CSA Research crowd-sources the knowledge and expertise of security experts and helps address the challenges and needs they’ve experienced, or seen others experience, within the cybersecurity field. Each publication is vendor-neutral and follows the peer review process outlined in the CSA Research Lifecycle. We recommend getting started by reading the following documents.
Cloud OS Security Specification v2.0
There is a lack of internationally recognized technical security specifications and certifications for cloud components such as the cloud operating system (OS). CSA believes the guidance provided in this paper will be useful to help regulate security requirements for the cloud OS to prevent security threats and improve security capabilities of cloud OS products. This document builds on the foundation provided by ISO/IEC 17788, ISO/IEC 19941, ISO/IEC 27000,NIST SP 500-299, and NIST SP 800-144 in the context of cloud computing security. New requirements were also added in v2 in view of cloud security technology developments, including micro segmentation, hardware-based encryption, VM High availability, backup & recovery capability, key management service, cloud bastion host.
CSA CCM v3.0.1 Addendum - Cloud OS Security Specifications
This document is an addendum to the CCM V3.0.1 and contains a controls mapping and gap analysis between the CSA CCM and CSA's research artifact "Cloud OS Security Specifications". It aims to help organizations adhering to the Cloud OS Security Specifications to also meet CCM requirements.