CINXE.COM
DevSecOps Working Group | CSA
<!DOCTYPE html><html><head><title>DevSecOps Working Group | CSA</title> <meta name="description" content="This group defines best practices and provides guidance to help teams implement security into their DevOps process."> <link rel="canonical" href="https://cloudsecurityalliance.org/research/working-groups/devsecops"> <link rel="image_src" href="/assets/social-share/facebook-429f9d45f1c2afbf16c63ff940668c3dfc1e7ed3f9155f98eab6691bf6b5fd82.jpg"> <meta property="og:locale" content="en"> <meta property="og:type" content="website"> <meta property="og:title" content="DevSecOps Working Group | CSA"> <meta property="og:description" content="This group defines best practices and provides guidance to help teams implement security into their DevOps process."> <meta property="og:url" content="https://cloudsecurityalliance.org/research/working-groups/devsecops"> <meta property="og:image" content="/assets/social-share/facebook-429f9d45f1c2afbf16c63ff940668c3dfc1e7ed3f9155f98eab6691bf6b5fd82.jpg"> <meta name="twitter:card" content="summary"> <meta name="twitter:title" content="DevSecOps Working Group | CSA"> <meta name="twitter:description" content="This group defines best practices and provides guidance to help teams implement security into their DevOps process."> <meta name="twitter:site" content="@cloudsa"> <meta name="twitter:creator" content="@cloudsa"> <meta name="twitter:image" content="/assets/social-share/facebook-429f9d45f1c2afbf16c63ff940668c3dfc1e7ed3f9155f98eab6691bf6b5fd82.jpg"><meta name="csrf-param" content="authenticity_token" /> <meta name="csrf-token" content="Iq4ET5EM76yhFFO_tR40ipjZYJjHJDA_EMjsa90k2SEO5UuoRWtIbPBYgXcI4oykcJPhRTNxyhvSbyh0fKRaFA" /><meta name="csp-nonce" /><meta content="text/html;charset=utf-8" http-equiv="Content-type" /><meta content="width=device-width, initial-scale=1" name="viewport" /><meta content="IE=edge,chrome=1" http-equiv="X-UA-Compatible" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/favicon/favicon.ico" rel="Shortcut Icon" type="image/x-icon" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/iphone.png" rel="apple-touch-icon" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-57x57.png" rel="apple-touch-icon" sizes="57x57" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-60x60.png" rel="apple-touch-icon" sizes="60x60" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-72x72.png" rel="apple-touch-icon" sizes="72x72" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-76x76.png" rel="apple-touch-icon" sizes="76x76" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-114x114.png" rel="apple-touch-icon" sizes="114x114" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-120x120.png" rel="apple-touch-icon" sizes="120x120" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-144x144.png" rel="apple-touch-icon" sizes="144x144" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-152x152.png" rel="apple-touch-icon" sizes="152x152" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/apple-touch-icons/apple-touch-icon-180x180.png" rel="apple-touch-icon" sizes="180x180" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/favicon/favicon-16x16.png" rel="icon" sizes="16x16" type="image/png" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/favicon/favicon-32x32.png" rel="icon" sizes="32x32" type="image/png" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/favicon/favicon-96x96.png" rel="icon" sizes="96x96" type="image/png" /><link href="https://assets.cloudsecurityalliance.org/legacy/local-cdn/global/site/android-chrome-icons/android-chrome-192x192.png" rel="icon" sizes="192x192" type="image/png" /><link rel="stylesheet" href="/assets/application-05bb97dee3bde9273f3ea4ad89383d77da30c6ea8d3bcd824987c3524b12507b.css" data-turbolinks-track="reload" /><link href="https://fonts.googleapis.com/css?family=Open+Sans%3A300italic%2C400italic%2C600italic%2C700italic%2C800italic%2C400%2C300%2C600%2C700%2C800&amp;#038;ver=1.0" media="all" rel="stylesheet" type="text/css" /><link href="https://fonts.googleapis.com/css?family=Titillium+Web%3A400%2C600&amp;#038;ver=1.0" media="all" rel="stylesheet" type="text/css" /><link href="https://use.typekit.net/tpr8qgx.css" rel="stylesheet" /><script>window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} gtag('consent', 'default', { 'ad_storage': 'denied', 'ad_user_data': 'denied', 'ad_personalization': 'denied', 'analytics_storage': 'denied', }); window.gtag = gtag;</script><!-- Google Tag Manager Head Tag--><script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({"gtm.start": new Date().getTime(),event:"gtm.js"});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!="dataLayer"?"&l="+l:"";j.async=true;j.src= "https://www.googletagmanager.com/gtm.js?id=" +i+dl;f.parentNode.insertBefore(j,f); })(window,document,"script","dataLayer",'GTM-WGMWDNB');</script><!-- End Google Tag Manager Head Tag --><script src="/assets/application-ba4225ec596eebba3745394b97bb2fd7e5bcbe822dfa1440400acee76232d3fd.js" data-turbo-track="reload"></script><script async="" defer="" src="https://www.google.com/recaptcha/api.js?render=explicit"></script><script>window.addEventListener("turbo:before-render", function () { window.zEACLoaded = undefined; // this is the "hidden" global var that zendesk uses to check if it's loaded its widget yet });</script></head><body class="csa"><!-- Google Tag Manager Body Tag (noscript) --> <noscript> <iframe src="https://www.googletagmanager.com/ns.html?id=GTM-WGMWDNB" height="0" width="0" style="display:none;visibility:hidden"> </iframe> </noscript> <!-- End Google Tag Manager Body Tag (noscript) --> <style>.callout-banner { text-align: center; position: relative; font-weight: 300; font-size: 12px; } @media screen and (max-width: 1110px) { .callout-banner { margin-top: 40px; } }</style><style>.app_notification a { color: white !important; text-decoration: underline; }</style><header class="csa-c-layout-header"><div class="o-area" id="quicklinks"><div class="c-quicklinks"><div class="o-container"><a class="c-quicklink" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Cloud 101 - https://cloudsecurityalliance.org/cloud-newbie"});" href="https://cloudsecurityalliance.org/cloud-newbie">Cloud 101</a><a class="c-quicklink" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Circle - https://circle.cloudsecurityalliance.org/"});" rel="noopener" target="_blank" href="https://circle.cloudsecurityalliance.org/">Circle</a><a class="c-quicklink" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Events - https://cloudsecurityalliance.org/events/"});" href="https://cloudsecurityalliance.org/events/">Events</a><a class="c-quicklink" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Blog - https://cloudsecurityalliance.org/blog/"});" href="https://cloudsecurityalliance.org/blog/">Blog</a><form class="c-quicklink" method="post" action="/auth/auth0"><button style="text-transform: uppercase;" data-turbo="false" type="submit">Sign in or Sign Up</button><input type="hidden" name="authenticity_token" value="cM6tCtAoiGfzZHp9rT1LolE7TI9fN9w5oDtS-hu2juXDkF0gxdgQBuPRkXcSqLenvRpQ4b8EukiVpqxH3ArQYg" autocomplete="off" /></form></div></div></div><div id="megamenu"><div class="c-megamenu"><div class="o-container"><div class="o-grid"><a class="c-megamenu__logo o-grid__cell o-grid__cell--width-15@xsmall" href="/"><img src="/assets/CSA-logo-RGB-a0a3855889ad836fa585d60f6caf8d619f241d43904c304c2f64284127fe9bf3.svg" /></a><div class="c-megamenu__categories o-grid__cell o-grid__cell--width-75@xsmall"><div class="c-megamenu__category" data-target="#membership-nav"><div class="c-megamenu__anchor">Membership</div><div class="c-megamenu__category-content" id="membership-nav"><div class="o-container"><div class="o-grid o-grid--small-fit o-grid--medium-fit o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Membership Benefits - /membership/"});" href="/membership/">Membership Benefits</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Our Member Community - /membership/current/"});" href="/membership/current/">Our Member Community</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Get Involved - /membership/get-involved/"});" href="/membership/get-involved/">Get Involved</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Become a Member - /membership/contact/"});" href="/membership/contact/">Become a Member</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Member-Exclusive Programs</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Enabled Solutions - /star/registry/star-enabled-solutions/"});" href="/star/registry/star-enabled-solutions/">STAR Enabled Solutions</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trusted Cloud Consultant - /trusted-cloud-consultant/registry/"});" href="/trusted-cloud-consultant/registry/">Trusted Cloud Consultant</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trusted Cloud Provider - /trusted-cloud-provider/"});" href="/trusted-cloud-provider/">Trusted Cloud Provider</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certified STAR Auditors - /star/certified-star-auditors/"});" href="/star/certified-star-auditors/">Certified STAR Auditors</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Member Portal - https://cloudsecurityalliance.my.site.com"});" href="https://cloudsecurityalliance.my.site.com">Member Portal</a></div></div></div></div></div></div></div><div class="c-megamenu__category" data-target="#star-program-nav"><div class="c-megamenu__anchor">STAR Program</div><div class="c-megamenu__category-content" id="star-program-nav"><div class="o-container"><div class="o-grid o-grid--small-fit o-grid--medium-fit o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Home - /star/"});" href="/star/">STAR Home</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Registry - /star/registry/"});" data-turbo="false" href="/star/registry/">STAR Registry</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Submit to Registry - /star/submit/"});" href="/star/submit/">Submit to Registry</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Provide Feedback - /star/feedback/"});" href="/star/feedback/">Provide Feedback</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certified STAR Auditors - /star/certified-star-auditors/"});" href="/star/certified-star-auditors/">Certified STAR Auditors</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Enabled Solutions - /star/star-enabled-solutions/overview/"});" href="/star/star-enabled-solutions/overview/">STAR Enabled Solutions</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Stay compliant in the cloud</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CCAK Training - /education/ccak/"});" href="/education/ccak/">CCAK Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Lead Auditor Training - /education/star-lead-auditor-training/"});" href="/education/star-lead-auditor-training/">STAR Lead Auditor Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Training for Government Agencies - /education/gsa-schedule/"});" href="/education/gsa-schedule/">Training for Government Agencies</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Governance, Risk & Compliance Tools</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud Controls Matrix (CCM) - /research/cloud-controls-matrix/"});" href="/research/cloud-controls-matrix/">Cloud Controls Matrix (CCM)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Consensus Assessment Initiative Questionnaire (CAIQ) - /research/cloud-controls-matrix/"});" href="/research/cloud-controls-matrix/">Consensus Assessment Initiative Questionnaire (CAIQ)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"EU Cloud Code of Conduct - /gdpr/eu-cloud-code-of-conduct/"});" href="/gdpr/eu-cloud-code-of-conduct/">EU Cloud Code of Conduct</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Level 1 - /star/registry/?level=1"});" data-turbo="false" href="/star/registry/?level=1">STAR Level 1</a></div><div class="c-megamenu__item-description">At level one organizations submit a self-assessment.</div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"View companies at level one - /star/registry/?level=1"});" data-turbo="false" href="/star/registry/?level=1">View companies at level one</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Learn about level one - /star/#tab_levelOne"});" href="/star/#tab_levelOne">Learn about level one</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Level 2 - /star/registry/?level=2"});" data-turbo="false" href="/star/registry/?level=2">STAR Level 2</a></div><div class="c-megamenu__item-description">At level two organizations earn a certification or third-party attestation.</div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"View companies at level two - /star/registry/?level=2"});" data-turbo="false" href="/star/registry/?level=2">View companies at level two</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Learn about level two - /star/#tab_levelTwo"});" href="/star/#tab_levelTwo">Learn about level two</a></div></div></div></div></div></div></div><div class="c-megamenu__category" data-target="#certificates-training-nav"><div class="c-megamenu__anchor">Certificates & Training</div><div class="c-megamenu__category-content" id="certificates-training-nav"><div class="o-container"><div class="o-grid o-grid--small-fit o-grid--medium-fit o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Online Education Platforms</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Knowledge Center - https://knowledge.cloudsecurityalliance.org"});" href="https://knowledge.cloudsecurityalliance.org">Knowledge Center</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CSA Exams - https://exams.cloudsecurityalliance.org"});" href="https://exams.cloudsecurityalliance.org">CSA Exams</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Events - /events/"});" href="/events/">Events</a></div><div class="c-megamenu__item-description">Learn and network while you earn CPE credits.</div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Virtual Events \u0026 Webinars - /events/virtual-and-webinars/"});" data-turbo="false" href="/events/virtual-and-webinars/">Virtual Events & Webinars</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Event Sponsorships - /sponsor/"});" href="/sponsor/">Event Sponsorships</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificates - /education/"});" href="/education/">Certificates</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificate of Cloud Security Knowledge (CCSK) - /education/ccsk/"});" href="/education/ccsk/">Certificate of Cloud Security Knowledge (CCSK)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificate of Cloud Auditing Knowledge (CCAK) - /education/ccak/"});" href="/education/ccak/">Certificate of Cloud Auditing Knowledge (CCAK)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificate of Competence in Zero Trust (CCZT) - /education/cczt/"});" href="/education/cczt/">Certificate of Competence in Zero Trust (CCZT)</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Digital Badges - /education/digital-badges/"});" href="/education/digital-badges/">Digital Badges</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trainings - /education/"});" href="/education/">Trainings</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud Infrastructure Security Training - /education/cloud-infrastructure-security-training"});" href="/education/cloud-infrastructure-security-training">Cloud Infrastructure Security Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Lead Auditor Training - /education/star-lead-auditor-training/"});" href="/education/star-lead-auditor-training/">STAR Lead Auditor Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Advanced Cloud Security Practitioner (ACSP) Training - /education/advanced-cloud-security-practitioner-training"});" href="/education/advanced-cloud-security-practitioner-training">Advanced Cloud Security Practitioner (ACSP) Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CCSK Train the Trainer - /education/train-the-trainer/"});" href="/education/train-the-trainer/">CCSK Train the Trainer</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Training Network - /education/partner#become_partner"});" href="/education/partner#become_partner">Training Network</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Become an Instructor - /education/instructors/"});" href="/education/instructors/">Become an Instructor</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Become a Training Partner - /education/training-partners/"});" href="/education/training-partners/">Become a Training Partner</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Specialized Training Options</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Train my entire team - /education/business/"});" href="/education/business/">Train my entire team</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Training for Government Agencies - /education/gsa-schedule/"});" href="/education/gsa-schedule/">Training for Government Agencies</a></div></div></div></div></div></div></div><div class="c-megamenu__category" data-target="#research-nav"><div class="c-megamenu__anchor">Research</div><div class="c-megamenu__category-content" id="research-nav"><div class="o-container"><div class="o-grid o-grid--small-fit o-grid--medium-fit o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CSA Research - /research/"});" href="/research/">CSA Research</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Latest Research - /research/artifacts"});" href="/research/artifacts">Latest Research</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Working Groups - /research/working-groups/"});" href="/research/working-groups/">Working Groups</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Chapters - /chapters/"});" href="/chapters/">Chapters</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Open Peer Reviews - /research/contribute#peer-reviews"});" href="/research/contribute#peer-reviews">Open Peer Reviews</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Research Topics - /research/topics"});" href="/research/topics">Research Topics</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Strategic Initiatives</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Safety Initiative - /research/working-groups/artificial-intelligence/"});" href="/research/working-groups/artificial-intelligence/">AI Safety Initiative</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Zero Trust Advancement Center - /zt/"});" href="/zt/">Zero Trust Advancement Center</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CxO Trust - /cxo-trust/"});" href="/cxo-trust/">CxO Trust</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trusted Cloud Consultant - /trusted-cloud-consultant/"});" href="/trusted-cloud-consultant/">Trusted Cloud Consultant</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"FinCloud Security - /fincloud-security"});" href="/fincloud-security">FinCloud Security</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Thought Leadership</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CloudBytes Webinars - /events/virtual-and-webinars/?event_kind=Webinar"});" data-turbo="false" href="/events/virtual-and-webinars/?event_kind=Webinar">CloudBytes Webinars</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Blog - /blog/"});" href="/blog/">Blog</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Getting Started with CSA Research</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud security best practices - /research/guidance/"});" href="/research/guidance/">Cloud security best practices</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Assess your cloud compliance - /research/cloud-controls-matrix/"});" href="/research/cloud-controls-matrix/">Assess your cloud compliance</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Security questionnaire for vendors - /artifacts/star-level-1-security-questionnaire-caiq-v4/"});" href="/artifacts/star-level-1-security-questionnaire-caiq-v4/">Security questionnaire for vendors</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Top threats to cloud computing - /research/working-groups/top-threats/"});" href="/research/working-groups/top-threats/">Top threats to cloud computing</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud Security Glossary - /cloud-security-glossary"});" href="/cloud-security-glossary">Cloud Security Glossary</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Awards & Recognition</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Juanita Koilpillai Awards - /research/juanita-koilpillai/service-award/"});" href="/research/juanita-koilpillai/service-award/">Juanita Koilpillai Awards</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Research Fellows - /research/fellowship#fellows"});" href="/research/fellowship#fellows">Research Fellows</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Critical Topics</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Safety Initiative - /research/working-groups/artificial-intelligence"});" href="/research/working-groups/artificial-intelligence">AI Safety Initiative</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Technology and Risk - /research/working-groups/ai-technology-and-risk"});" href="/research/working-groups/ai-technology-and-risk">AI Technology and Risk</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Governance \u0026 Compliance - /research/working-groups/ai-governance-compliance"});" href="/research/working-groups/ai-governance-compliance">AI Governance & Compliance</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Controls - /research/working-groups/ai-controls"});" href="/research/working-groups/ai-controls">AI Controls</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Organizational Responsibilities - /research/working-groups/ai-organizational-responsibilities"});" href="/research/working-groups/ai-organizational-responsibilities">AI Organizational Responsibilities</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Enterprise Architecture - /research/working-groups/enterprise-architecture"});" href="/research/working-groups/enterprise-architecture">Enterprise Architecture</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Blockchain - /research/working-groups/blockchain"});" href="/research/working-groups/blockchain">Blockchain</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Zero Trust - /research/working-groups/zero-trust"});" href="/research/working-groups/zero-trust">Zero Trust</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"DevSecOps - /research/working-groups/devsecops"});" href="/research/working-groups/devsecops">DevSecOps</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Top Threats - /research/working-groups/top-threats"});" href="/research/working-groups/top-threats">Top Threats</a></div></div></div></div></div></div></div></div><div class="o-grid__cell c-megamenu__search"><form action="/search" class="input-pair u-mb0" method="get" role="search"><label><span class="u-screen-reader">Search for:</span></label><input autocomplete="off" class="c-megamenu__search-input" name="s" placeholder="Search CSA resources, tools, research publications and more…" title="Search for:" type="text" value="" /><button class="c-button c-button--secondary"><i class="fas fa-search"></i></button><div class="c-button c-button--expand"><i class="fas fa-search"></i></div><div class="c-button c-button--close"><div class="i fas fa-times"></div></div></form></div></div></div></div></div><div id="megamenu_mobile"><div class="c-mobile-menu"><div class="c-mobile-menu__head"><a class="c-megamenu__logo" href="/"><img src="/assets/CSA-logo-RGB-a0a3855889ad836fa585d60f6caf8d619f241d43904c304c2f64284127fe9bf3.svg" /></a><span class="c-mobile-menu__search"><a style="color: black" href="/search"><i class="fas fa-search"></i></a></span><span class="c-mobile-menu__hamburger"><i class="fas fa-bars"></i></span></div><div class="o-container c-mobile-menu__body"><div class="c-megamenu__categories"><div class="c-megamenu__category" data-target="#mobile-membership-nav"><div class="c-megamenu__anchor">Membership</div><div class="c-megamenu__category-content" id="mobile-membership-nav"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Membership Benefits - /membership/"});" href="/membership/">Membership Benefits</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Our Member Community - /membership/current/"});" href="/membership/current/">Our Member Community</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Get Involved - /membership/get-involved/"});" href="/membership/get-involved/">Get Involved</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Become a Member - /membership/contact/"});" href="/membership/contact/">Become a Member</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Member-Exclusive Programs</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Enabled Solutions - /star/registry/star-enabled-solutions/"});" href="/star/registry/star-enabled-solutions/">STAR Enabled Solutions</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trusted Cloud Consultant - /trusted-cloud-consultant/registry/"});" href="/trusted-cloud-consultant/registry/">Trusted Cloud Consultant</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trusted Cloud Provider - /trusted-cloud-provider/"});" href="/trusted-cloud-provider/">Trusted Cloud Provider</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certified STAR Auditors - /star/certified-star-auditors/"});" href="/star/certified-star-auditors/">Certified STAR Auditors</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Member Portal - https://cloudsecurityalliance.my.site.com"});" href="https://cloudsecurityalliance.my.site.com">Member Portal</a></div></div></div></div></div><hr /><div class="c-megamenu__category" data-target="#mobile-star-program-nav"><div class="c-megamenu__anchor">STAR Program</div><div class="c-megamenu__category-content" id="mobile-star-program-nav"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Home - /star/"});" href="/star/">STAR Home</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Registry - /star/registry/"});" data-turbo="false" href="/star/registry/">STAR Registry</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Submit to Registry - /star/submit/"});" href="/star/submit/">Submit to Registry</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Provide Feedback - /star/feedback/"});" href="/star/feedback/">Provide Feedback</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certified STAR Auditors - /star/certified-star-auditors/"});" href="/star/certified-star-auditors/">Certified STAR Auditors</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Enabled Solutions - /star/star-enabled-solutions/overview/"});" href="/star/star-enabled-solutions/overview/">STAR Enabled Solutions</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Stay compliant in the cloud</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CCAK Training - /education/ccak/"});" href="/education/ccak/">CCAK Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Lead Auditor Training - /education/star-lead-auditor-training/"});" href="/education/star-lead-auditor-training/">STAR Lead Auditor Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Training for Government Agencies - /education/gsa-schedule/"});" href="/education/gsa-schedule/">Training for Government Agencies</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Governance, Risk & Compliance Tools</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud Controls Matrix (CCM) - /research/cloud-controls-matrix/"});" href="/research/cloud-controls-matrix/">Cloud Controls Matrix (CCM)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Consensus Assessment Initiative Questionnaire (CAIQ) - /research/cloud-controls-matrix/"});" href="/research/cloud-controls-matrix/">Consensus Assessment Initiative Questionnaire (CAIQ)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"EU Cloud Code of Conduct - /gdpr/eu-cloud-code-of-conduct/"});" href="/gdpr/eu-cloud-code-of-conduct/">EU Cloud Code of Conduct</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Level 1 - /star/registry/?level=1"});" data-turbo="false" href="/star/registry/?level=1">STAR Level 1</a></div><div class="c-megamenu__item-description">At level one organizations submit a self-assessment.</div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"View companies at level one - /star/registry/?level=1"});" data-turbo="false" href="/star/registry/?level=1">View companies at level one</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Learn about level one - /star/#tab_levelOne"});" href="/star/#tab_levelOne">Learn about level one</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Level 2 - /star/registry/?level=2"});" data-turbo="false" href="/star/registry/?level=2">STAR Level 2</a></div><div class="c-megamenu__item-description">At level two organizations earn a certification or third-party attestation.</div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"View companies at level two - /star/registry/?level=2"});" data-turbo="false" href="/star/registry/?level=2">View companies at level two</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Learn about level two - /star/#tab_levelTwo"});" href="/star/#tab_levelTwo">Learn about level two</a></div></div></div></div></div><hr /><div class="c-megamenu__category" data-target="#mobile-certificates-training-nav"><div class="c-megamenu__anchor">Certificates & Training</div><div class="c-megamenu__category-content" id="mobile-certificates-training-nav"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Online Education Platforms</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Knowledge Center - https://knowledge.cloudsecurityalliance.org"});" href="https://knowledge.cloudsecurityalliance.org">Knowledge Center</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CSA Exams - https://exams.cloudsecurityalliance.org"});" href="https://exams.cloudsecurityalliance.org">CSA Exams</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Events - /events/"});" href="/events/">Events</a></div><div class="c-megamenu__item-description">Learn and network while you earn CPE credits.