Cloud 101CircleEventsBlog
CSA's Continuous Audit Metrics Working Group is expanding! Help shape the future of cloud assurance.
Cloud Controls Matrix and CAIQ v4
Cloud Controls Matrix and CAIQ v4

Download

This CAIQ group has been merged with the CCM Working Group

Lack of security control transparency is a leading inhibitor to the adoption of cloud services. The CSA Consensus Assessments (CAIQ) working group was launched to perform research, create tools and create industry partnerships to enable cloud computing assessments. 

The CAIQ is used by CSPs to submit to the CSA STAR Registry.
The Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. offers an industry-accepted way to document which security controls exist in IaaS, PaaS, and SaaS services, providing security control transparency. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM). It helps cloud customers to gauge the security posture of prospective cloud service providers and determine if their cloud services are suitably secure. The CAIQ is used by CSPs to submit to the CSA STAR Registry.

CAIQEnterprise ArchitectureConsensus AssessmentsCCAKCloud Component SpecificationsCloud Controls MatrixSecurity Guidance

Discuss this topic in Circle

View discussion community
Press MentionSourceDate
Startups’ Guide to Security QuestionnairesSecurity BoulevardJuly 21, 2023
CISOs Beware of The Rising Risk of Supply Chain AttacksSpiceworksNovember 22, 2023
View all

Cloud Security Research for Vendor Assessments

CSA Research crowd-sources the knowledge and expertise of security experts and helps address the challenges and needs they’ve experienced, or seen others experience, within the cybersecurity field. Each publication is vendor-neutral and follows the peer review process outlined in the CSA Research Lifecycle. We recommend getting started by reading the following documents.

Cloud Controls Matrix and CAIQ v4

Cloud Controls Matrix and CAIQ v4

The Consensus Assessments Initiative Questionnaire (CAIQ) provides a set of “yes or no” questions based on the security controls in the CCM that a cloud consumer or auditor may wish to ask a cloud provider. You can now download version 4 for the CCM and CAIQ together. 

CAIQ-Lite

CAIQ-Lite

CSA and Whistic identified the need for a lighter-weight assessment questionnaire in order to accommodate the shift to cloud procurement models, and to enable cybersecurity professionals to more easily engage with cloud vendors. CAIQ-Lite was developed to meet the demands of an increasingly fast-paced cybersecurity environment where adoption is becoming paramount when selecting a vendor security questionnaire. CAIQ-Lite contains 71 questions compared to the 295 found in the CAIQ, while maintaining representation of 100% of the original 16 control domains present in the Cloud Controls Matrix (CCM) 3.0.1.

Webinars

CCAK Webinar Series: Module 1 - Cloud Governance
CCAK Webinar Series: Module 1 - Cloud Governance

August 4 | Virtual

Learn more

CCAK Webinar Series: Module 2
CCAK Webinar Series: Module 2

August 11 | TBD

Learn more

CCAK Webinar Series: Modules 4 & 9
CCAK Webinar Series: Modules 4 & 9

August 18 | Online

Learn more

CCAK Webinar Series: Modules 3 & 7
CCAK Webinar Series: Modules 3 & 7

August 18 | Online

Learn more

Blog Posts

The CSA Cloud Controls Matrix and Consensus Assessment Initiative Questionnaire: FAQs
CSA STAR CCM Lite
CSA STAR Certifications: What are They?