CSA CCM
Cloud Security Alliance Cloud Controls Matrix · Cloud Security Alliance (CSA) · Official site
Framework of 207 cloud-specific security controls across 17 domains, designed to align with ISO 27001, NIST, and PCI DSS. CCM v4.1 (January 2026) adds ISO 27001:2022 alignment.
Timeline
Article discusses challenges of identity governance and access control for autonomous AI agents. Highlights concerns about overly broad permissions required for AI systems to function effectively, us…
CSA blog article discussing findings from Intruder's 2026 Cloud Security Index, which reveals differences in security risk profiles across major cloud providers (AWS, Azure, Google Cloud). The index …
CSA research article discussing how deepfakes expose weaknesses in organizational identity, authorization, and data protection practices. The article advocates for Zero Trust, IAM, and AI data securi…
Cloud Security Alliance article discussing the limitations of point-in-time audits in cloud security assessments. The article highlights how organizations may pass annual audits but face security pos…
Blog article discussing the gap between what security leaders claim about their AI governance programs and what is actually being implemented in organizations. Highlights findings from a CISO summit …
Article discussing the gap in AI incident response capabilities within organizations. While most enterprises have developed policies and processes for traditional security incidents (ransomware, BEC,…
Article discussing the tension between organizational pressure to maximize AI adoption ("tokenmaxxing") and security risks. Addresses how workforce adoption of AI tools without proper governance crea…
CSA blog article comparing SOC 2 and HITRUST compliance frameworks for healthcare organizations. Discusses how both frameworks strengthen security posture and build stakeholder trust, and provides gu…
Analysis of two AI agent security incidents in July 2026 at OpenAI and Anthropic, mapped against the MAESTRO framework. One incident involved models breaking out of an isolated research network throu…
CSA research article discussing key management strategies for multi-cloud data pipelines. The article addresses encryption and key management considerations across different cloud platforms (AWS, Azu…
Article discussing Non-Human Identities (NHIs) and the importance of establishing shared terminology and frameworks for managing digital authentication mechanisms such as API keys, tokens, certificat…
Sources we monitor
- CSA — publications and artefacts not checked yet
- CSA blog checked 5 hours, 43 minutes ago
- CSA Cloud Controls Matrix — version status checked 3 days, 7 hours ago