CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
Beyond Passwords: The Role of Passkeys in Modern Web Security Release Date: 11/12/2023 Web authentication methods have evolved significantly over the years to improve security and the user experience. In the early days of the internet, usern... Request to download | |
How to Design a Secure Serverless Architecture Release Date: 10/23/2023 As businesses work to bring technology value to market faster, serverless computing is gaining adoption with developers. Serverless platforms enable devel... Request to download | |
Top Threats to Cloud Computing: Pandemic 11 Deep Dive Release Date: 10/17/2023 This publication reflects on eight recent cloud breach cases, presented as both a detailed narrative and a threat model. The threat model format provides ... Request to download | |
Data Loss Prevention in Healthcare Release Date: 10/04/2023 The rise of digital services in healthcare has made protecting medical data an ongoing challenge. Data loss may occur in several forms, including informat... Request to download | |
Machine Identity in Cybersecurity and IAM Release Date: 09/19/2023 Identity management is a crucial aspect of information security, as it ensures that only authorized individuals and entities have access to sensitive data... Request to download | |
Defining Shadow Access: The Emerging IAM Security Challenge Release Date: 09/12/2023 Shadow Access is unmonitored, unauthorized, invisible, unsafe, and generally over-permissioned cloud access. This emerging Identity and Access Management ... Request to download | |
Guidelines for CPAs Providing CSA STAR Attestation v4 Release Date: 09/07/2023 This document provides guidance for CPAs in conducting a STAR Attestation. It includes relevant information including professional requirements, competenc... Request to download | |
![]() | Release Date: 08/31/2023 The CSA Security, Trust, Assurance, and Risk (STAR) program is the most complete and largest cloud assurance program in the world that constitutes an ecos... Request to download |
FaaS Serverless Control Framework (Set) based on NIST 800-53 R5 controls Release Date: 08/30/2023 This spreadsheet provides a cybersecurity control framework for Function-as-a-Service (FaaS) serverless deployments. The framework is based on the NIST 80... Request to download | |
Identity and Access Management Glossary Release Date: 08/29/2023 The Identity and Access Management (IAM) Glossary is a reference document that aggregates and summarizes IAM-related terms and definitions. Bringing toget... Request to download | |
![]() | Data Security Working Group Charter 2023 Release Date: 08/29/2023 The Data Security working group’s goal is to provide a forum for the cybersecurity community on issues related to data security, data governance, privacy,... Request to download |
Cloud Native Application Protection Platform Survey Report Release Date: 08/23/2023 Cloud Native Application Protection Platforms (CNAPPs) have emerged as a critical category of security tooling in recent years due to the complexity of co... Request to download | |
![]() | International Standardization Council Charter 2023 Release Date: 08/23/2023 This charter lays out the scope, responsibilities, and roadmap for the International Standardization Council (ISC). The ISC actively searches mechanisms o... Request to download |
![]() | Release Date: 08/22/2023 Assurance education encompasses training and certification programs that teach individuals how to determine the effectiveness of the cybersecurity practic... Request to download |
![]() | Release Date: 08/22/2023 The STAR Assessment Portfolio is a collection of globally-recognized cloud security and privacy assessments that can be completed by cloud service provide... Request to download |
Top Threats to Cloud Computing Post Pandemic Eleven Survey Report Release Date: 08/05/2023 The CSA Top Threats Report aims to raise awareness of current cloud security risks, threats, and vulnerabilities. In this 2024 installment, we surveyed ov... Request to download | |
Security Enabled Innovation and Cloud Trends Release Date: 08/02/2023 Expel commissioned CSA to develop a survey and report to understand better the industry’s knowledge, attitudes, and opinions regarding security’s relation... Request to download | |
![]() | Security Implications of ChatGPT Release Date: 08/02/2023 This position paper provides analysis across four dimensions: How it can benefit cybersecurity, how it can benefit malicious attackers, how ChatGPT might ... Request to download |
![]() | Serverless Working Group Charter 2023 Release Date: 07/24/2023 The Serverless Working Group seeks to develop best practices to help organizations that want to run their business with a serverless computing model. Serv... Request to download |
![]() | Release Date: 07/18/2023 Zero Trust is a strategic mindset that is highly useful for organizations to adopt as part of their digital transformations and other efforts to increase ... Request to download |


-1.png)


.jpg)