CSA STAR (Security, Trust, Assurance, and Risk)
The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 — SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Data Security and Privacy
Data lifecycle management, encryption, and privacy
| Code | Title |
|---|---|
| CSA-DATA-01 | Data Classification and Handling |
| CSA-DATA-02 | Encryption and Key Management |
| CSA-DATA-03 | Data Retention and Deletion |
| CSA-DATA-04 | Privacy by Design |
Infrastructure and Operations Security
Cloud infrastructure, identity, and operational security
| Code | Title |
|---|---|
| CSA-INF-01 | Identity and Access Management |
| CSA-INF-02 | Infrastructure and Virtualization Security |
| CSA-INF-03 | Security Monitoring and Logging |
| CSA-INF-04 | Incident Management |
| CSA-INF-05 | Business Continuity and Disaster Recovery |
Threat and Vulnerability Management
Vulnerability management, penetration testing, and DevSecOps
| Code | Title |
|---|---|
| AESCSF-TVM-1 | Vulnerability Assessment |
| AESCSF-TVM-2 | Threat Intelligence |
| AESCSF-TVM-3 | Patch Management |
| CSA-TVM-01 | Vulnerability Management |
| CSA-TVM-02 | Penetration Testing |
| CSA-TVM-03 | Application Security (DevSecOps) |
Maps to 641 other frameworks
Frequently Asked Questions
What is CSA STAR (Security, Trust, Assurance, and Risk)?
CSA STAR (Security, Trust, Assurance, and Risk) is a compliance framework from International with 3 domains and 15 controls. The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 — SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CSA STAR (Security, Trust, Assurance, and Risk) have?
CSA STAR (Security, Trust, Assurance, and Risk) has 15 controls organised across 3 domains. The largest domains are Threat and Vulnerability Management (6 controls), Infrastructure and Operations Security (5 controls), Data Security and Privacy (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CSA STAR (Security, Trust, Assurance, and Risk) map to?
CSA STAR (Security, Trust, Assurance, and Risk) maps to 641 other compliance frameworks. The top mapping partners are CSA CCM v4 (93% coverage), Singapore Government Instruction Manual on ICT&SS Management (IM8) (93% coverage), PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments (87% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CSA STAR (Security, Trust, Assurance, and Risk) compliance?
Start your CSA STAR (Security, Trust, Assurance, and Risk) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CSA STAR (Security, Trust, Assurance, and Risk) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 15 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required