verified_user
Standardful
首頁chevron_right標準chevron_rightCSA STAR
現行有效國際標準update 最後更新:2024年7月

CSA STAR

雲安全聯盟 安全、信任、保證和風險計畫

apartment發布組織:雲端安全聯盟(CSA)

標準簡介

CSA STAR(安全、信任、保證與風險)是由雲端安全聯盟開發的雲端安全保證計畫。它透過三個保證級別(自我評估、第三方認證和持續監控)為評估雲端服務供應商的安全狀況提供了全面框架。該計畫基於雲端控制矩陣(CCM)構建,定義了 197 個雲端運算特定的安全控制目標。

CSA STAR 已成為廣泛認可的雲端安全基準,數千家供應商在公開的 STAR 登錄冊中列出。二級認證將 CCM 評估與 ISO/IEC 27001 認證或 SOC 2 鑑證相結合,對通用和雲端特定安全控制進行全面評估。該計畫幫助企業客戶在採購和供應商風險管理過程中比較雲端服務供應商。

cloud

Three Assurance Levels

Offers Level 1 (self-assessment), Level 2 (third-party certification/attestation), and Level 3 (continuous monitoring) to match different risk appetites and maturity levels.

grid_view

Cloud Controls Matrix

Built on the CCM framework with 197 cloud-specific control objectives mapped to ISO 27001, NIST, PCI DSS, and other standards for unified cloud governance.

verified_user

Registry Transparency

All certified providers are listed in the public STAR Registry, enabling customers to compare cloud provider security postures before procurement.

list_alt CCM Control Domains

  • Audit assurance & compliance
  • Application & interface security
  • Business continuity management & operational resilience
  • Change control & configuration management
  • Data security & privacy lifecycle management
  • Encryption & key management
  • Identity & access management
  • Infrastructure & virtualization security

Who Needs to Comply?

groups

Cloud service providers (IaaS, PaaS, SaaS) seeking to demonstrate security posture to enterprise customers, and organizations evaluating cloud providers during vendor due diligence.

Key Requirements

1

Cloud Controls Matrix Compliance

Implement controls across all applicable CCM domains covering 197 control objectives aligned with cloud-specific risks and mapped to ISO 27001 Annex A controls.

2

CAIQ Self-Assessment

Complete the Consensus Assessment Initiative Questionnaire (CAIQ) documenting how your organization addresses each CCM control objective for Level 1 registration.

3

Third-Party Audit (Level 2)

Engage an accredited auditor to perform an independent assessment combining CSA CCM with ISO 27001 certification or SOC 2 attestation for Level 2 STAR certification.

4

Continuous Monitoring (Level 3)

Implement continuous security monitoring and automated compliance verification to maintain real-time assurance of control effectiveness.

Penalties & Enforcement

warning

No direct legal penalties — CSA STAR is a voluntary certification. However, lack of STAR certification can result in exclusion from enterprise procurement processes, especially in regulated industries like finance and healthcare.

官方文件

查看全部

實施時間線

groups
2008年11月
Cloud Security Alliance concept founded at ISSA CISO Forum
description
2009年
CSA incorporated; published first Security Guidance for Cloud Computing
rocket_launch
2011年
STAR program launched to improve cloud trust and assurance
verified_user
2013年
CSA STAR Certification (Level 2) launched with third-party audits
update
2021年
Cloud Controls Matrix v4 released with 197 control objectives
psychology
2025年11月
STAR for AI Level 2 introduced combining AI-CAIQ with ISO 42001

相關分類