</div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Virtual Events \u0026 Webinars - /events/virtual-and-webinars/"});" data-turbo="false" href="/events/virtual-and-webinars/">Virtual Events & Webinars</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Event Sponsorships - /sponsor/"});" href="/sponsor/">Event Sponsorships</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificates - /education/"});" href="/education/">Certificates</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificate of Cloud Security Knowledge (CCSK) - /education/ccsk/"});" href="/education/ccsk/">Certificate of Cloud Security Knowledge (CCSK)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificate of Cloud Auditing Knowledge (CCAK) - /education/ccak/"});" href="/education/ccak/">Certificate of Cloud Auditing Knowledge (CCAK)</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Certificate of Competence in Zero Trust (CCZT) - /education/cczt/"});" href="/education/cczt/">Certificate of Competence in Zero Trust (CCZT)</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Digital Badges - /education/digital-badges/"});" href="/education/digital-badges/">Digital Badges</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trainings - /education/"});" href="/education/">Trainings</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud Infrastructure Security Training - /education/cloud-infrastructure-security-training"});" href="/education/cloud-infrastructure-security-training">Cloud Infrastructure Security Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"STAR Lead Auditor Training - /education/star-lead-auditor-training/"});" href="/education/star-lead-auditor-training/">STAR Lead Auditor Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Advanced Cloud Security Practitioner (ACSP) Training - /education/advanced-cloud-security-practitioner-training"});" href="/education/advanced-cloud-security-practitioner-training">Advanced Cloud Security Practitioner (ACSP) Training</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CCSK Train the Trainer - /education/train-the-trainer/"});" href="/education/train-the-trainer/">CCSK Train the Trainer</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Training Network - /education/partner#become_partner"});" href="/education/partner#become_partner">Training Network</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Become an Instructor - /education/instructors/"});" href="/education/instructors/">Become an Instructor</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Become a Training Partner - /education/training-partners/"});" href="/education/training-partners/">Become a Training Partner</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Specialized Training Options</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Train my entire team - /education/business/"});" href="/education/business/">Train my entire team</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Training for Government Agencies - /education/gsa-schedule/"});" href="/education/gsa-schedule/">Training for Government Agencies</a></div></div></div></div></div><hr /><div class="c-megamenu__category" data-target="#mobile-research-nav"><div class="c-megamenu__anchor">Research</div><div class="c-megamenu__category-content" id="mobile-research-nav"><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CSA Research - /research/"});" href="/research/">CSA Research</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Latest Research - /research/artifacts"});" href="/research/artifacts">Latest Research</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Working Groups - /research/working-groups/"});" href="/research/working-groups/">Working Groups</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Chapters - /chapters/"});" href="/chapters/">Chapters</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Open Peer Reviews - /research/contribute#peer-reviews"});" href="/research/contribute#peer-reviews">Open Peer Reviews</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Research Topics - /research/topics"});" href="/research/topics">Research Topics</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Strategic Initiatives</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Safety Initiative - /research/working-groups/artificial-intelligence/"});" href="/research/working-groups/artificial-intelligence/">AI Safety Initiative</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Zero Trust Advancement Center - /zt/"});" href="/zt/">Zero Trust Advancement Center</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CxO Trust - /cxo-trust/"});" href="/cxo-trust/">CxO Trust</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Trusted Cloud Consultant - /trusted-cloud-consultant/"});" href="/trusted-cloud-consultant/">Trusted Cloud Consultant</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"FinCloud Security - /fincloud-security"});" href="/fincloud-security">FinCloud Security</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Thought Leadership</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"CloudBytes Webinars - /events/virtual-and-webinars/?event_kind=Webinar"});" data-turbo="false" href="/events/virtual-and-webinars/?event_kind=Webinar">CloudBytes Webinars</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Blog - /blog/"});" href="/blog/">Blog</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Getting Started with CSA Research</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud security best practices - /research/guidance/"});" href="/research/guidance/">Cloud security best practices</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Assess your cloud compliance - /research/cloud-controls-matrix/"});" href="/research/cloud-controls-matrix/">Assess your cloud compliance</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Security questionnaire for vendors - /artifacts/star-level-1-security-questionnaire-caiq-v4/"});" href="/artifacts/star-level-1-security-questionnaire-caiq-v4/">Security questionnaire for vendors</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Top threats to cloud computing - /research/working-groups/top-threats/"});" href="/research/working-groups/top-threats/">Top threats to cloud computing</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Cloud Security Glossary - /cloud-security-glossary"});" href="/cloud-security-glossary">Cloud Security Glossary</a></div></div><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Awards & Recognition</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Juanita Koilpillai Awards - /research/juanita-koilpillai/service-award/"});" href="/research/juanita-koilpillai/service-award/">Juanita Koilpillai Awards</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Research Fellows - /research/fellowship#fellows"});" href="/research/fellowship#fellows">Research Fellows</a></div></div></div><div class="o-grid__cell o-grid__cell--width-25@medium"><div class="c-megamenu__subcategory"><div class="c-megamenu__item"><span>Critical Topics</span></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Safety Initiative - /research/working-groups/artificial-intelligence"});" href="/research/working-groups/artificial-intelligence">AI Safety Initiative</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Technology and Risk - /research/working-groups/ai-technology-and-risk"});" href="/research/working-groups/ai-technology-and-risk">AI Technology and Risk</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Governance \u0026 Compliance - /research/working-groups/ai-governance-compliance"});" href="/research/working-groups/ai-governance-compliance">AI Governance & Compliance</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Controls - /research/working-groups/ai-controls"});" href="/research/working-groups/ai-controls">AI Controls</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"AI Organizational Responsibilities - /research/working-groups/ai-organizational-responsibilities"});" href="/research/working-groups/ai-organizational-responsibilities">AI Organizational Responsibilities</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Enterprise Architecture - /research/working-groups/enterprise-architecture"});" href="/research/working-groups/enterprise-architecture">Enterprise Architecture</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Blockchain - /research/working-groups/blockchain"});" href="/research/working-groups/blockchain">Blockchain</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Zero Trust - /research/working-groups/zero-trust"});" href="/research/working-groups/zero-trust">Zero Trust</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"DevSecOps - /research/working-groups/devsecops"});" href="/research/working-groups/devsecops">DevSecOps</a></div><div class="c-megamenu__item c-megamenu__item--actionable"><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"mega_menu","event_label":"Top Threats - /research/working-groups/top-threats"});" href="/research/working-groups/top-threats">Top Threats</a></div></div></div></div></div><hr /><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Cloud 101 - https://cloudsecurityalliance.org/cloud-newbie"});" href="https://cloudsecurityalliance.org/cloud-newbie">Cloud 101</a><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Circle - https://circle.cloudsecurityalliance.org/"});" rel="noopener" target="_blank" href="https://circle.cloudsecurityalliance.org/">Circle</a><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Events - https://cloudsecurityalliance.org/events/"});" href="https://cloudsecurityalliance.org/events/">Events</a><a class="c-megamenu__anchor" onclick="gtag('event', 'sitewide_menu_click', {"event_category":"quick_links_menu","event_label":"Blog - https://cloudsecurityalliance.org/blog/"});" href="https://cloudsecurityalliance.org/blog/">Blog</a><div class="u-pb16"><form class="c-megamenu__anchor" method="post" action="/auth/auth0"><button data-turbo="false" type="submit">Sign In</button><input type="hidden" name="authenticity_token" value="ystwW8SkvcW6X-2iV_pQp-FxX0pd_V-oSoS8fIg3xq95lYBx0VQlpKrqBqjob6yiDVBDJL3OOdl_GULBT4uYKA" autocomplete="off" /></form></div></div></div></div></div><div class="app_notification o-area o-area--inverse u-centered u-inverse u-pt8 u-pb8 u-bg-color-blue-300" data-controller="record-link-interaction" data-record-link-interaction-action-value="click" data-record-link-interaction-interactable-id-value="293" data-record-link-interaction-interactable-type-value="AppNotification"><small class="u-text-color-white"><div class="trix-content"> <div>Master CSA’s Security, Trust, Assurance, and Risk program—<a href="https://cloudsecurityalliance.org/artifacts/star-prep-kit">download the STAR Prep Kit</a> for essential tools to enhance your assurance!