CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
Release Date: 11/19/2025 The AI Controls Matrix (AICM) provides a foundational security and governance framework for AI service providers and customers. It helps them securely imp... Request to download | |
Capabilities-Based Risk Assessment (CBRA) for AI Systems Release Date: 11/12/2025 This publication introduces the Capabilities-Based Risk Assessment (CBRA), a structured, scalable approach to evaluating AI risk in enterprise environment... Request to download | |
NIST CSF v2 Cloud Community Profile - Based on CCM v4 Release Date: 10/15/2024 The CSFv2.0 Cloud Community Profile aligns the Cloud Controls Matrix (CCM) version 4.0 with the Cybersecurity Framework (CSF) version 2.0 by mapping equiv... Request to download | |
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2 Release Date: 10/08/2024 The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices for securing cloud... Request to download | |
Cloud Controls Matrix and CAIQ v4 Release Date: 06/03/2024 The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s... Request to download | |
![]() | Measuring Risk and Risk Governance Release Date: 06/21/2022 Adapting to the cloud presents a new challenge to enterprises. The shared responsibility model, used to distinguish responsibilities between cloud provide... Request to download |
![]() | Roles and Responsibilities of Third Party Security Services Release Date: 11/30/2021 As we witness the broader adoption of cloud services, it is no surprise that third-party outsourced services are also on the rise. The security responsibi... Request to download |
State of Cloud Security Risk, Compliance, and Misconfigurations Release Date: 09/17/2021 Cloud misconfigurations consistently are a top concern for organizations utilizing public cloud. Such errors lead to data breaches, allow the deletion or ... Request to download | |
STAR Level 1: Security Questionnaire (CAIQ v4) Release Date: 06/07/2021 The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,... Request to download | |
![]() | APAC Data Sovereignty Working Group Charter Release Date: 01/12/2021 The proposed charter outlines the scope, responsibilities, issues to address, align and guide the working group. Request to download |
![]() | Enterprise Architecture to CCM Shared Responsibility Model Release Date: 12/18/2020 The EA-CCM Shared Responsibility Model is a companion piece with the EA-CCM Mapping. To review the EA-CCM Mapping, follow this link. (https://cloudsecuritya... Request to download |
![]() | Enterprise Architecture to CCM v3.0.1 Mapping Release Date: 12/18/2020 The EA-CCM Mapping is a companion piece with the EA-CCM Shared Responsibility Model. To review the Shared Responsibility Model, follow this link. (http://cl... Request to download |
![]() | Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted] Release Date: 04/01/2020 Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an i... Request to download |
![]() | CSA CCM v3.0.1 Addendum - Cloud OS Security Specifications Release Date: 01/29/2020 This document is an addendum to the CCM V3.0.1 and contains a controls mapping and gap analysis between the CSA CCM and CSA's research artifact "Cloud OS Sec... Request to download |
![]() | Beyond the General Data Protection Regulation (GDPR) Release Date: 11/19/2019 Data residency insights from around the world. This study reveals the top data protection concerns and strategies of more than 800 senior business profession... Request to download |
![]() | Code of Conduct (CoC): Statement of Adherence 3rd Party Certification Release Date: 11/19/2019 CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f... Request to download |
![]() | Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment Release Date: 11/19/2019 The CSA CoC for GDPR Compliance Self-Assessment is the voluntary publication of a CSP’s self-assessment results based on the requirements specified in the PL... Request to download |
![]() | Release Date: 08/03/2019 The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations... Request to download |
![]() | Cloud Security Alliance Code of Conduct for GDPR Compliance (Updated - September 2020) Release Date: 06/03/2019 The CSA Code of Conduct is designed to offer both a compliance tool for GDPR compliance and transparency guidelines regarding the level of data protection o... Request to download |
![]() | Release Date: 10/07/2013 This info sheet is for an old version of the Cloud Controls Matrix (CCM). You learn more about the latest version of the CCM and download it here: https://cl... Request to download |





![Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted]](https://cloudsecurityalliance.org/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTc3MjEsInB1ciI6ImJsb2JfaWQifX0=--846e63ecb5438faa0471cb729b8fd20217573428/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJhdXRvX29yaWVudCI6dHJ1ZSwicm90YXRlIjowLCJncmF2aXR5IjoiY2VudGVyIiwiYmFja2dyb3VuZCI6Im5vbmUiLCJyZXNpemUiOiIxMTF4MTQzIn0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--93baa008e2971cd847242da268875a6f46d313a8/CAIQ-No-Longer-Accepted.png)



