CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
Key Management in Cloud Services This document is an updated edition of the original “Key Management in Cloud Services” paper, first published in 2020. To ensure the accuracy, completeness, ... Request to download | |
Data Security within AI Environments Release Date: 12/03/2025 As organizations adopt large language models, multi-modal AI systems, and agentic AI, traditional safeguards must evolve. This publication provides a comp... Request to download | |
Managing Privileged Access in a Cloud-First World Release Date: 11/24/2025 Organizations are shifting to cloud-first architectures, distributed workforces, and identity-centric security models. This means that Privileged Access M... Request to download | |
Release Date: 11/19/2025 The AI Controls Matrix (AICM) provides a foundational security and governance framework for AI service providers and customers. It helps them securely imp... Request to download | |
Release Date: 11/17/2025 This publication enables and encourages effective threat modeling for cloud applications, services, and security decisions. It offers practical guidance to h... Request to download | |
Capabilities-Based Risk Assessment (CBRA) for AI Systems Release Date: 11/12/2025 This publication introduces the Capabilities-Based Risk Assessment (CBRA), a structured, scalable approach to evaluating AI risk in enterprise environment... Request to download | |
A Practitioner’s Guide to Post-Quantum Cryptography Release Date: 11/10/2025 Cryptographically relevant quantum computers are projected to emerge as early as the 2030s. Traditional cryptographic systems like RSA, Diffie-Hellman, an... Request to download | |
Release Date: 07/09/2025 The AI Controls Matrix (AICM) is a first-of-its-kind vendor-agnostic framework for cloud-based AI systems. Organizations can use the AICM to develop, impl... Request to download | |
AICM Implementation & Auditing Guidelines (Frameworks) Release Date: 10/22/2025 The Cloud Security Alliance (CSA) AI Controls Matrix (AICM) Implementation and Auditing Guidelines Bundle provides comprehensive direction for both implem... Request to download | |
Release Date: 10/12/2025 This infographic offers a clear understanding of how cloud service providers and customers share responsibilities for cloud key management.Cloud key manag... Request to download | |
Beyond the Hype: A Benchmark Study of AI Agents in the SOC Release Date: 10/06/2025 CSA experts conducted a benchmarking study that evaluated how AI can transform alert investigations in Security Operations Centers (SOCs). Using simulated... Request to download | |
![]() | Release Date: 10/03/2025 The CSA Research Lifecycle graphic illustrates how research moves from proposal to approval, execution, peer review, publication, and dissemination. This res... Request to download |
SaaS Security Capability Framework (SSCF) Release Date: 09/23/2025 The SaaS Security Capability Framework (SSCF) is a new technical framework that defines configurable, consumable, and customer-facing security controls pr... Request to download | |
Release Date: 08/27/2025 Machine learning (ML) is becoming increasingly central to business operations, making the security of ML pipelines essential rather than optional. Machine... Request to download | |
Analyzing Log Data with AI Models to Meet Zero Trust Principles Release Date: 09/15/2025 Logs are fundamental to Zero Trust. They capture critical details about user activity, device behavior, network traffic, and application access. However, ... Request to download | |
The State of Cloud and AI Security 2025 Release Date: 09/09/2025 This global survey report, developed in partnership with Tenable, examines how organizations are adapting security strategies for hybrid, multi-cloud, and... Request to download | |
![]() | Security Guidance for Critical Areas of Focus in Cloud Computing v5 Release Date: 07/15/2024 Cloud computing has firmly cemented its place as the foundation of the information security industry. The Cloud Security Alliance’s Security Guidance v5 i... Request to download |
Agentic AI Identity and Access Management: A New Approach Release Date: 08/18/2025 Agentic AI is pushing the boundaries of automation, autonomy, and decision-making at machine speed. But traditional identity and access management (IAM) p... Request to download | |
Secure Agentic System Design: A Trait-Based Approach Release Date: 07/30/2025 Thanks to powerful reasoning models, AI agents are making more nuanced decisions and interacting more effectively with their environments. At the same tim... Request to download | |
![]() | Release Date: 07/28/2025 The CCM Working Group is responsible for maintaining and evolving the Cloud Security Alliance’s foundational framework for cloud security assurance, the C... Request to download |