</div> </div> </small></div></header><main class="c-layout-main"><div class="c-container"><div class="o-container"></div></div><div class="o-area o-area--layered o-area--separated"><div class="o-area__layer u-bg-color-gray-25" style="background-image: url(/assets/research/research-bg-light-d8358edc9081fcb49b8cde5bd08c6685af8c428030a46cb378f780e40b223764.png)"></div><div class="o-area__top-layer"><div class="o-container"><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-65@medium"><h2 class="u-text-color-gray-200 u-mb0">Working Group</h2><h1>DevSecOps</h1><h5 class="u-text-color-gray-400 u-separate">This group defines best practices and provides guidance and playbooks to help teams implement security into their DevOps process. </h5><a class="c-button c-button--primary" href="#current_projects">View Current Projects</a></div><div class="o-grid__cell u-mt52"><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-60@medium" style="padding-right: 0px;"><a href="/artifacts/six-pillars-of-devsecops"><img alt="Six Pillars of DevSecOps" class="u-mw180" style="border: 2px solid white;" src="https://cloudsecurityalliance.org/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTE5NzgsInB1ciI6ImJsb2JfaWQifX0=--14e38990ce7ca6f5d4e6905c81f73f26f5846e9e/2.png" /></a></div><div class="o-grid__cell o-grid__cell--width-40@medium" style="padding-left: 0px;"><h6 class="u-pt48">Six Pillars of DevSecOps</h6><p><a href="/artifacts/six-pillars-of-devsecops"><small>Download</small> </a><br /><a href="/artifacts/six-pillars-of-devsecops"><img width="50px" src="/assets/arrows/arrow-orange-down-e3ee0b669a5fb915f04a7ae90efad0f6845e454fa16ca9fbd5a79266ae6d7293.svg" /></a></p></div></div></div></div></div></div></div><div class="o-area"><div class="c-nav"><div class="o-container"><div class="c-nav__item"><a class="c-nav__anchor" href="/research/topics">Research Topics</a></div><div class="c-nav__item"><a class="c-nav__anchor" href="/research/topics/devsecops">About Topic</a></div><div class="c-nav__item"><div class="c-nav__anchor c-nav__anchor--active">Working Group</div></div><div class="c-nav__item"><a target="_blank" rel="noopener" class="c-nav__anchor" href="https://cloudsecurityalliance.org/research/working-groups/devsecops/join">Discussion Community</a></div><div class="c-nav__item"><a target="_blank" rel="noopener" class="c-nav__anchor" href="/research/artifacts?term=devsecops">Publications</a></div></div></div></div><div class="o-area"><div class="o-container"><div class="c-breadcrumbs"><div class="c-breadcrumbs__item"><a href="/">Home</a></div><div class="c-breadcrumbs__item"><a href="/research">Research</a></div><div class="c-breadcrumbs__item"><a href="/research/working-groups">Working Groups</a></div><div class="c-breadcrumbs__item">DevSecOps</div></div></div></div><div class="o-area o-area--separated"><div class="o-container"><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-60@medium"><div class="o-rich-text"><div class="trix-content"> <div><strong>Working Group Overview</strong><br><br></div><div>Our working group discusses the DevSecOps. We welcome anyone who would like to join, even if you would like to just listen-in on your first call.<br><br></div><div>What do we discuss? During these meetings we typically discuss changes in the industry that relate to DevOps, and collaborate on projects the group is currently working on.<br><br></div><div>This working group meets every other week. To find out more about participating email <a href="/cdn-cgi/l/email-protection#c0b3b5b0b0afb2b480a3acafb5a4b3a5a3b5b2a9b4b9a1acaca9a1aea3a5eeafb2a7"><span class="__cf_email__" data-cfemail="3e4d4b4e4e514c4a7e5d52514b5a4d5b5d4b4c574a475f5252575f505d5b10514c59">[email protected]</span></a> or sign up here: <a href="https://csaurl.org/devsecops-signup">https://csaurl.org/devsecops-signup</a><br><br></div><div><strong>Drafts & Important Docs<br></strong><br></div><ul><li><a href="https://circle.cloudsecurityalliance.org/community-home1/librarydocuments?communitykey=fed0970b-dfd3-4de0-a718-68630e77c5db&tab=librarydocuments&LibraryFolderKey=&DefaultView=">Document drafts</a></li><li><a href="https://circle.cloudsecurityalliance.org/viewdocument/devsecops-working-charter?CommunityKey=fed0970b-dfd3-4de0-a718-68630e77c5db&tab=librarydocuments&LibraryFolderKey=bc11d27d-5cf8-40a0-846d-551259909461&DefaultView=folder">Group charter</a></li><li><a href="https://cloudsecurityalliance.org/secure-development-lifecycle">Secure Development Lifecycle</a></li></ul><div><strong>Looking for additional information?<br></strong><br></div><div>Scroll down below for the working group calendar, whitepaper drafts, and other information!<br><br></div> </div> </div></div><div class="o-grid__cell"><h3>Working Group Co-Chairs</h3><div class="c-headshot-group u-separate" style="justify-content: left;"><div class="c-combo-headshot c-combo-headshot--compact"><div data-obscurable="true" data-obscurable-width="500"><div class="c-combo-headshot__content"><div class="c-emblem"><div class="c-emblem__layer"><img data-retina-src="/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTQ3MjQsInB1ciI6ImJsb2JfaWQifX0=--74707484cfb25f875eecfc537c76db3aee974baf/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJhdXRvX29yaWVudCI6dHJ1ZSwicm90YXRlIjowLCJncmF2aXR5IjoiY2VudGVyIiwicmVzaXplIjoiMzYweDQ4MF4iLCJiYWNrZ3JvdW5kIjoibm9uZSJ9LCJwdXIiOiJ2YXJpYXRpb24ifX0=--184082a01f7e1e6415e4d6e03b7cd8002a80db59/20210120_145802.jpg" alt="Roupe Sahans" style="width: 100%; height: 100%; object-fit: cover;" src="/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTQ3MjQsInB1ciI6ImJsb2JfaWQifX0=--74707484cfb25f875eecfc537c76db3aee974baf/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJhdXRvX29yaWVudCI6dHJ1ZSwicm90YXRlIjowLCJncmF2aXR5IjoiY2VudGVyIiwicmVzaXplIjoiMTgweDI0MF4iLCJiYWNrZ3JvdW5kIjoibm9uZSJ9LCJwdXIiOiJ2YXJpYXRpb24ifX0=--ce1f0b273c14895214513c640abe6c284218f1db/20210120_145802.jpg" /></div></div><div class="c-combo-headshot__label">Roupe Sahans</div></div><div class="b-obscured u-align-left"><p class="u-mb0"><strong>Roupe Sahans</strong></p><p class="u-text-color-gray-400">DevSecOps Leader</p><p><p>Roupe leads DevSecOps delivery and thought leadership for technology and media clients embracing digital transformation.<br><br>Roupe started his DevOps journey in 2016, building containerised microservices on AWS for government platforms. He has since been working with engineers to c-suite executives to embed security and resilience into digital products, secure cloud services, and reduce cyber technical-debt.<br><br>Most recently Roupe ha...</p></p><p><a href="/profiles/roupe-sahans"><span>Read more</span> <i class="fas fa-long-arrow-alt-right"></i></a></p></div></div></div><div class="c-combo-headshot c-combo-headshot--unclickable c-combo-headshot--compact"><div data-obscurable="true" data-obscurable-width="500"><div class="c-combo-headshot__content"><div class="c-emblem"><div class="c-emblem__layer"><img alt="Abdul Sattar Headshot Missing" width="100%" src="/assets/fallback/csa-headshot-7b449f5deff0b8be963d29536d108a63e2ef86ec765da989bb085a7d8c14217c.png" /></div></div><div class="c-combo-headshot__label">Abdul Sattar</div></div><div class="b-obscured u-align-left"><p class="u-mb0"><strong>Abdul Sattar</strong></p><p class="u-text-color-gray-400"></p></div></div></div></div><table class="c-table c-table--condensed"><thead class="c-table__head"><tr class="c-table__row"><th class="c-table__cell" width="70%">Publications in Review</th><th class="c-table__cell" width="30%">Open Until</th></tr></thead><tbody class="c-table__body"><tr class="c-table__row"><td class="c-table__cell"><a href="https://docs.google.com/document/d/1ko3NRDtIg46YeaiPCqRL-shzqSSk32Xpg4a_fGYOQ0A/edit?usp=sharing">Fully Homomorphic Encryption: A Comprehensive Guide for Cybersecurity Professionals</a></td><td class="c-table__cell">Dec 06, 2024</td></tr><tr class="c-table__row"><td class="c-table__cell"><a href="https://docs.google.com/document/d/1riEDrEcv0roOgyu3Hl68GNFlRfIuBW3zJz0R3BtNfac/edit?usp=sharing">AI Organizational Responsibilities: AI Tools and Applications</a></td><td class="c-table__cell">Dec 08, 2024</td></tr><tr class="c-table__row"><td class="c-table__cell"><a href="https://docs.google.com/document/d/1SBNkqZA0Ac3SJyMWE9JdTcu5ddT7yeSrHWH1BccoP5o/edit?usp=sharing">Zero Trust Guidance for Small and Medium Size Businesses (SMBs)</a></td><td class="c-table__cell">Dec 15, 2024</td></tr><tr class="c-table__row"><td class="c-table__cell"><a href="https://docs.google.com/document/d/1RlnM1yEg4KZyCSQYtKJR2upWf3BCxKoXoH7ptXKPPNM/edit?usp=sharing">Zero Trust Privacy Assessment and Guidance</a></td><td class="c-table__cell">Dec 27, 2024</td></tr></tbody></table><a target="_blank" rel="noopener" href="/research/contribute#peer-reviews"><span>View all</span> <i class="fas fa-long-arrow-alt-right"></i></a></div></div></div></div><div class="o-area o-area--announcement u-bg-color-orange-500"><div class="o-area__container"><div class="o-area__item"><h5 class="c-heading"><a href="https://circle.cloudsecurityalliance.org/devsecops/home">Want to join this working group? Register or sign-into Circle to get started.