Cloud 101CircleEventsBlog
The CCSK v5 and Security Guidance v5 are now available!

STAR Registry Listing for

Dropbox Business

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

Dropbox Business Logo

Dropbox Business

Dropbox is a smart workspace and productivity platform which offers collaboration features such as secure file sync and share, version history, deletion recovery, live support, and a suite of administrator features for better control, visibility, and management. Dropbox products described here only apply to four service plans: Dropbox Standard, Advanced, Enterprise, and Education (collectively, “the Dropbox Service Plans”). The Dropbox Service Plans includes the following products: Dropbox File Sync and Share (FSS), Dropbox Paper, Dropbox Backup, Dropbox Transfer, Dropbox Capture, Dropbox Managed Encryption Keys Service, and Dropbox Replay. The Dropbox Service Plans offer specific feature packages tailored to different organizational needs. Dropbox Education is based on Dropbox Standard, Advanced, and Enterprise, but is designed specifically for the needs of higher education institutions.

Information about Dropbox Business
Listed Since: 02/12/2016
Last Updated: 03/01/2024

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.2

CAIQ 4.0.2 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).
EU Cloud Code of Conduct (CoC)

EU Cloud CoC (Level 2)
This trustmark signifies adherence to the EU Cloud CoC through a dedicated framework and legally demonstrates GDPR compliance. Cloud Service Providers that have successfully passed the EU Cloud CoC’s evaluation process have their Compliance Mark visible in both the Code’s Public Registry as well as here in the CSA STAR Registry.

STAR Level 2

Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

Consensus Assessments Initiative Questionnaire v3.0.1

STAR Attestation
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.
Cloud Controls Matrix v3.0.1

STAR Certification
A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).