strategy and value proposition for STAR Level 3... Request to download |













