Cloud 101CircleEventsBlog

STAR Registry Listing for

MongoDB Cloud Platform

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

MongoDB Cloud Platform Logo
MongoDB Cloud Platform

MongoDB Cloud Platform

The MongoDB Cloud Platform provides customers with an elastic, managed offering that includes automated provisioning and healing, comprehensive system monitoring, managed backup and restore, default security and other features that reduce operational complexity and increase application resiliency. The MongoDB Cloud Platform allows customers to remove themselves from the complexity of managing the database and related underlying infrastructure, so they can instead focus on the application and end-user experience. Additionally, MongoDB introduced additional enterprise functionality, such as advanced security, auditing, and compliance to support mission-critical enterprise workloads. The MongoDB Cloud Platform is available on three major cloud providers: Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure in North America, Europe, and Asia Pacific, providing customers broad geographic coverage across more than 65 regions globally, enabling them to leverage the benefits of different cloud platforms for different use cases and helping them avoid infrastructure vendor lock-in. The organization differentiates between a service and feature. A service is what a customer subscribes to while a feature is a piece of functionality contained within a service. The current services included in the MongoDB Cloud Platform service offerings are: MongoDB Atlas, MongoDB Realm, MongoDB Charts, and MongoDB Atlas Data Lake.

Organizations who have the CSA Trusted Cloud Provider seal demonstrate a commitment to organizational security. They are a CSA Corporate Member volunteer regularly for CSA, and have at least one staff member who has earned their CCSK.
Information about MongoDB Cloud Platform
Listed Since: 10/26/2021
Last Updated: 01/20/2023

Level 1: Self-Assessment

At level one organizations can submit one or both of the security and privacy self-assessments. These are based off of the Cloud Controls Matrix and the CSA Code of Conduct for GDPR Compliance.

Security Self-Assessment
Consensus Assessments Initiative Questionnaire v4.0.2
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).

Level 2: Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

STAR Certification: ISO/IEC 27001:2013

A technology-neutral certification leveraging the requirements of the ISO/IEC 27001:2013 management system standard together with the CSA Cloud Controls Matrix (CCM).

STAR Certification
A technology-neutral certification leveraging the requirements of the ISO/IEC 27001:2013 management system standard together with the CSA Cloud Controls Matrix (CCM).