Open Certification Framework

Latest ResearchJoin Group
Streamlining Vendor IT Security and Risk Assessments
Streamlining Vendor IT Security and Risk Assessments

Download

Join this working group
Open Certification Framework
The Cloud Security Alliance has identified gaps within the IT ecosystem that are inhibiting market adoption of secure and reliable cloud services. Consumers do not have simple, cost effective ways to evaluate and compare their providers’ resilience, data protection and privacy capabilities and service portability. 

The CSA Open Certification Framework (OCF) is an industry initiative to allow global, trusted independent evaluation of cloud providers. It is a program for flexible, incremental and multi-layered cloud provider certification and/or attestation according to the Cloud Security Alliance’s industry leading security guidance and control framework. The program will integrate with popular third-party assessment and attestation statements developed within the public accounting community to avoid duplication of effort and cost.

As a critical step toward securing the digital foundation of our economy, we recommend that businesses reduce their reliance on proprietary, in-house security assessment programs related to cloud computing. Instead, we recommend leveraging the CSA’s Security, Trust & Assurance Registry (STAR) program and its associated assurance tools as core components of vetting and procuring cloud providers and services. We believe this emphasis on consistent, uniform cloud security standards will increase the security baseline for all participants in our economy.

View the CSA STAR Registry 

Open Certification FrameworkEnterprise ArchitectureSecurity GuidanceCAIQCCAKSTAR

The CSA Open Certification working group is an industry initiative to allow global, accredited, trusted certification of cloud providers.

Next Meeting

No Meetings Currently Scheduled



Working Group Leadership

Andrew Williams Headshot

Andrew Williams

Ryan Mackie Headshot

Ryan Mackie

Ronald Tse Headshot

Ronald Tse

Andreas Fuchsberger Headshot

Andreas Fuchsberger

John DiMaria Headshot

John DiMaria

Daniele Catteddu Headshot

Daniele Catteddu

Join this working group

Open Certification Framework

CSA Research crowd-sources the knowledge and expertise of security experts and helps address the challenges and needs they’ve experienced, or seen others experience, within the cybersecurity field. Each publication is vendor-neutral and follows the peer review process outlined in the CSA Research Lifecycle. We recommend getting started by reading the following documents.

Streamlining Vendor IT Security and Risk Assessments

Streamlining Vendor IT Security and Risk Assessments

Vendor security assessments generally consume a lot of time and cost while resulting in a limited understanding of a vendor’s risk profile. These inefficient assessments have trouble keeping up with the growing ecosystem of technology vendors—and especially the increased reliance on cloud security vendors. In such an ecosystem, technology leaders must redouble their efforts to improve vendor security oversight, risk assessment, and risk management activities. In this paper, the Cloud Security Alliance (CSA) and the National Technology Security Coalition (NTSC) are advocating for a new approach to how organizations manage risks, achieve assurance, and enable trust in the cloud.

CSA STAR Program & Open Certification Framework in 2016 and Beyond

CSA STAR Program & Open Certification Framework in 2016 and Beyond

The Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR) program is the industry’s leading trust mark for cloud security. The CSA Open Certification Framework (OCF) is a program for flexible, incremental and multi-layered CSP certifications according to the CSA’s industry leading security guidance. The OCF/STAR program comprises a global cloud computing assurance framework with a scope of capabilities, flexibility of execution, and completeness of vision that far exceeds the risk and compliance objectives of other security audit and certification programs.

Open Certification Framework Working Group Charter

Open Certification Framework Working Group Charter

The CSA Open Certification Framework (OCF) is an industry initiative to allow global, trusted independent evaluation of cloud providers. It is a program for flexible, incremental and multi-layered cloud provider certification and/or attestation according to the Cloud Security Alliance’s industry leading security guidance and control framework. 

Blog Posts

Using CSA STAR to Improve Cloud Governance and Compliance
Continuous Auditing and Continuous Certification
Using SOC Reports for Cloud Security and Privacy