</a></h5></div><div class="o-area__item"><a class="c-button c-button--icon c-button--green u-pb0" href="https://circle.cloudsecurityalliance.org/devsecops/home"><img width="50" height="50" src="/assets/arrows/arrow-white-right-53b5245d5c2df81c153080d64b7cbaeddc14e5b9e8f582d1400b7be8edda4db2.svg" /></a></div></div></div><div class="o-area o-area--separated o-area--color-blue-800 o-area--inverse"><div class="o-container"><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit"><div class="o-grid__cell o-grid__cell--width-45@medium o-grid__cell--offset-5@medium u-centered"><img width="75px;" src="/assets/research/working-groups/who-can-join-b7c5781a7d99d0c9752b35f1de825c2dec5a2de7fb50a69b5cf5c38fac815dd3.svg" /><h5><strong>Who can join?</strong></h5><p class="u-text-color-gray-50">Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.</p></div><div class="o-grid__cell o-grid__cell--width-45@medium u-centered"><img width="75px;" src="/assets/research/working-groups/time-commitment-a3d572f19f4dca6086c2af39943461714ee4f5cca3f6e58e42ec8412efc9b45a.svg" /><h5><strong>What is the time commitment?</strong></h5><p class="u-text-color-gray-50">The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.</p></div></div></div></div><div class="o-area o-area--separated o-area--alternating" id="virtual_meetings"><div class="o-container"><h2 class="c-heading c-heading--section">Virtual Meetings</h2><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit u-separate"><div class="o-grid__cell o-grid__cell--width-90@medium o-grid__cell--offset-5@medium"><p><span>Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can</span> <a href="https://cloudsecurityalliance.org/meetings">view all research meetings here</a><span>.</span></p></div></div><div class="c-calendar-events"><div class="c-calendar-event"><div class="c-card c-card--shadow c-card--flex-child"><div class="u-centered u-bg-color-gray-400 u-mb8"><p class="u-text-color-gray-75 u-mb0 u-pt8">Dec</p><h3 class="u-text-color-white u-mb0 u-pb8">5</h3></div><div class="c-card__item"><small class="u-text-color-gray-200">Thu, December 5, 8:00am <span>-</span> 9:00am PST</small><h5 class="u-text--bold u-mb0">CSA DevSecOps Working Group</h5><div class="b-calendar-accordion"><small class="u-text-color-blue-500 b-calendar-accordion__trigger"><span>See details</span> </small><div class="b-calendar-accordion__content"><small><b>CSA DevSecOps Working Group</b><u></u><br><u></u><b><br></b><u></u><br><u></u><u></u>This is the main meeting for the working group, and is open to everyone to attend. We typically will cover updates from our in progress initiatives, other related CSA & industry news, and open the floor for discussion.<u></u><br><u></u><br><u></u><br><u></u>If you are new to the working group and looking to learn more about DevSecOps, or get help with participating as a volunteer, this is the meeting for you!<br><ul><li>Meeting Invite:<br><a href="https://cloudsecurityalliance.zoom.us/j/87632146528?pwd=bTJwaXFTL3NvMWVNVU5WVlFpdURjZz09"><u><u>https://cloudsecurityalliance.zoom.us/j/87632146528?pwd=bTJwaXFTL3NvMWVNVU5WVlFpdURjZz09</u></u></a><br></li><li>Rolling Agenda:<br><a href="https://docs.google.com/document/d/1DiBsHoQfs7JPSl4kBE203KjNd96NwkQTZJqcut_htVA/edit" class="pastedDriveLink-0"><u>https://docs.google.com/document/d/1DiBsHoQfs7JPSl4kBE203KjNd96NwkQTZJqcut_htVA/edit</u></a></li></ul></small></div></div><div class="u-centered u-mt24 u-mb20"><a class="c-button c-button--ghost c-button--orange" href="https://www.google.com/calendar/event?eid=NGcwNms5dGRvZHJwYWRoNHF0dWVucm9sNmxfMjAyNDEyMDVUMTYwMDAwWiBjX2N0ZWZvZ3Q4cWZmYmo1bW1iZTdqZ2xrYmpnQGc">View Event</a></div></div></div></div><div class="c-calendar-event"><div class="c-card c-card--shadow c-card--flex-child"><div class="u-centered u-bg-color-gray-400 u-mb8"><p class="u-text-color-gray-75 u-mb0 u-pt8">Dec</p><h3 class="u-text-color-white u-mb0 u-pb8">19</h3></div><div class="c-card__item"><small class="u-text-color-gray-200">Thu, December 19, 8:00am <span>-</span> 9:00am PST</small><h5 class="u-text--bold u-mb0">DevSecOps WG - MLOps Paper(s) Working Session</h5><div class="b-calendar-accordion"><small class="u-text-color-blue-500 b-calendar-accordion__trigger"><span>See details</span> </small><div class="b-calendar-accordion__content"><small>This is a working session to sync on the current MLOps whitepapers the DevSecOps working group is currently writing.<br><br>We meet every 1st and 3rd Thursday at 8am Pacific Time.<br><br>Writing will mostly be done asynchronously between meetings.<br><br>Useful links:<br><ul><li>Zoom Meeting Link: <a href="https://csaurl.org/devsecops-call">https://csaurl.org/devsecops-call</a></li><li>CSA Public Slack: <a href="https://csaurl.org/csa-public-slack">https://csaurl.org/csa-public-slack</a></li><li>Working Group Slack Channel: <b><a href="https://csa-public.slack.com/archives/C03EBB86P09">#devsecops-working-group</a></b></li></ul><br>Links to the draft documents can be found in the #devsecops-working-group Slack channel bookmarks at the top of the screen.</small></div></div><div class="u-centered u-mt24 u-mb20"><a class="c-button c-button--ghost c-button--orange" href="https://www.google.com/calendar/event?eid=MnVqOW4yOGNmdWE1M2Voc3VhaGNrcXMzMzdfMjAyNDEyMTlUMTYwMDAwWiBjX2N0ZWZvZ3Q4cWZmYmo1bW1iZTdqZ2xrYmpnQGc">View Event</a></div></div></div></div><div class="c-calendar-event"><div class="c-card c-card--shadow c-card--flex-child"><div class="u-centered u-bg-color-gray-400 u-mb8"><p class="u-text-color-gray-75 u-mb0 u-pt8">Jan</p><h3 class="u-text-color-white u-mb0 u-pb8">2</h3></div><div class="c-card__item"><small class="u-text-color-gray-200">Thu, January 2, 8:00am <span>-</span> 9:00am PST</small><h5 class="u-text--bold u-mb0">CSA DevSecOps Working Group</h5><div class="b-calendar-accordion"><small class="u-text-color-blue-500 b-calendar-accordion__trigger"><span>See details</span> </small><div class="b-calendar-accordion__content"><small><b>CSA DevSecOps Working Group</b><u></u><br><u></u><b><br></b><u></u><br><u></u><u></u>This is the main meeting for the working group, and is open to everyone to attend. We typically will cover updates from our in progress initiatives, other related CSA & industry news, and open the floor for discussion.<u></u><br><u></u><br><u></u><br><u></u>If you are new to the working group and looking to learn more about DevSecOps, or get help with participating as a volunteer, this is the meeting for you!<br><ul><li>Meeting Invite:<br><a href="https://cloudsecurityalliance.zoom.us/j/87632146528?pwd=bTJwaXFTL3NvMWVNVU5WVlFpdURjZz09"><u><u>https://cloudsecurityalliance.zoom.us/j/87632146528?pwd=bTJwaXFTL3NvMWVNVU5WVlFpdURjZz09</u></u></a><br></li><li>Rolling Agenda:<br><a href="https://docs.google.com/document/d/1DiBsHoQfs7JPSl4kBE203KjNd96NwkQTZJqcut_htVA/edit" class="pastedDriveLink-0"><u>https://docs.google.com/document/d/1DiBsHoQfs7JPSl4kBE203KjNd96NwkQTZJqcut_htVA/edit</u></a></li></ul></small></div></div><div class="u-centered u-mt24 u-mb20"><a class="c-button c-button--ghost c-button--orange" href="https://www.google.com/calendar/event?eid=NGcwNms5dGRvZHJwYWRoNHF0dWVucm9sNmxfMjAyNTAxMDJUMTYwMDAwWiBjX2N0ZWZvZ3Q4cWZmYmo1bW1iZTdqZ2xrYmpnQGc">View Event</a></div></div></div></div><div class="c-calendar-event"><div class="c-card c-card--shadow c-card--flex-child"><div class="u-centered u-bg-color-gray-400 u-mb8"><p class="u-text-color-gray-75 u-mb0 u-pt8">Jan</p><h3 class="u-text-color-white u-mb0 u-pb8">16</h3></div><div class="c-card__item"><small class="u-text-color-gray-200">Thu, January 16, 8:00am <span>-</span> 9:00am PST</small><h5 class="u-text--bold u-mb0">DevSecOps WG - MLOps Paper(s) Working Session</h5><div class="b-calendar-accordion"><small class="u-text-color-blue-500 b-calendar-accordion__trigger"><span>See details</span> </small><div class="b-calendar-accordion__content"><small>This is a working session to sync on the current MLOps whitepapers the DevSecOps working group is currently writing.<br><br>We meet every 1st and 3rd Thursday at 8am Pacific Time.<br><br>Writing will mostly be done asynchronously between meetings.<br><br>Useful links:<br><ul><li>Zoom Meeting Link: <a href="https://csaurl.org/devsecops-call">https://csaurl.org/devsecops-call</a></li><li>CSA Public Slack: <a href="https://csaurl.org/csa-public-slack">https://csaurl.org/csa-public-slack</a></li><li>Working Group Slack Channel: <b><a href="https://csa-public.slack.com/archives/C03EBB86P09">#devsecops-working-group</a></b></li></ul><br>Links to the draft documents can be found in the #devsecops-working-group Slack channel bookmarks at the top of the screen.</small></div></div><div class="u-centered u-mt24 u-mb20"><a class="c-button c-button--ghost c-button--orange" href="https://www.google.com/calendar/event?eid=MnVqOW4yOGNmdWE1M2Voc3VhaGNrcXMzMzdfMjAyNTAxMTZUMTYwMDAwWiBjX2N0ZWZvZ3Q4cWZmYmo1bW1iZTdqZ2xrYmpnQGc">View Event</a></div></div></div></div></div></div></div><div class="o-area o-area--separated o-area--alternating" id="current_projects"><div class="o-container"><h2 class="c-heading c-heading--section">Current Projects</h2><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit u-separate"><div class="o-grid__cell o-grid__cell--width-20@medium o-grid__cell--offset-30@medium"><a target="_blank" rel="noopener" href="/research/artifacts?term=devsecops"><span>View recent publications</span> <i class="fas fa-long-arrow-alt-right"></i></a></div><div class="o-grid__cell o-grid__cell--width-20@medium"><a target="_blank" rel="noopener" href="https://circle.cloudsecurityalliance.org/devsecops/home"><span>Sign-up for this group</span> <i class="fas fa-long-arrow-alt-right"></i></a></div></div><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit u-separate"><div class="o-grid__cell c-card--tall"><div class="c-embed"><iframe frameborder="0" src="https://airtable.com/embed/shrsQqtbNlCiL7vD7" style="height: 500px;"></iframe></div></div></div></div></div><div class="o-area o-area--separated o-area--alternating" id="open_peer_reviews"><div class="o-container"><h2 class="c-heading c-heading--section">Open Peer Reviews</h2><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit u-separate"><div class="o-grid__cell o-grid__cell--width-60@medium o-grid__cell--offset-20@medium u-centered"><p>Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.