Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
New Training Courses: Turn CSA research into practical skills with self-paced Frontier Ready Training.

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

CCM-Lite and CAIQ-Lite

CCM-Lite and CAIQ-Lite

Release Date: 01/27/2026

The Cloud Security Alliance, in collaboration with the CCM Working Group, proudly presents the CCM-Lite and CAIQ-Lite File Bundle. These tools offer a str...

Request to download
The State of Non-Human Identity and AI Security

The State of Non-Human Identity and AI Security

Release Date: 01/26/2026

Based on a comprehensive survey of IT and security professionals, this report explores how rapid AI adoption amplifies long-standing Identity and Access M...

Request to download
Security Controls Catalog WG 2026 Charter

Security Controls Catalog WG 2026 Charter

Release Date: 01/26/2026

This charter establishes the mission, scope and responsibilities, goals, objectives, and operational procedures for the Security Controls Catalog (SCC) WG. ...

Request to download
The State of AI Security and Governance

The State of AI Security and Governance

Release Date: 12/17/2025

Organizations are rapidly moving from AI experimentation to operational deployment, yet their abilities to secure this transformation vary widely. Commiss...

Request to download
Key Responsibility Models

Key Responsibility Models

Release Date: 12/10/2025

This infographic offers a clear understanding of how cloud service providers and customers share responsibilities for cloud key management.Cloud key manag...

Request to download
Key Management in Cloud Services

Key Management in Cloud Services

This document is an updated edition of the original “Key Management in Cloud Services” paper, first published in 2020. To ensure the accuracy, completeness, ...

Request to download
Data Security within AI Environments

Data Security within AI Environments

Release Date: 12/03/2025

As organizations adopt large language models, multi-modal AI systems, and agentic AI, traditional safeguards must evolve. This publication provides a comp...

Request to download
Managing Privileged Access in a Cloud-First World

Managing Privileged Access in a Cloud-First World

Release Date: 11/24/2025

Organizations are shifting to cloud-first architectures, distributed workforces, and identity-centric security models. This means that Privileged Access M...

Request to download
Introductory Guidance to AICM

Introductory Guidance to AICM

Release Date: 11/19/2025

The AI Controls Matrix (AICM) provides a foundational security and governance framework for AI service providers and customers. It helps them securely imp...

Request to download
Cloud Threat Modeling 2025

Cloud Threat Modeling 2025

Release Date: 11/17/2025

This publication enables and encourages effective threat modeling for cloud applications, services, and security decisions. It offers practical guidance to h...

Request to download
Standards-Benchmarks-Maturity

Standards-Benchmarks-Maturity

Release Date: 11/14/2025

Standardization serves as a foundational backbone that enables uniqueness and diversity to flourish within structured environments, akin to the balance of...

Request to download
Capabilities-Based Risk Assessment (CBRA) for AI Systems

Capabilities-Based Risk Assessment (CBRA) for AI Systems

Release Date: 11/12/2025

This publication introduces the Capabilities-Based Risk Assessment (CBRA), a structured, scalable approach to evaluating AI risk in enterprise environment...

Request to download
A Practitioner’s Guide to Post-Quantum Cryptography

A Practitioner’s Guide to Post-Quantum Cryptography

Release Date: 11/10/2025

Cryptographically relevant quantum computers are projected to emerge as early as the 2030s. Traditional cryptographic systems like RSA, Diffie-Hellman, an...

Request to download
AI Controls Matrix v1

AI Controls Matrix v1

Release Date: 07/09/2025

*The newest version is the AI Controls Matrix (AICM) v1.1 which can be found here.The AI Controls Matrix (AICM) is a first-of-its-kind vendor-agnostic fra...

Request to download
AICM v1.0 Implementation & Auditing Guidelines (Frameworks)

AICM v1.0 Implementation & Auditing Guidelines (Frameworks)

Release Date: 10/22/2025

The Cloud Security Alliance (CSA) AI Controls Matrix (AICM) Implementation and Auditing Guidelines Bundle provides comprehensive direction for both implem...

Request to download
Beyond the Hype: A Benchmark Study of AI Agents in the SOC

Beyond the Hype: A Benchmark Study of AI Agents in the SOC

Release Date: 10/06/2025

CSA experts conducted a benchmarking study that evaluated how AI can transform alert investigations in Security Operations Centers (SOCs). Using simulated...

Request to download
SaaS Security Capability Framework (SSCF)

SaaS Security Capability Framework (SSCF)

Release Date: 09/23/2025

The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls pr...

Request to download
MLOps Overview

MLOps Overview

Release Date: 08/27/2025

Machine learning (ML) is becoming increasingly central to business operations, making the security of ML pipelines essential rather than optional. Machine...

Request to download
Analyzing Log Data with AI Models to Meet Zero Trust Principles

Analyzing Log Data with AI Models to Meet Zero Trust Principles

Release Date: 09/15/2025

Logs are fundamental to Zero Trust. They capture critical details about user activity, device behavior, network traffic, and application access. However, ...

Request to download
The State of Cloud and AI Security 2025

The State of Cloud and AI Security 2025

Release Date: 09/09/2025

This global survey report, developed in partnership with Tenable, examines how organizations are adapting security strategies for hybrid, multi-cloud, and...

Request to download