Cloud 101CircleEventsBlog
Get 50% off the Cloud Infrastructure Security training bundle with code 'unlock50advantage'

STAR Registry Listing for

ForgeRock Identity Cloud

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

ForgeRock Identity Cloud

At ForgeRock , we help people safely and simply access the connected world by enabling exceptional digital experiences, no compromise security, and comprehensive functionality at any scale with simple, flexible, and rapid implementations. We do all of this with our unified identity platform — delivered as-a-service, with push-button deployments to any cloud, or into your own data center to create next-gen hybrid cloud with all the essential ForgeRock features. ForgeRock Identity Cloud gives our customers full power of a true identity platform delivered as a cloud service.

Information about ForgeRock Identity Cloud
Listed Since: 06/04/2020
Last Updated: 10/10/2023

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.2

CAIQ 4.0.2 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).
(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the self-assessment has not been updated in more than one year. We suggest contacting this organization directly to request that they submit an updated self-assessment.

STAR Level 2

Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

Consensus Assessments Initiative Questionnaire v3.0.1

STAR Attestation
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.
(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the self-assessment has not been updated in more than one year. We suggest contacting this organization directly to request that they submit an updated self-assessment.