ChaptersCircleEventsBlog
Improve the quality of your STAR Level 1 self-assessment by submitting to Valid-AI-ted →

Working Group

Cloud Component Specifications

In order to address the gap in industry best practices for cloud components this working group proposes to develop internationally recognized technical security specifications for cloud components.
Cloud OS Security Specification v2.0
Cloud OS Security Specification v2.0

Download

Cloud Component Specifications
Working Group Overview

In order to address the gap in industry best practices for cloud components, this working group proposes to develop internationally recognized technical security specifications for cloud components.


Drafts & Important Docs


Working Group Leadership

Frank Guanco
Frank Guanco

Frank Guanco

Operations Director, CSA

Publications in ReviewOpen Until
AICM mapping to NIST 600-1Jun 16, 2025
Analyzing Log Data with AI ModelsJun 20, 2025
Agentic AI Identity and Access Management: A New ApproachJul 03, 2025
Fully Homomorphic Encryption to CCM v4.0.1 MappingJul 10, 2025
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

AICM mapping to NIST 600-1

Open Until: 06/16/2025

The Cloud Security Alliance (CSA) invites public peer review of its draft mapping between the AI Controls Matrix (AICM) and NIST 600-1. This initiative suppo...

Analyzing Log Data with AI Models

Open Until: 06/20/2025

In a Zero Trust environment, logs play a critical role in the visibility and analytics cross-cutting capability. Architectu...

Agentic AI Identity and Access Management: A New Approach

Open Until: 07/03/2025

Traditional Identity and Access Management (IAM) systems, primarily designed for human users or static machine identities v...

Fully Homomorphic Encryption to CCM v4.0.1 Mapping

Open Until: 07/10/2025

We are seeking input from industry and legal professionals with experience in cloud security and policy, and comment from F...