Cloud 101CircleEventsBlog
Participate in the Peer Review of SaaS Technical Controls!

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Enterprise Authority To Operate (EATO) Auditing Guidelines

Enterprise Authority To Operate (EATO) Auditing Guidelines

Release Date: 03/05/2025

Now includes Auditing Guidelines!

Many small and mid-sized cloud-based Anything-as-a-Service (XaaS) vendors struggle to implement robust information security controls. These security gaps particularly discourage corporate customers that operate in highly regulated industries. Customers in these...
Understanding Data Security Risk Survey Report 2025

Understanding Data Security Risk Survey Report 2025

Release Date: 02/26/2025

Organizations face a rapidly changing threat landscape. The complexities of hybrid and multi-cloud environments are exposing new vulnerabilities and challenging traditional cybersecurity risk management strategies.

To better understand the current state of the industry, Thales commissioned CSA to...
Zero Trust Privacy Assessment and Guidance

Zero Trust Privacy Assessment and Guidance

Release Date: 02/18/2025

When people discuss Zero Trust, they often focus on how it can help protect data across an organization. However, they tend to forget how it can also help achieve compliant data privacy. Zero Trust thinking results in better management of identities that access sensitive data. It encourages...