Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

STAR-Enabled Solution:

Whistic

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

Whistic Logo

Whistic

Whistic simplifies how businesses assess, publish, and share security documentation with customers and vendors. The Whistic Vendor Security Network accelerates the vendor assessment process by enabling buyers to access and evaluate a vendor’s Whistic Profile and create trusted connections that last well beyond the initial point-in-time assessment. Additionally, Whistic facilitates zero-touch assessments via the Whistic Trust Catalog which contains security information for more than 35,000 businesses.

Organizations who have the CSA Trusted Cloud Provider seal demonstrate a commitment to organizational security. They are a CSA Corporate Member volunteer regularly for CSA, and have at least one staff member who has earned their CCSK.
Information about Whistic
Listed Since: 11/04/2022
Last Updated: 11/04/2022

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.2

CAIQ 4.0.2 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).
(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the self-assessment has not been updated in more than one year. We suggest contacting this organization directly to request that they submit an updated self-assessment.