Back to Frameworks

CSA STAR (Security, Trust, Assurance, and Risk)

International
vCCM v4.0 (2021)
6 domains
24 controls

The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 - SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

CSA STAR: Assurance Quality and Lifecycle

4 controls
Controls in the CSA STAR: Assurance Quality and Lifecycle domain of CSA STAR (Security, Trust, Assurance, and Risk)4 controls
CodeTitle
STAR-INTERNAL-01Internal audit coverage of STAR scope
STAR-NONCONF-01Nonconformity and corrective action management
STAR-RETIRE-01Status withdrawal and suspension
STAR-RISK-01Risk treatment alignment with CCM

CSA STAR: Level 1 Self-Assessment (CAIQ)

4 controls
Controls in the CSA STAR: Level 1 Self-Assessment (CAIQ) domain of CSA STAR (Security, Trust, Assurance, and Risk)4 controls
CodeTitle
STAR-CAIQ-01CAIQ response accuracy and completeness
STAR-CCM-01CCM control mapping completeness
STAR-L1-01Level 1 CAIQ self-assessment submission
STAR-L1-02Self-assessment refresh cadence

CSA STAR: Level 2 Third-Party Assurance

6 controls
Controls in the CSA STAR: Level 2 Third-Party Assurance domain of CSA STAR (Security, Trust, Assurance, and Risk)6 controls
CodeTitle
STAR-L2-01STAR Certification (ISO/IEC 27001 + CCM)
STAR-L2-02STAR Attestation (SOC 2 + CCM)
STAR-L2-03C-STAR assessment (Greater China market)
STAR-L2-04Accredited assessor / auditor selection
STAR-L2-05Maturity model scoring
STAR-L2-06Surveillance and recertification cycle

CSA STAR: Level 3 Continuous

2 controls
Controls in the CSA STAR: Level 3 Continuous domain of CSA STAR (Security, Trust, Assurance, and Risk)2 controls
CodeTitle
STAR-L3-01Continuous auditing capability
STAR-L3-02Continuous evidence publication

CSA STAR: Program, Scope and Shared Responsibility

4 controls
Controls in the CSA STAR: Program, Scope and Shared Responsibility domain of CSA STAR (Security, Trust, Assurance, and Risk)4 controls
CodeTitle
STAR-PROG-01STAR Program eligibility and assurance-level selection
STAR-SCOPE-01Service scope definition for the assessment
STAR-SHARED-01Shared responsibility disclosure
STAR-SUPPLY-01Subservice and supply chain disclosure

CSA STAR: Registry and Customer Transparency

4 controls
Controls in the CSA STAR: Registry and Customer Transparency domain of CSA STAR (Security, Trust, Assurance, and Risk)4 controls
CodeTitle
STAR-COMM-01Customer communication of assurance status
STAR-INCIDENT-01Incident notification to registry users
STAR-REG-01STAR Registry listing
STAR-REG-02Registry update process

Your Compliance Coverage

If you comply with CSA STAR (Security, Trust, Assurance, and Risk), you already cover:

Maps to 14 other frameworks

24 total controls
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
11 source controls mapped|4 target controls covered
46%
ISO/IEC 42001:2023
2 source controls mapped|2 target controls covered
8%
ISO 22301:2019
2 source controls mapped|2 target controls covered
8%
ISO 9001:2015
2 source controls mapped|2 target controls covered
8%
ISO 31000:2018
1 source controls mapped|1 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
4%
ISO 22000:2018
1 source controls mapped|1 target controls covered
4%
ISO 55001:2014
1 source controls mapped|1 target controls covered
4%
ISO 37301:2021
1 source controls mapped|1 target controls covered
4%
ISO 37001:2016
1 source controls mapped|1 target controls covered
4%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|1 target controls covered
4%
ISO 27701:2019
1 source controls mapped|1 target controls covered
4%
ISO 14001:2015
1 source controls mapped|1 target controls covered
4%
ISO 10005:2005
1 source controls mapped|1 target controls covered
4%

Frequently Asked Questions

What is CSA STAR (Security, Trust, Assurance, and Risk)?

CSA STAR (Security, Trust, Assurance, and Risk) is a compliance framework from International with 6 domains and 24 controls. The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 - SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CSA STAR (Security, Trust, Assurance, and Risk) have?

CSA STAR (Security, Trust, Assurance, and Risk) has 24 controls organised across 6 domains. The largest domains are CSA STAR: Level 2 Third-Party Assurance (6 controls), CSA STAR: Assurance Quality and Lifecycle (4 controls), CSA STAR: Level 1 Self-Assessment (CAIQ) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CSA STAR (Security, Trust, Assurance, and Risk) map to?

CSA STAR (Security, Trust, Assurance, and Risk) maps to 14 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (46% coverage), ISO/IEC 42001:2023 (8% coverage), ISO 22301:2019 (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with CSA STAR (Security, Trust, Assurance, and Risk) compliance?

Start your CSA STAR (Security, Trust, Assurance, and Risk) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CSA STAR (Security, Trust, Assurance, and Risk) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required