Latest News
01/24/2019
Cloud Security Alliance Celebrates 10th Anniversary at CSA Summit at RSA Conference 2019
IBM, Starbucks, Turner CISOs to Give Keynote Addresses SEATTLE – RSA CONFERENCE 2019 - Jan. 24, 2019 –The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today a...
01/14/2019
New Cloud Security Alliance Study Finds Cybersecurity Incidents and Misconceptions Both Increase as Critical ERP Systems Migrate to Clouds
Seattle, WA – January 11, 2019 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications and best practices to help ensure a secure cloud computing environment, today released the findings from the first research survey on “Enterprise Re...
12/20/2018
Cloud Security Alliance, National Technology Security Coalition Release “Streamlining Vendor IT Security and Risk Assessments” Whitepaper
Report advocates for a new approach to how organizations manage risks, achieve assurance, and enable trust in the cloudSEATTLE – Dec. 20, 2018 –The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure...
12/10/2018
Cloud Security Alliance Announces 2018 Ron Knode Service Award Recipients
Volunteers recognized for dedication, efforts to furthering cloud security best practicesORLANDO – Dec. 11, 2018 –The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment...
12/10/2018
Cloud Security Alliance to Develop Holistic Cloud Incident Response Whitepaper
Singapore – 11 December, 2018 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, will be developing a holistic Cloud Incident Response Whitepaper. The framework wi...
12/04/2018
Cloud Security Alliance and OneTrust Launch Free Vendor Risk Management Tool for CSA Members
The CSA-OneTrust VRM tool is pre-populated with templates reproducing the CSA's best practices for cloud security and privacy assurance and compliance, including the Cloud Control Matrix (CCM), the Consensus Assessment Initiative Questionnaire (CAIQ) and GDPR Code of Conduct.
11/26/2018
International Effort with Collaboration Between Cloud Security Alliance and Huawei Culminated in International Standard ISO/IEC 21878
Singapore – November 26, 2018 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, is pleased to announce that the international standard ISO/IEC 21878 – Security Gu...
11/15/2018
Cloud Security Alliance’s CCSK Wins Cyber Defense Global Award for Leader Cybersecurity Training
SEATTLE, WA – Nov. 16, 2018– The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced that its Certificate of Cloud Security Knowledge (CCSK), the first cr...
10/10/2018
Cloud Security Alliance Releases Guidelines on Effectively Managing Security Service in the Cloud
Newest paper offers clearly defined security responsibilities for vendors, customers across various cloud-service modelsSINGAPORE – October 11, 2018 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a...
09/27/2018
Cloud Security Alliance Establishes New European Headquarters, GDPR Center of Excellence in Berlin
Berlin, Germany – Sept. 27, 2018 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications and best practices to help ensure a secure cloud computing environment, today announced that in response to rapid membership growth throughout the...
Press Coverage
Cybersecurity Expert Stiennon’s Latest Book: Secure Cloud Transformation
DevOps Chat: DisruptOps: SecurityOps, Disrupted – RSAC Edition
Prioritizing security in a multi-cloud world
Microsoft launches bot service for healthcare sector
To Understand IoT Security: Look to the Clouds
A guide to choosing cloud-based security services
Moving to the Hybrid Cloud? Make Sure It’s Secure by Design
Moving to the Hybrid Cloud? Make Sure It’s Secure by Design
3 Tips to Mitigate Security Risk During an ERP Cloud Migration
Former BSI official DiMaria gears up to promote Cloud Security Alliance’s STAR program
Cloud security group calls for clarity in GDPR guidance on requirements, role of regulators
Salt Security Unveils Platform to Secure APIs
Banks must decompose legacy “ball of mud” to grab cloud opportunity
Software Defined Perimeter – a Modern VPN with Traditional Challenges
How to become a cloud engineer: A cheat sheet
A cloud compliance checklist for the GDPR age
Cyber security incidents and misconceptions both increase as critical ERP systems migrate to the cloud
Report Looks at Security Misconceptions of Moving ERP to Cloud
ERP cloud migration and its complexities
Communities, GDPR Opportunities and Security in IoT
Recent Blog Posts
Rethinking Security for Public Cloud
Symantec’s Raj Patel highlights how organizations should be retooling security postures to support a modern cloud environment By Beth Stackpole, Writer, Symantec Enterprises have come a long way with cyber security, embracing robust enterprise security platforms and elevating security roles and best practices. Yet with public cloud adoption on the rise and businesses shifting to […]
Bitglass Security Spotlight: Financial Services Facing Cyberattacks
