CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | Key Management in Cloud Services Release Date: 11/09/2020 The purpose of this document is to provide guidance for using Key Management Systems (KMS) with cloud services, whether the key management system is native t... Request to download |
![]() | Cloud Controls Matrix v3.0.1 ISO Reverse Mapping Release Date: 10/22/2020 This latest expansion to the CCM incorporates the ISO/IEC 27017:2015:2015 and ISO/IEC 27018:20147:2015 and ISO/IEC 27002:2013 controls, introduces a new appr... Request to download |
![]() | Mitigating Hybrid Clouds Risks Release Date: 10/22/2020 Hybrid clouds are often the starting point for organizations in their cloud journey. However, any cloud model consists of risks, threats, and vulnerabilitie... Request to download |
![]() | Cloud OS Security Specification v2.0 Release Date: 10/14/2020 Currently, most of the standards related to cloud computing security focus on information security management systems (ISMS), and corresponding certification... Request to download |
![]() | Survey Report - Security Practices in HPC & HPC Cloud Release Date: 10/08/2020 This survey report aims to provide insights to the level and type of cyber and cloud security adopted by High Performance Computing (HPC) / HPC Cloud infrast... Request to download |
![]() | Critical-Controls-Implementation-for-SAP-(Parts-1-and-2) Release Date: 10/05/2020 SAP security documentation can be difficult to navigate and there are currently no frameworks that aligns with standard controls. This document aims to allev... Request to download |
![]() | Top Threats to Cloud Computing: Egregious Eleven Deep Dive Release Date: 09/23/2020 The purpose of the report is to provide organizations with an up-to-date, expert-informed understanding of cloud security concerns in order to make educated ... Request to download |
![]() | Release Date: 09/14/2020 The CCM Addendum (mapping with Association of Banks in Singapore Cloud Computing Implementation Guide 2.9) is a companion piece with the Gap Analysis Report.... Request to download |
![]() | CCM Gap Analysis Report (ABS CCIG) Release Date: 09/14/2020 The Gap Analysis Report is a companion piece with the CCM Addendum (mapping with Association of Banks in Singapore Cloud Computing Implementation Guide 2.9).... Request to download |
![]() | CSA's Perspective on Cloud Risk Management Release Date: 08/20/2020 The rapid growth in both scope and market share, combined with the inherent complexity of cloud computing, appears to be straining the capabilities of existi... Request to download |
![]() | STAR Certification Guidance Document: Auditing the Cloud Controls Matrix (CCM) Release Date: 08/05/2020 There are a number of control areas on the CCM that will each be awarded a management capability score on a scale of 1-15. This 2nd version release includes ... Request to download |
![]() | Healthcare Big Data in the Cloud Release Date: 07/21/2020 We are living in the information age. There are large and complex data sets generated daily. Data is generated by social media, emails, as well as numerous d... Request to download |
![]() | Mobile Application Security Testing – Sum-Up & Landscape Overview Release Date: 07/13/2020 Users place a good deal of trust in mobile app stores’ abilities to review, test, flag and block apps that exhibit undesirable behavior. However, even with t... Request to download |
![]() | Hybrid Cloud and Its Associated Risks Release Date: 07/13/2020 Cloud computing is flourishing. Hybrid clouds, especially, have been gaining more traction as cloud customers increasingly understand that using public cloud... Request to download |
![]() | Enterprise Architecture Working Group Charter Release Date: 07/13/2020 The Enterprise Architecture Working Group (EAWG) helps cloud customers and providers develop industry-recommended, secure and interoperable identity, access ... Request to download |
![]() | Quantum-Safe Security Working Group Charter Release Date: 07/07/2020 The focus of the Quantum‐Safe Security Working Group is on cryptographic methods that will remain safe after the widespread availability of the quantum compu... Request to download |
![]() | The Six Pillars of DevSecOps: Automation Release Date: 07/06/2020 Automation is a critical component of DevSecOps because it enables process efficiency, allowing developers, infrastructure, and information security teams to... Request to download |
![]() | Evolution of CASB Survey Report Release Date: 07/05/2020 The study on CASB, which queried more than 200 IT and security professionals from a variety of organization sizes and locations, examined the expectations, t... Request to download |
![]() | Blockchain and Distributed Ledger Technology Working Group Charter Release Date: 06/28/2020 This Cloud Security Alliance charter outlines the mission, scope and responsibilities, structure, etc. of the Blockchain and Distributed Ledger Technology... Request to download |
![]() | Application Containers and Microservices Working Group Charter Release Date: 06/26/2020 This Cloud Security Alliance charter outlines the mission, scope and responsibilities, structure, etc. of the Application Containers and Microservices Wor... Request to download |