ChaptersCircleEventsBlog

Working Group

Controls Catalog

Expanding CSA's CCM, developing implementation guidelines, and maintaining a repository of controls as code.
This working group focuses on expanding and standardizing cybersecurity control objectives across various technologies, including Cloud, AI, and IoT/OT. It extends the CSA Cloud Control Matrix (CCM), ensuring interoperability with global frameworks. The group also defines control implementation guidelines, maintains a repository of technical controls as code, and enables automation to streamline compliance integration and enforcement.

  • Expands CSA’s Cloud Control Matrix (CCM) to support diverse technologies (Cloud, AI, IoT/OT).
  • Standardizes controls for interoperability across regulatory frameworks.
  • Develops vendor-agnostic and vendor-specific implementation guidelines for control adoption.
  • Defines control objectives related to cybersecurity, privacy, safety, and accountability.
  • Establishes a repository of technical controls as code to streamline compliance integration.

Working Group Leadership

Andy Ruth
Andy Ruth

Andy Ruth

Content Developer, CSA

Daniele Catteddu
Daniele Catteddu

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Larry Hughes Headshot Missing
Larry Hughes

Larry Hughes

Publications in ReviewOpen Until
Secure Agentic System Design - A Trait-Based ApproachMay 15, 2025
Managing Privileged Access in a Cloud-First WorldMay 23, 2025
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

Secure Agentic System Design - A Trait-Based Approach

Open Until: 05/15/2025

This paper addresses the security challenges unique to agentic AI systems. As AI transitions from passive tools to autonomo...

Managing Privileged Access in a Cloud-First World

Open Until: 05/23/2025

Managing privileged access has become increasingly critical due to the complexity and ubiquity of distributed IT environmen...