CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | State of Cloud Security Concerns, Challenges, and Incidents Release Date: 03/30/2021 The use of cloud services has continued to increase over the past decade. Particularly in the wake of the COVID-19 public health crisis, many enterprises’... Request to download |
![]() | Release Date: 03/10/2021 The following resources are frequently referenced in the CCAK study guide and training materials. You can download the unofficial prep-kit with the correc... Request to download |
Confidence in Post Quantum Algorithms Release Date: 02/25/2021 NIST made the recent announcement of its Round 3 candidates for future post-quantum cryptography or quantum safe standards. As the world prepares to transiti... Request to download | |
![]() | Cloud Incident Response Working Group Charter Release Date: 02/14/2021 In today’s connected era, a comprehensive incident response strategy is an integral aspect of any organization aiming to manage and lower their risk profile.... Request to download |
Blockchains in the Quantum Era Release Date: 02/05/2021 Digital Ledger Technologies (DLT) such as blockchain are being deployed as part of diverse applications that span multiple market segments. Application devel... Request to download | |
CSA IoT Security Controls Framework v2 Release Date: 01/28/2021 The IoT Security Controls Framework is relevant for enterprise IoT systems that incorporate multiple types of connected devices, cloud services, and networki... Request to download | |
Guide to the Internet of Things (IoT) Security Controls Framework v2 Release Date: 01/28/2021 The Guide to the IoT Security Controls Framework provides instructions for using the companion CSA IoT Security Controls Framework v2 spreadsheet. This guide... Request to download | |
Earning Trust in the 21st Century Release Date: 01/26/2021 This paper addresses the technical, social, policy, and regulatory issues associated with creating trust frameworks in a Zero Trust world. Industry and gover... Request to download | |
![]() | APAC Data Sovereignty Working Group Charter Release Date: 01/12/2021 The proposed charter outlines the scope, responsibilities, issues to address, align and guide the working group. Request to download |
![]() | Mitigating Hybrid Clouds Risks - Turkish Translation Release Date: 01/12/2021 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translated c... Request to download |
![]() | Software-Defined Perimeter Zero Trust Charter Release Date: 12/29/2020 The proposed charter outlines the scope, responsibilities, etc. to align and guide the Software-Defined Perimeter Zero Trust working group through the year 2... Request to download |
![]() | Cloud Security Initiative for the Financial Sector - Working Group Charter Release Date: 12/20/2020 CSA is partnering with the Cyber Risk Institute (CRI) to provide the financial community with new resources to map and integrate CSA’s Cloud Controls Matr... Request to download |
![]() | Enterprise Architecture to CCM Shared Responsibility Model Release Date: 12/18/2020 The EA-CCM Shared Responsibility Model is a companion piece with the EA-CCM Mapping. To review the EA-CCM Mapping, follow this link. (https://cloudsecuritya... Request to download |
![]() | Enterprise Architecture to CCM v3.0.1 Mapping Release Date: 12/18/2020 The EA-CCM Mapping is a companion piece with the EA-CCM Shared Responsibility Model. To review the Shared Responsibility Model, follow this link. (http://cl... Request to download |
Cloud-Based, Intelligent Ecosystems Release Date: 12/10/2020 This paper proposes a call to action for security executives to break the endless cycle of iterative tool adoption and, instead, move to data-centric securit... Request to download | |
![]() | The 2020 State of Identity Security in the Cloud Release Date: 11/19/2020 The use of cloud services have continued to increase over the past decade. Particularly in the wake of the COVID-19 public health crisis, many enterprises di... Request to download |
Key Management in Cloud Services Release Date: 11/09/2020 The purpose of this document is to provide guidance for using Key Management Systems (KMS) with cloud services, whether the key management system is native t... Request to download | |
![]() | Cloud Controls Matrix v3.0.1 ISO Reverse Mapping Release Date: 10/22/2020 This latest expansion to the CCM incorporates the ISO/IEC 27017:2015:2015 and ISO/IEC 27018:20147:2015 and ISO/IEC 27002:2013 controls, introduces a new appr... Request to download |
Mitigating Hybrid Clouds Risks Release Date: 10/22/2020 Hybrid clouds are often the starting point for organizations in their cloud journey. However, any cloud model consists of risks, threats, and vulnerabilitie... Request to download | |
Cloud OS Security Specification v2.0 Release Date: 10/14/2020 Currently, most of the standards related to cloud computing security focus on information security management systems (ISMS), and corresponding certification... Request to download |










