CSAIChaptersEventsBlog
Discover the key legal, regulatory, and executive risks of AI and how to mitigate them. Register for the June 23 webinar →

Working Group

Compliance Automation Revolution

The Compliance Automation Revolution (CAR) working group focuses on automating compliance processes and controls frameworks for cloud security.
Working Group
Compliance Automation Revolution
The Compliance Automation Revolution (CAR) Working Group focuses on advancing security and compliance automation, and continuous assurance through standardized, and machine-readable approaches to controls, assessments, and governance. CAR brings together industry stakeholders to develop strategies that reduce compliance burden while improving consistency, transparency, and scalability across cloud and emerging technologies.

As part of this effort, the Security Controls Catalog operates as a CAR subgroup responsible for maintaining a canonical set of technology-agnostic security controls and control metadata. The subgroup focuses on control harmonization, regulatory mappings, machine-readable control formats, and governance of control content to support automation and interoperability across CSA frameworks and external standards.

Working Group Leadership

Andy Ruth
Andy Ruth

Andy Ruth

Content Developer, CSA

Publications in ReviewOpen Until
Zero Trust Microsegmentation GuidanceJun 10, 2026
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

Zero Trust Microsegmentation Guidance

Open Until: 06/10/2026

Microsegmentation is a foundational Zero Trust strategy that strengthens security by enforcing explicit, fine-grained commu...