</p><p><a target="_blank" rel="noopener" href="https://support.cloudsecurityalliance.org/hc/en-us/articles/4419874386199-How-to-participate-in-a-peer-review">Learn how to participate in a peer review here.</a></p></div></div><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit b-unified"><div class="o-grid__cell o-grid__cell--width-50@medium"><div class="c-card c-card--actionable u-separate b-unified__item" id="fully-homomorphic-encryption-a-comprehensive-guide-for-cybersecurity-professionals"><div class="c-card__item c-card__item--cta"><h3 class="u-mb8">Fully Homomorphic Encryption: A Comprehensive Guide for Cybersecurity Professionals</h3><p><strong>Open Until:</strong> <span>12/06/2024</span></p><p> The document Fully Homomorphic Encryption: A Comprehensive Guide for Cybersecurity Professionals serves as an in-d...</p><div class="c-card__cta"><a href="/artifacts/fully-homomorphic-encryption-a-comprehensive-guide-for-cybersecurity-professionals">Participate in peer review</a></div></div><a class="u-position-center" href="/artifacts/fully-homomorphic-encryption-a-comprehensive-guide-for-cybersecurity-professionals"></a></div></div><div class="o-grid__cell o-grid__cell--width-50@medium"><div class="c-card c-card--actionable u-separate b-unified__item" id="ai-organizational-responsibilities-ai-tools-and-applications"><div class="c-card__item c-card__item--cta"><h3 class="u-mb8">AI Organizational Responsibilities: AI Tools and Applications</h3><p><strong>Open Until:</strong> <span>12/08/2024</span></p><p> The integration of LLMs and Generative AI introduces vital security considerations across development and deployment proces...</p><div class="c-card__cta"><a href="/artifacts/ai-organizational-responsibilities-ai-tools-and-applications">Participate in peer review</a></div></div><a class="u-position-center" href="/artifacts/ai-organizational-responsibilities-ai-tools-and-applications"></a></div></div></div><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit b-unified"><div class="o-grid__cell o-grid__cell--width-50@medium"><div class="c-card c-card--actionable u-separate b-unified__item" id="zero-trust-guidance-for-small-and-medium-size-businesses-smbs"><div class="c-card__item c-card__item--cta"><h3 class="u-mb8">Zero Trust Guidance for Small and Medium Size Businesses (SMBs)</h3><p><strong>Open Until:</strong> <span>12/15/2024</span></p><p> In an increasingly digital world, small and medium-sized businesses (SMBs) are facing heightened security challenges, makin...</p><div class="c-card__cta"><a href="/artifacts/zero-trust-guidance-for-small-and-medium-size-businesses-smbs">Participate in peer review</a></div></div><a class="u-position-center" href="/artifacts/zero-trust-guidance-for-small-and-medium-size-businesses-smbs"></a></div></div><div class="o-grid__cell o-grid__cell--width-50@medium"><div class="c-card c-card--actionable u-separate b-unified__item" id="zero-trust-privacy-assessment-and-guidance"><div class="c-card__item c-card__item--cta"><h3 class="u-mb8">Zero Trust Privacy Assessment and Guidance</h3><p><strong>Open Until:</strong> <span>12/27/2024</span></p><p> The objective of this paper is to provide guidance for using zero trust in privacy implementation. This document highlights...</p><div class="c-card__cta"><a href="/artifacts/zero-trust-privacy-assessment-and-guidance">Participate in peer review</a></div></div><a class="u-position-center" href="/artifacts/zero-trust-privacy-assessment-and-guidance"></a></div></div></div></div></div></main><footer class="c-layout-footer"><div class="o-area"><div class="cookie-banner" style="display: block;"><div data-controller="dynamic-content"><div class="c-notification c-notification--info" id="cookie-banner-main"><div class="c-notification__item c-notification__item--icon"><div class="fas fa-info-circle"></div></div><div class="c-notification__item"><p><strong>We value your privacy.</strong> <span>Our website uses analytics and advertising cookies to improve your browsing experience. Read our full</span> <a href="/legal/privacy-notice/">Privacy Policy</a><span>.</span></p><div class="c-button-group c-button-group--centered u-mb16"><a class="c-button c-button--gray" data-action="click->dynamic-content#update" data-dynamic-content-hide-param="#cookie-banner-main" data-dynamic-content-show-param="#cookie-banner-customize" href="#">Customize</a><a class="c-button c-button--blue" id="cookie-banner-accept-all" data-action="cookie-consent#acceptAll" data-controller="cookie-consent" href="#">Allow</a></div></div></div><div class="c-notification c-notification--info" id="cookie-banner-customize" style="display: none;"><div class="c-notification__item c-notification__item--icon"><div class="fas fa-info-circle"></div></div><div class="c-notification__item"><p class="u-pt12" style="line-height: 1.3em; font-size: 1.2em;"><strong>About the Cookies</strong></p><form class="c-form" data-action="cookie-consent#update" data-controller="cookie-consent" action="/research/working-groups/devsecops" accept-charset="UTF-8" method="post"><input type="hidden" name="authenticity_token" value="73N1UEd96JkHzCF8VKQjlwSUbd6dMB3gK_3DmrqrqmqaoxR8SdJ18iqS0Muqe0yvfvKLy_2kdLjWdipO_ggZcw" autocomplete="off" /><p><strong>Analytics cookies,</strong> from <a target="_blank" href="https://analytics.google.com/">Google Analytics</a> and <a target="_blank" href="https://clarity.microsoft.com/">Microsoft Clarity</a> help us analyze site usage to continuously improve our website.</p><div class="c-form__item-group c-form__item-group--duo c-form__item-group--checkbox--big"><div class="c-form__item"><input id="analytics" type="checkbox" value="1" checked="checked" name="analytics" /></div><div class="c-form__item c-form__item--label"><label for="analytics">Enable cookies for analytics.</label></div></div><p class="u-pt12"><strong>Advertising cookies,</strong> enable <a target="_blank" href="https://policies.google.com/privacy">Google</a> to collect information to display content and ads tailored to your interests.</p><div class="c-form__item-group c-form__item-group--duo c-form__item-group--checkbox--big"><div class="c-form__item"><input id="advertising" type="checkbox" value="1" checked="checked" name="advertising" /></div><div class="c-form__item c-form__item--label"><label for="advertising">Enable cookies for advertising.</label></div></div><div class="c-button-group c-button-group--centered u-mb16 u-mt16"><a class="c-button c-button--gray" id="cookie-banner-reject-all" data-action="cookie-consent#rejectAll" data-controller="cookie-consent" href="#">Decline All</a><input type="submit" name="commit" value="Confirm" class="c-button c-button--blue" data-disable-with="Confirm" /></div></form></div></div></div></div><div class="c-footer"><div class="o-container"><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit"><div class="c-footer__item o-grid__cell o-grid__cell--width-30@medium u-align-left"><div class="c-footer__logo u-separate"><img src="/assets/csa-logo-white-33c6ce89081b4488f9fe480c8e4f5e662f8a9723e5467d30359ff832c269b7d6.png" /></div><p class="u-separate"><a class="c-button c-button--social-circle c-button--linkedin" target="_blank" rel="noopener" href="https://www.linkedin.com/groups/1864210/profile"><img src="/assets/social-share/li-icon-09fa81c48d4329077ed9608610eb94677c1598373b57333973e931874e641c30.svg" /></a><a class="c-button c-button--social-circle c-button--twitter" target="_blank" rel="noopener" href="https://twitter.com/intent/tweet?text=&url="><img src="/assets/social-share/x-icon-d5737d8484c6d1c6b2c18ad43c18037db1925464c40f14899cdfdb82fe33a861.svg" /></a><a class="c-button c-button--social-circle c-button--facebook" target="_blank" rel="noopener" href="https://www.facebook.com/csacloudfiles"><img src="/assets/social-share/fb-icon-c0307da13019b8e4ef32e5f2e7039eac01c272bcbc2c3a7aad4ba033c0a27153.svg" /></a><a class="c-button c-button--social-circle c-button--youtube" target="_blank" rel="noopener" href="https://www.youtube.com/channel/UCrcG6ZtsBPz3xkUZU6asVhA"><img src="/assets/social-share/yt-icon-ade320bf2b6ffeae084895dac740b736c7dda9f181a871260f83da2462465ab3.svg" /></a><p class="u-separate"><span>© 2009–</span><span>2024</span> <span>Cloud Security Alliance.</span><br /><span>All rights reserved.</span></p></p></div><div class="c-footer__item o-grid__cell"><div class="o-grid o-grid--small-full o-grid--medium-full o-grid--large-fit"><div class="o-grid__cell"><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Corporate Membership - https://cloudsecurityalliance.org/membership/"});" href="https://cloudsecurityalliance.org/membership/">Corporate Membership</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Cloud Customers - https://cloudsecurityalliance.org/membership/enterprises/"});" href="https://cloudsecurityalliance.org/membership/enterprises/">Cloud Customers</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Cloud Solution Providers - https://cloudsecurityalliance.org/membership/solution-providers/"});" href="https://cloudsecurityalliance.org/membership/solution-providers/">Cloud Solution Providers</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Join as an Individual - https://circle.cloudsecurityalliance.org/home"});" href="https://circle.cloudsecurityalliance.org/home">Join as an Individual</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Circle Community Forum - https://cloudsecurityalliance.org/circle/"});" href="https://cloudsecurityalliance.org/circle/">Circle Community Forum</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Chapters - https://cloudsecurityalliance.org/chapters/"});" href="https://cloudsecurityalliance.org/chapters/">Chapters</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Working Groups - https://cloudsecurityalliance.org/research/working-groups/"});" href="https://cloudsecurityalliance.org/research/working-groups/">Working Groups</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Research - https://cloudsecurityalliance.org/research/"});" href="https://cloudsecurityalliance.org/research/">Research</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Download Publications - https://cloudsecurityalliance.org/research/artifacts/"});" href="https://cloudsecurityalliance.org/research/artifacts/">Download Publications</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"View Working Groups - https://cloudsecurityalliance.org/research/working-groups/"});" href="https://cloudsecurityalliance.org/research/working-groups/">View Working Groups</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"View All Topics - https://cloudsecurityalliance.org/research/topics"});" href="https://cloudsecurityalliance.org/research/topics">View All Topics</a></div><div class="c-footer__list"><h6><span>Find a...