Cloud 101CircleEventsBlog

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

CCM v4 - Chinese Translation

CCM v4 - Chinese Translation
Release Date: 10/26/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
The Continuous Audit Metrics Catalog

The Continuous Audit Metrics Catalog
Release Date: 10/19/2021

Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo...

Request to download
CCM v4 - Hungarian Translation

CCM v4 - Hungarian Translation
Release Date: 10/19/2021

This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate...

Request to download
The Evolution of STAR: Introducing Continuous Auditing

The Evolution of STAR: Introducing Continuous Auditing
Release Date: 09/14/2021

The CSA Continuous Auditing Certification (aka STAR Level 3) is the most rigorous assurance tier in the STAR program. Level 3 certified services providers...

Request to download
CCM v4.0 Implementation Guidelines

CCM v4.0 Implementation Guidelines
Release Date: 09/13/2021

This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM cont...

Request to download
Code of Practice for Implementing STAR Level 2

Code of Practice for Implementing STAR Level 2
Release Date: 06/23/2021

This Code of Practice shows how you can apply the CCM control set in your organization to reach STAR Level 2 third party certification/attestation and als...

Request to download
STAR Level 1: Security Questionnaire (CAIQ v4)

STAR Level 1: Security Questionnaire (CAIQ v4)
Release Date: 06/07/2021

The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,...

Request to download
STAR Enabled Solution | CAIQ-Lite v3

STAR Enabled Solution | CAIQ-Lite v3
Release Date: 05/05/2021

CSA and Whistic identified the need for a lighter-weight assessment questionnaire in order to accommodate the shift to cloud procurement models, and to enabl...

Request to download
STAR Enabled Solution | CSA - OneTrust VRM Tool

STAR Enabled Solution | CSA - OneTrust VRM Tool
Release Date: 05/05/2021

The CSA-OneTrust Vendor Risk Management (VRM) tool automates the entire vendor management lifecycle, including onboarding and offboarding vendors, triaging v...

Request to download
CSA STAR Level 3 Focus Group Charter

CSA STAR Level 3 Focus Group Charter
Release Date: 04/02/2021

The CSA STAR Level 3 Focus Group  will advise on the scope, objectives, structure, go-to-market (GTM) strategy and value proposition for STAR Level 3...

Request to download
STAR Certification Guidance Document: Auditing the Cloud Controls Matrix (CCM)

STAR Certification Guidance Document: Auditing the Cloud Controls Matrix (CCM)
Release Date: 08/05/2020

There are a number of control areas on the CCM that will each be awarded a management capability score on a scale of 1-15. This 2nd version release includes ...

Request to download
Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted]

Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted]
Release Date: 04/01/2020

Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an i...

Request to download
PLA Code of Conduct (CoC): Statement of Adherence Self-Assessment

PLA Code of Conduct (CoC): Statement of Adherence Self-Assessment
Release Date: 11/19/2019

CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f...

Request to download
Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment

Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment
Release Date: 11/19/2019

The CSA CoC for GDPR Compliance Self-Assessment is the voluntary publication of a CSP’s self-assessment results based on the requirements specified in the PL...

Request to download
Cloud Controls Matrix v3.0.1

Cloud Controls Matrix v3.0.1
Release Date: 08/03/2019

The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations...

Request to download
CCM and CAIQ v3 (Japanese Translations)

CCM and CAIQ v3 (Japanese Translations)
Release Date: 07/10/2019

This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t...

Request to download
STAR Continuous Technical Guidance

STAR Continuous Technical Guidance
Release Date: 02/27/2019

STAR Continuous specifies the necessary activities and conditions for the continuous auditing of the cloud service over a defined set of security requirement...

Request to download
CSA STAR Program & Open Certification Framework in 2016 and Beyond

CSA STAR Program & Open Certification Framework in 2016 and Beyond
Release Date: 04/12/2016

The Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR) program is the industry’s leading trust mark for cloud security. The CSA Open...

Request to download
STAR Overview PDF

STAR Overview PDF
Release Date: 04/20/2015

The CSA STAR Program is a publicly accessible registry designed to recognize the varying assurance requirements and maturity levels of providers and consumer...

Request to download
Publicizing Your STAR Certification

Publicizing Your STAR Certification
Release Date: 09/03/2013

The following guidelines will help you to apply good practice in publicizing, communicating and promoting your certification to stakeholders, including staff...

Request to download