Cloud 101
Circle
Events
Blog

Working Group

Zero Trust

This group is working to raise awareness of best practices for operating secure Zero Trust architectures.
View Current Projects
CISO Perspectives and Progress in Deploying Zero Trust
CISO Perspectives and Progress in Deploying Zero Trust

Download

Working Group Overview

This working group aims to develop Zero Trust standards to achieve consistency for cloud, hybrid and mobile endpoint environments. The topic of group discourse include Zero Trust benefits, architecture, automation and maturity models, publication reviews, and relevant industry forums and events.

What do we discuss?

During our meetings, we typically discuss changes in the industry and collaborate on projects the group is currently working on. This group will have the following nine workstreams:

  1. Zero Trust as a Philosophy & Guiding Principles
  2. Zero Trust Organizational Strategy & Governance
  3. Pillar: Identity
  4. Pillar: Device
  5. Pillar: Network/Environment
  6. Pillar: Applications & Workload
  7. Pillar: Data
  8. Automation, Orchestration, Visibility & Analytics
  9. Zero Trust Architecture, Implementation, and Maturity Model

We welcome anyone who would like to join, even if you would like to just listen in on any calls. Interest in participation can be submitted to [email protected] describing your interests and expertise.


Drafts & Important Docs

Working Group Leadership

Daniele Catteddu
Daniele Catteddu

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Erik Johnson
Erik Johnson

Erik Johnson

Cloud Security Specialist & Senior Research Analyst

Worked for the Federal Reserve for many years and volunteered with the CSA with a focus on CCM/CAIQ V4, specifically the STA domain, and developing a comprehensive framework and guidance for defining and managing the cloud shared security responsibility model (SSRM).

I recently retired from the Federal Reserve and am now consulting with the CSA as a Senior Research Analyst with a focus on Zero Trust and Financial Services.

Linke...

Read more

John Yeoh
John Yeoh

John Yeoh

Global Vice President of Research, CSA

With over 15 years of experience in research and technology, John excels at executive-level leadership, relationship management, and strategy development. He is a published author, technologist, and researcher with areas of expertise in cybersecurity, cloud computing, information security, and next generation technology (IoT, Big Data, SecaaS, Quantum). John specializes in risk management, third party assessment, GRC, data protection, incid...

Read more

Publications in ReviewOpen Until
Telesurgery Tabletop Guide BookDec 16, 2022
Security Guidance for Critical Areas of Focus in Cloud Computing v5 - Section 2: Organization ManagementDec 18, 2022
ATT&CK & D3FEND with a CAVEATDec 23, 2022
Security Guidance for Critical Areas of Focus in Cloud Computing v5 - OutlineMar 31, 2023
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Virtual Meetings

Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can view all research meetings here.

Dec

15

Thu, December 15, 5:00am - 6:00am PST
ZT Maturity Model - AM Working Session (Updated)
See details
Zero Trust Maturity Model working group AM call. Recurs every 4 weeks and is complemented by an 8PM ET call on an alternate 4 week schedule so there's a call every two weeks (AM/PM/AM/PM...)

CSA Zero Trust Circle Community

──────────

Erik Johnson is inviting you to a scheduled Zoom meeting.

Join Zoom Meeting
https://cloudsecurityalliance.zoom.us/j/86350084101?pwd=c3h6RmNWcHFDeSs0NWRiWHltWlhudz09

Meeting ID: 863 5008 4101
Passcode: 455143
One tap mobile
+16469313860,,86350084101# US
+13017158592,,86350084101# US (Washington DC)

Dial by your location
+1 646 931 3860 US
+1 301 715 8592 US (Washington DC)
+1 309 205 3325 US
+1 312 626 6799 US (Chicago)
+1 646 558 8656 US (New York)
+1 720 707 2699 US (Denver)
+1 253 215 8782 US (Tacoma)
+1 346 248 7799 US (Houston)
+1 386 347 5053 US
+1 564 217 2000 US
+1 669 444 9171 US
+1 719 359 4580 US
Meeting ID: 863 5008 4101
Find your local number: https://cloudsecurityalliance.zoom.us/u/k5QJuNhz

Join by Skype for Business
https://cloudsecurityalliance.zoom.us/skype/86350084101



──────────

Dec

29

Thu, December 29, 5:00pm - 6:00pm PST
ZT Maturity Model - PM Working Session (Updated)
See details
ZeroTrust Architecture, Implementation, and Maturity Model working group PM call. Recurs every 4 weeks and is complemented by an 8AM ET call on an alternate 4 week schedule so there's a call every two weeks (AM/PM/AM/PM...)