</span></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Cloud Consultant - https://cloudsecurityalliance.org/trusted-cloud-consultant"});" href="https://cloudsecurityalliance.org/trusted-cloud-consultant">Cloud Consultant</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Cloud Service Provider - https://cloudsecurityalliance.org/star/registry/"});" data-turbo="false" href="https://cloudsecurityalliance.org/star/registry/">Cloud Service Provider</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Trusted Cloud Provider - https://cloudsecurityalliance.org/trusted-cloud-provider"});" href="https://cloudsecurityalliance.org/trusted-cloud-provider">Trusted Cloud Provider</a></div></div><div class="o-grid__cell"><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Certificates - https://cloudsecurityalliance.org/education/"});" href="https://cloudsecurityalliance.org/education/">Certificates</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"CCSK - https://cloudsecurityalliance.org/education/ccsk/"});" href="https://cloudsecurityalliance.org/education/ccsk/">CCSK</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"CCAK - https://cloudsecurityalliance.org/education/ccak/"});" href="https://cloudsecurityalliance.org/education/ccak/">CCAK</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"CCZT - https://cloudsecurityalliance.org/education/cczt/"});" href="https://cloudsecurityalliance.org/education/cczt/">CCZT</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Events - https://cloudsecurityalliance.org/events/"});" href="https://cloudsecurityalliance.org/events/">Events</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Americas - https://cloudsecurityalliance.org/events/americas"});" href="https://cloudsecurityalliance.org/events/americas">Americas</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"EMEA - https://cloudsecurityalliance.org/events/emea/"});" href="https://cloudsecurityalliance.org/events/emea/">EMEA</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"APAC - https://cloudsecurityalliance.org/events/apac/"});" href="https://cloudsecurityalliance.org/events/apac/">APAC</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Education - https://cloudsecurityalliance.org/education/"});" href="https://cloudsecurityalliance.org/education/">Education</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Blog - https://cloudsecurityalliance.org/blog/"});" href="https://cloudsecurityalliance.org/blog/">Blog</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Virtual Events \u0026 Webinars - https://cloudsecurityalliance.org/events/virtual-and-webinars/"});" data-turbo="false" href="https://cloudsecurityalliance.org/events/virtual-and-webinars/">Virtual Events & Webinars</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Training - https://cloudsecurityalliance.org/education/"});" href="https://cloudsecurityalliance.org/education/">Training</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Cloud 101 - https://cloudsecurityalliance.org/cloud-newbie"});" href="https://cloudsecurityalliance.org/cloud-newbie">Cloud 101</a></div><div class="c-footer__list"><h6><span>Popular Resources</span></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Security Guidance - https://cloudsecurityalliance.org/research/guidance/"});" href="https://cloudsecurityalliance.org/research/guidance/">Security Guidance</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"CCM - https://cloudsecurityalliance.org/research/cloud-controls-matrix/"});" href="https://cloudsecurityalliance.org/research/cloud-controls-matrix/">CCM</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"CAIQ - https://cloudsecurityalliance.org/research/cloud-controls-matrix/"});" href="https://cloudsecurityalliance.org/research/cloud-controls-matrix/">CAIQ</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"STAR - https://cloudsecurityalliance.org/star/"});" href="https://cloudsecurityalliance.org/star/">STAR</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"GDPR - https://cloudsecurityalliance.org/privacy/gdpr/"});" href="https://cloudsecurityalliance.org/privacy/gdpr/">GDPR</a></div></div><div class="o-grid__cell"><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"About CSA - https://cloudsecurityalliance.org/about/"});" href="https://cloudsecurityalliance.org/about/">About CSA</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Contact Us - https://cloudsecurityalliance.org/contact/"});" href="https://cloudsecurityalliance.org/contact/">Contact Us</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Press Releases - https://cloudsecurityalliance.org/press-releases/"});" href="https://cloudsecurityalliance.org/press-releases/">Press Releases</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Affiliates - https://cloudsecurityalliance.org/membership/current-affiliates/"});" href="https://cloudsecurityalliance.org/membership/current-affiliates/">Affiliates</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Press Coverage - https://cloudsecurityalliance.org/press-coverage/"});" href="https://cloudsecurityalliance.org/press-coverage/">Press Coverage</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Quality Policy - https://cloudsecurityalliance.org/quality-policy/"});" href="https://cloudsecurityalliance.org/quality-policy/">Quality Policy</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Our Team - https://cloudsecurityalliance.org/about/csa-staff/"});" href="https://cloudsecurityalliance.org/about/csa-staff/">Our Team</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Board of Directors - https://cloudsecurityalliance.org/about/board-of-directors/"});" data-turbo="false" href="https://cloudsecurityalliance.org/about/board-of-directors/">Board of Directors</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Management \u0026 Staff - https://cloudsecurityalliance.org/about/csa-staff/"});" data-turbo="false" href="https://cloudsecurityalliance.org/about/csa-staff/">Management & Staff</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Careers - https://cloudsecurityalliance.org/about/careers"});" href="https://cloudsecurityalliance.org/about/careers">Careers</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Legal - https://cloudsecurityalliance.org/legal/"});" href="https://cloudsecurityalliance.org/legal/">Legal</a></h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Privacy Notice - https://cloudsecurityalliance.org/legal/privacy-notice/"});" href="https://cloudsecurityalliance.org/legal/privacy-notice/">Privacy Notice</a><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Terms \u0026 Conditions - https://cloudsecurityalliance.org/legal/website-terms-and-conditions/"});" href="https://cloudsecurityalliance.org/legal/website-terms-and-conditions/">Terms & Conditions</a></div><div class="c-footer__list"><h6><a onclick="gtag('event', 'sitewide_menu_click', {"event_category":"footer_menu","event_label":"Cloud Security Glossary - https://cloudsecurityalliance.org/cloud-security-glossary/"});" href="https://cloudsecurityalliance.org/cloud-security-glossary/">Cloud Security Glossary</a></h6></div></div></div></div></div></div></div><div class="u-scroll-to-top"><span class="c-button c-button--primary c-button--elevated">▴</span></div></div></footer><div class="c-modal"><div class="c-modal__content"></div><span class="c-modal__close-button"></span></div> <script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script><script id="ze-snippet" src="https://static.zdassets.com/ekr/snippet.js?key=2121b371-8db3-4beb-8ca2-5e994ec5fb73"></script> <script type="text/javascript"> var isDesktop = true; // device detection if(/(android|bb\d+|meego).+mobile|avantgo|bada\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|ipad|iris|kindle|Android|Silk|lge |maemo|midp|mmp|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\.(browser|link)|vodafone|wap|windows (ce|phone)|xda|xiino/i.test(navigator.userAgent) || /1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\-(n|u)|c55\/|capi|ccwa|cdm\-|cell|chtm|cldc|cmd\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\-s|devi|dica|dmob|do(c|p)o|ds(12|\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\-|_)|g1 u|g560|gene|gf\-5|g\-mo|go(\.w|od)|gr(ad|un)|haie|hcit|hd\-(m|p|t)|hei\-|hi(pt|ta)|hp( i|ip)|hs\-c|ht(c(\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\-(20|go|ma)|i230|iac( |\-|\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\/)|klon|kpt |kwc\-|kyo(c|k)|le(no|xi)|lg( g|\/(k|l|u)|50|54|\-[a-w])|libw|lynx|m1\-w|m3ga|m50\/|ma(te|ui|xo)|mc(01|21|ca)|m\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\-2|po(ck|rt|se)|prox|psio|pt\-g|qa\-a|qc(07|12|21|32|60|\-[2-7]|i\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\-|oo|p\-)|sdk\/|se(c(\-|0|1)|47|mc|nd|ri)|sgh\-|shar|sie(\-|m)|sk\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\-|v\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\-|tdg\-|tel(i|m)|tim\-|t\-mo|to(pl|sh)|ts(70|m\-|m3|m5)|tx\-9|up(\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\-|your|zeto|zte\-/i.test(navigator.userAgent.substr(0,4))) { isDesktop = false; } window.zESettings = { webWidget: { color: { launcherText: '#FFFFFF' } } }; var customizeWidget = function () { // Dodge Recaptcha when it also exists on the page if (typeof grecaptcha !== 'undefined') { $('#launcher').animate({'margin-right': '80px'}); }; }; setTimeout(customizeWidget, 2000); </script> </body></html>