Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

STAR Registry Listing for

Black Duck, Polaris & Managed Service Portal

Founded in 2013 by the Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices.

Black Duck, Polaris & Managed Service Portal

Black Duck, Polaris & Managed Service Portal

Managed Services Portal:
SIG offers software application security assessments and a variety of IP penetration tests. These service offerings can be facilitated through a customer facing portal, the Managed Services Portal (MSP). The MSP allows SIG customers to request these services on demand.

Polaris:
Polaris is a hosted solution which facilitates static analysis using SIG’s static analysis product, Coverity. Coverity static application security testing (SAST), is highly accurate, supports thousands of developers, and quickly analyzes large software development projects exceeding 100 million lines of code. By offering integrations with key development tools and CI/CD systems, Coverity enables AppSec testing at DevOps speed and has helped thousands of organizations get to market faster with reduced cost and risk.

Black Duck:
Black Duck Software Composition Analysis is a hosted solution which provides a comprehensive software composition analysis (SCA) solution for managing security, quality, and IP license compliance risk that comes from the use of open source and third-party code in applications and containers. Black Duck gives organizations unmatched visibility into third-party code, enabling them to control it across their software supply chain and throughout the application’s life cycle.

Information about Black Duck, Polaris & Managed Service Portal
Listed Since: 07/29/2021
Last Updated: 12/05/2022

STAR Level 1

Self-Assessment & Partner-Provided

Consensus Assessments Initiative Questionnaire v4.0.2

CAIQ 4.0.2 Self-assessment
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the CSA Cloud Controls Matrix (CCM).
(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the self-assessment has not been updated in more than one year. We suggest contacting this organization directly to request that they submit an updated self-assessment.