CSA Zero Trust Circle Community

Join Zoom Meeting
https://cloudsecurityalliance.zoom.us/j/85967122309?pwd=YU1rS2xkVTNscC8waVh4Z3hxVTRUZz09

Meeting ID: 859 6712 2309
Passcode: 927749
One tap mobile
+12532158782,,85967122309# US (Tacoma)
+17207072699,,85967122309# US (Denver)

Dial by your location
        +1 253 215 8782 US (Tacoma)
        +1 720 707 2699 US (Denver)
        +1 346 248 7799 US (Houston)
        +1 646 558 8656 US (New York)
        +1 301 715 8592 US (Washington DC)
        +1 312 626 6799 US (Chicago)
Meeting ID: 859 6712 2309
Find your local number: https://cloudsecurityalliance.zoom.us/u/kdHb072e0m

Join by Skype for Business
https://cloudsecurityalliance.zoom.us/skype/85967122309


Jan

12

Thu, January 12, 5:00am - 6:00am PST
ZT Maturity Model - AM Working Session (Updated)
See details
Zero Trust Maturity Model working group AM call. Recurs every 4 weeks and is complemented by an 8PM ET call on an alternate 4 week schedule so there's a call every two weeks (AM/PM/AM/PM...)

CSA Zero Trust Circle Community

──────────

Erik Johnson is inviting you to a scheduled Zoom meeting.

Join Zoom Meeting
https://cloudsecurityalliance.zoom.us/j/86350084101?pwd=c3h6RmNWcHFDeSs0NWRiWHltWlhudz09

Meeting ID: 863 5008 4101
Passcode: 455143
One tap mobile
+16469313860,,86350084101# US
+13017158592,,86350084101# US (Washington DC)

Dial by your location
+1 646 931 3860 US
+1 301 715 8592 US (Washington DC)
+1 309 205 3325 US
+1 312 626 6799 US (Chicago)
+1 646 558 8656 US (New York)
+1 720 707 2699 US (Denver)
+1 253 215 8782 US (Tacoma)
+1 346 248 7799 US (Houston)
+1 386 347 5053 US
+1 564 217 2000 US
+1 669 444 9171 US
+1 719 359 4580 US
Meeting ID: 863 5008 4101
Find your local number: https://cloudsecurityalliance.zoom.us/u/k5QJuNhz

Join by Skype for Business
https://cloudsecurityalliance.zoom.us/skype/86350084101



──────────

Jan

26

Thu, January 26, 5:00pm - 6:00pm PST
ZT Maturity Model - PM Working Session (Updated)
See details
ZeroTrust Architecture, Implementation, and Maturity Model working group PM call. Recurs every 4 weeks and is complemented by an 8AM ET call on an alternate 4 week schedule so there's a call every two weeks (AM/PM/AM/PM...)

CSA Zero Trust Circle Community

Join Zoom Meeting
https://cloudsecurityalliance.zoom.us/j/85967122309?pwd=YU1rS2xkVTNscC8waVh4Z3hxVTRUZz09

Meeting ID: 859 6712 2309
Passcode: 927749
One tap mobile
+12532158782,,85967122309# US (Tacoma)
+17207072699,,85967122309# US (Denver)

Dial by your location
        +1 253 215 8782 US (Tacoma)
        +1 720 707 2699 US (Denver)
        +1 346 248 7799 US (Houston)
        +1 646 558 8656 US (New York)
        +1 301 715 8592 US (Washington DC)
        +1 312 626 6799 US (Chicago)
Meeting ID: 859 6712 2309
Find your local number: https://cloudsecurityalliance.zoom.us/u/kdHb072e0m

Join by Skype for Business
https://cloudsecurityalliance.zoom.us/skype/85967122309


Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

Telesurgery Tabletop Guide Book

Open Until: 12/16/2022

The purpose of this guidebook is to assist healthcare providers in planning and facilitating a discussion and evaluation of...

Security Guidance for Critical Areas of Focus in Cloud Computing v5 - Section 2: Organization Management

Open Until: 12/18/2022

With the growing amount of cloud applications that customers are using, it is as important as ever to get a handle on the m...

ATT&CK & D3FEND with a CAVEAT

Open Until: 12/23/2022

Cybersecurity practitioners continue to search for adversarial threat models to drive system assessment and operational ana...

Security Guidance for Critical Areas of Focus in Cloud Computing v5 - Outline

Open Until: 03/31/2023

The proposed outline for the Cloud Security Alliance Security Guidance for Critical Areas of Focus in Cloud Computing v5 is...