By Will Houcheime, Product Marketing Manager, Bitglass Here are the top cybersecurity stories of recent months: —Customer information exposed in Bankers Life hack—American Express India leaves customers defenseless—Online HSBC accounts breached—Millions of dollars taken from major Pakistani banks—U.S. government infrastructure accessed via DJI drones Customer information exposed in Bankers Life hack566,000 individuals have been notified […]
The 12 Most Critical Risks for Serverless Applications
By Sean Heide, CSA Research Analyst and Ory Segal, Israel Chapter Board Member When building the idea and thought process around implementing a serverless structure for your company, there are a few key risks one must take into account to ensure the architecture is gathering proper controls when speaking to security measures and how to […]
SaaS Apps and the Need for Specialized Security
By Paul Sullivan, Software Engineer, Bitglass Keeping cloud services running is a complex, multi-faceted endeavor for cloud service providers. They need to juggle adding new features, keeping their customers’ sensitive data secure, and having high uptime for their services – there is virtually no room for error. Microsoft learned about the need for high uptime […]
Deciphering DevSecOps
Security needs to be an integral part of the DevOps roadmap. Enterprise Strategy Group’s Doug Cahill shows the way By Beth Stackpole, Writer, Symantec Security has moved to the forefront of the IT agenda as organizations push forward with digital transformation initiatives. At the same time, DevOps, a methodology that applies agile and lean principles […]
Bitglass Security Spotlight: Breaches Expose Millions of Emails, Texts, and Call Logs
By Will Houcheime, Product Marketing Manager, Bitglass Here are the top cybersecurity stories of recent weeks: —773 million email accounts published on hacking forum— Unprotected FBI data and Social Security numbers found online — Millions of texts and call logs exposed on unlocked server—South Korean Defense Ministry breached by hackers—Ransomware forces City Hall of Del […]
Security Risks and Continuous Development Drive Push for DevSecOps
How the need to speed application creation and subsequent iterations has catalyzed the adoption of the DevOps philosophy By Dwight B. Davis, Writer, Symantec The sharp rise in cyber security attacks and damaging breaches in recent years has driven a new mantra among both application developers and security professionals: “Build security in from the ground […]
CCSK Success Stories: From the Financial Sector
By the CSA Education Team This is the second part in a blog series on Cloud Security Training. Today we will be interviewing an infosecurity professional working in the financial sector. John C Checco is President Emeritus for the New York Metro InfraGard Members Alliance, as well as an Information Security professional providing subject matter […]
CCM Addenda Updates for Two Additional Standards
By the CSA CCM Working Group Dear Colleagues, We’re happy to announce the publication of the updated Cloud Controls Matrix (CCM) Addenda for the following standards: — German Federal Office for Information Security (BSI) Cloud Computing Compliance Controls Catalogue (C5) — ISO/IEC 27002, ISO/IEC 27017 and ISO/IEC 27018 These CCM addenda aim to help organizations assess […]
Addressing the Skills Gap in Cloud Security Professionals
By Ryan Bergsma, Training Program Director, CSA One of the math lessons that has always stuck with me from childhood is that if you took a penny and doubled it every day for a month, it would make you a millionaire. In fact, it wouldn’t even take the whole month, you would be a millionaire on […]
Certification
CCSK: Certificate of Cloud Security Knowledge
The Certificate of Cloud Security Knowledge (CCSK) is designed to ensure that a broad range of professionals with a responsibility related to cloud computing have a demonstrated awareness of the security threats and best practices for securing the cloud.
Training
CSA Training
The Cloud Security Alliance offers training in the following three areas: CCSK training, PCI Cloud training, GRC Stack training.
Research Artifacts
CCM Mapping Workpackage Template
The 12 Most Critical Risks for Serverless Applications
The Future of Healthcare
Cloud Incident Response Charter
CCM v3.0.1 Addendum - BSI Germany C5 v1
CCM v3.0.1 Addendum - ISO 27002 27017 27018 v1.1
Enterprise Resource Planning and Cloud Adoption
Guideline on Effectively Managing Security Service in the Cloud
Streamlining Vendor IT Security and Risk Assessments
Top Threats to Cloud Computing: Deep Dive
Cloud Security Alliance Code of Conduct for GDPR Compliance
Consensus Assessments Initiative Questionnaire v3.0.1 (9-1-17 Update)
Description: The CAIQ is based upon the CCM and provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix.
Cloud Controls Matrix v3.0.1 (9-1-17 Update)
Description: The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations with the needed structure, detail and clarity relating to information security tailored to cloud computing. CCM is currently considered a de-facto standard for cloud security assurance and compliance.