CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | STAR Continuous Technical Guidance Release Date: 02/27/2019 STAR Continuous specifies the necessary activities and conditions for the continuous auditing of the cloud service over a defined set of security requirement... Request to download |
![]() | High Performance Computing (HPC) Cloud Security Working Group Charter Release Date: 02/26/2019 To develop a holistic security framework for cloud infrastructure architected for High Performance Computing needs, with the aim of securing where the cloud ... Request to download |
![]() | CCM Mapping Workpackage Template Release Date: 02/14/2019 This document is the companion document to the Methodology for the Mapping of the Cloud Controls Matrix (CCM). It is a CCM mapping workpackage template that ... Request to download |
![]() | The 12 Most Critical Risks for Serverless Applications Release Date: 02/11/2019 The 12 Most Critical Risks for Serverless Applications 2019 document is meant to serve as a security awareness and education guide. This report was curated a... Request to download |
![]() | Cloud Incident Response Charter Release Date: 01/21/2019 To develop a holistic Cloud Incident Response (CIR) framework that comprehensively covers key causes of cloud outages (both security and non-security related... Request to download |
![]() | CCM v3.0.1 Addendum - BSI Germany C5 v1 Release Date: 01/18/2019 This document is an addendum to the Cloud Controls Matrix (CCM) V3.0.1 controls. It contains the additional controls that serves to bridge the gap between CC... Request to download |
![]() | CCM v3.0.1 Addendum - ISO 27002 27017 27018 v1.1 Release Date: 01/18/2019 This document is an addendum to the Cloud Controls Matrix (CCM) V3.0.1 controls. It contains the additional controls that serves to bridge the gap between CC... Request to download |
![]() | Enterprise Resource Planning and Cloud Adoption Release Date: 01/11/2019 The “Impact of Cloud on ERP” survey report was designed to assess the impact of ERP solutions on organizations and better understand cloud preparation and da... Request to download |
![]() | Guideline on Effectively Managing Security Service in the Cloud Release Date: 01/04/2019 This initiative aims to develop a research whitepaper, focusing on building up a cloud security services management platform. This whitepaper will serve as a... Request to download |
![]() | Streamlining Vendor IT Security and Risk Assessments Release Date: 12/09/2018 Cloud computing has rapidly gained traction as a significant and even default IT system for many different organizations. In such a dynamic environment, cybe... Request to download |
![]() | Release Date: 11/27/2018 Thanks to the rise in popularity of Bitcoin cryptocurrency, the innovative technologies of Blockchain and other systems of distributed ledger technology (DLT... Request to download |
![]() | Release Date: 11/24/2018 The use of new technologies, such as cloud services and the Internet of Things (IoT), will disrupt legacy systems and the chain of data processing in the sup... Request to download |
![]() | Security Guidance v4.0 Info Sheet Release Date: 11/09/2018 This version, the first major update since 2011, is the culmination of over a year of dedicated research and public participation from the CSA community, wor... Request to download |
![]() | Release Date: 09/20/2018 The traditional approach to updating software for IT assets involves analysis, staging and distribution of the update—a process that usually occurs during of... Request to download |
![]() | Top Threats to Cloud Computing: Deep Dive Release Date: 08/08/2018 This case study attempts to connect all the dots when it comes to security analysis by using nine anecdotes cited in the Top Threats for its foundation. Each... Request to download |
![]() | OWASP Secure Medical Devices Deployment Standard Release Date: 08/07/2018 With the explosion of botnets and other malware that now target IoT devices (of which medical devices can be considered a subtype) the need for security-min... Request to download |
![]() | Release Date: 07/09/2018 The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) provides fundamental security principles to guide cloud vendors and cloud customers seeking to ... Request to download |
![]() | Firmware Integrity in the Cloud Data Center Release Date: 06/12/2018 This paper presents the point of view from key stakeholders in datacenter development regarding how to build cloud infrastructure using secure servers and in... Request to download |
![]() | Software Defined Perimeter Glossary Release Date: 06/12/2018 The Software Defined Perimeter (SDP) Glossary is a reference document that brings together SDP related terms and definitions from various professional resour... Request to download |
![]() | The State of Post-Quantum Cryptography Release Date: 05/23/2018 Most people pay little attention to the lock icon on their browser’s address bar that signifies a secure connection called HTTPS. This connection establishes... Request to download |