What is the CSA STAR program?
The CSA is an organization that publishes documents, best practices, and raises awareness for cloud security.
Any organization that provides cloud services should consider being compliant with the CSA STAR program. The CSA has created two documents related to cloud security, as follows:
- Cloud Control Matrix (CCM)—A cybersecurity control framework for cloud computing
- Consensus Assessment Initiative Questionnaire (CAIQ)—A set of industry-accepted security controls for IaaS/PaaS/SaaS services
The CSA has created a program called STAR that is an open registry of cloud providers who publicly share their security controls for the various service models and allow customers to download and review the vendor's compliance against industry best practices.
STAR Level 1
STAR Level 1 is a self-assessment questionnaire where cloud providers transparently share their security controls.
Customers should use a self-assessment...