CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
SaaS Security Capability Framework (SSCF) Release Date: 09/23/2025 The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls pr... Request to download | |
Release Date: 08/27/2025 Machine learning (ML) is becoming increasingly central to business operations, making the security of ML pipelines essential rather than optional. Machine... Request to download | |
Analyzing Log Data with AI Models to Meet Zero Trust Principles Release Date: 09/15/2025 Logs are fundamental to Zero Trust. They capture critical details about user activity, device behavior, network traffic, and application access. However, ... Request to download | |
The State of Cloud and AI Security 2025 Release Date: 09/09/2025 This global survey report, developed in partnership with Tenable, examines how organizations are adapting security strategies for hybrid, multi-cloud, and... Request to download | |
![]() | Security Guidance for Critical Areas of Focus in Cloud Computing v5 Release Date: 07/15/2024 Cloud computing has firmly cemented its place as the foundation of the information security industry. The Cloud Security Alliance’s Security Guidance v5 i... Request to download |
Agentic AI Identity and Access Management: A New Approach Release Date: 08/18/2025 Agentic AI is pushing the boundaries of automation, autonomy, and decision-making at machine speed. But traditional identity and access management (IAM) p... Request to download | |
Secure Agentic System Design: A Trait-Based Approach Release Date: 07/30/2025 Thanks to powerful reasoning models, AI agents are making more nuanced decisions and interacting more effectively with their environments. At the same tim... Request to download | |
![]() | Release Date: 07/28/2025 The CCM Working Group is responsible for maintaining and evolving the Cloud Security Alliance’s foundational framework for cloud security assurance, the C... Request to download |
![]() | Healthcare Confidential Computing and the Trusted Execution Environment Release Date: 07/14/2025 Healthcare Delivery Organizations (HDOs) routinely process Protected Health Information (PHI), Personally Identifiable Information (PII), and financial da... Request to download |
![]() | CAVEaT Working Group Charter 2025 Release Date: 06/26/2025 The Cloud Security Alliance (CSA), in collaboration with the MITRE Corporation, established the Cloud Adversarial Vectors, Exploits, and Threats (CAVEaT™)... Request to download |
Navigating the Human Factor: Addressing Employee Resistance to AI Adoption Release Date: 06/25/2025 In boardrooms around the world, leaders are hailing artificial intelligence (AI) as a game-changer for efficiency and innovation. Many organizations have ... Request to download | |
Zero Trust Automation & Orchestration and Visibility & Analytics Overview Release Date: 06/04/2025 Visibility & Analytics and Automation & Orchestration are foundational, cross-cutting capabilities within the Zero Trust paradigm. They enable con... Request to download | |
Dynamic Process Landscape: A Strategic Guide to Successful AI Implementation Release Date: 06/02/2025 Artificial Intelligence (AI) adoption in business and manufacturing is failing at least twice as often as it succeeds. Companies are trying to integrate A... Request to download | |
Release Date: 05/28/2025 Agentic AI systems represent a significant leap forward for AI. Their ability to plan, reason, act, and adapt autonomously introduces new capabilities and... Request to download | |
Release Date: 05/27/2025 Traditional security models treat Internet of Things (IoT) security solely as a long-term supply chain concern. This is a significant oversight in today's... Request to download | |
![]() | Top Threats to Cloud Computing - Deep Dive 2025 Release Date: 04/28/2025 This report uses the threats identified in CSA’s Top Threats to Cloud Computing 2024 to reflect on eight recent cybersecurity breaches. Notable incidents ... Request to download |
State of SaaS Security Report 2025 Release Date: 04/21/2025 Software-as-a-Service (SaaS) applications have become foundational to modern business operations. However, organizations are also facing a rising tide of ... Request to download | |
Requirements for Bodies Providing STAR Certification Release Date: 03/31/2025 This document outlines how to conduct STAR certification assessments to the Cloud Controls Matrix (CCM) as part of an ISO 27001 assessment. The STAR certi... Request to download | |
![]() | CSA Code of Conduct to EU Cloud Code of Conduct Mapping Release Date: 03/24/2025 Navigating General Data Protection Regulation (GDPR) compliance requirements can be challenging. Fortunately, Codes of Conduct (CoCs) provide a straightfo... Request to download |
![]() | Cloud Key Management Working Group Charter 2025 Release Date: 03/18/2025 Cloud services are becoming ubiquitous in all sizes, and customers encounter many obligations and opportunities for using key management systems with thos... Request to download |





.png)
