CAIQ (CSA)
Consensus Assessment Initiative Questionnaire for cloud providers
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Application and Interface Security
| Code | Title |
|---|---|
| AIS-01 | Application and Interface Security Policy and Procedures |
Audit and Assurance
| Code | Title |
|---|---|
| A&A-01 | Audit and Assurance Policy and Procedures |
Business Continuity and Operational Resilience
| Code | Title |
|---|---|
| BCR-01 | Business Continuity Management Policy |
CAIQ (CSA): Cloud Governance
Governance of cloud security (CAIQ (CSA))
| Code | Title |
|---|---|
| CAIQ-01 | Shared responsibility model definition |
| CAIQ-02 | Cloud security policy and strategy |
| CAIQ-03 | Cloud risk assessment |
| CAIQ-04 | Regulatory compliance for cloud services |
| CAIQ-05 | Cloud security roles and responsibilities |
CAIQ (CSA): Cloud Infrastructure Security
Securing cloud infrastructure (CAIQ (CSA))
| Code | Title |
|---|---|
| CAIQ-16 | Virtual network segmentation |
| CAIQ-17 | Container and serverless security |
| CAIQ-18 | Cloud workload protection |
| CAIQ-19 | Image and template hardening |
| CAIQ-20 | Cloud configuration management |
CAIQ (CSA): Cloud Operations & Monitoring
Operating and monitoring cloud securely (CAIQ (CSA))
| Code | Title |
|---|---|
| CAIQ-21 | Cloud security monitoring and logging |
| CAIQ-22 | Incident response in cloud |
| CAIQ-23 | Cloud vulnerability management |
| CAIQ-24 | Cloud change management |
| CAIQ-25 | Service level agreement management |
CAIQ (CSA): Data Protection in Cloud
Protecting data in cloud services (CAIQ (CSA))
| Code | Title |
|---|---|
| CAIQ-11 | Data classification for cloud |
| CAIQ-12 | Encryption of cloud-stored data |
| CAIQ-13 | Data residency and sovereignty |
| CAIQ-14 | Data backup and recovery in cloud |
| CAIQ-15 | Secure data deletion in cloud |
CAIQ (CSA): Identity & Access in Cloud
Identity management in cloud environments (CAIQ (CSA))
| Code | Title |
|---|---|
| CAIQ-06 | Cloud identity management |
| CAIQ-07 | Multi-factor authentication for cloud |
| CAIQ-08 | Privileged access in cloud environments |
| CAIQ-09 | Federation and single sign-on |
| CAIQ-10 | API security and access tokens |
Change Control and Configuration Management
| Code | Title |
|---|---|
| CCC-01 | Change Management Policy |
Cryptography, Encryption and Key Management
| Code | Title |
|---|---|
| CEK-01 | Encryption and Key Management Policy |
Data Security and Privacy Lifecycle
| Code | Title |
|---|---|
| DSP-01 | Disposal and End-of-Mission |
| DSP-02 | Data Inventory |
Datacenter Security
| Code | Title |
|---|---|
| DCS-01 | Off-site Equipment Disposal |
Governance, Risk and Compliance
| Code | Title |
|---|---|
| GRC-01 | Governance Program |
Human Resources
| Code | Title |
|---|---|
| HRS-01 | Background Screening |
| HRS-02 | Security Training |
Identity and Access Management
| Code | Title |
|---|---|
| IAM-01 | Identity and Access Management Policy |
| IAM-02 | Strong Authentication |
Infrastructure and Virtualization
| Code | Title |
|---|---|
| IVS-01 | Infrastructure and Virtualization Security |
Interoperability and Portability
| Code | Title |
|---|---|
| IPY-01 | Interoperability and Portability |
Logging and Monitoring
| Code | Title |
|---|---|
| LOG-01 | Logging and Monitoring |
Security Incident Management
| Code | Title |
|---|---|
| SEF-01 | Security Incident Management Policy |
Supply Chain Management
| Code | Title |
|---|---|
| STA-01 | SSRM Policy and Procedures |
Threat and Vulnerability Management
| Code | Title |
|---|---|
| TVM-01 | Threat and Vulnerability Management Policy |
Universal Endpoint Management
| Code | Title |
|---|---|
| UEM-01 | Endpoint Management |
Your Compliance Coverage
If you comply with CAIQ (CSA), you already cover:
C5 (Germany)
44%
20 controls mapped
Compare →Azure Security Benchmark
44%
20 controls mapped
Compare →AWS Well-Architected Security Pillar
44%
20 controls mapped
Compare →+ 658 more: ISMAP (Japan) (44%), NIST SP 800-190 (44%)
See all 661 mapped frameworks ↓Maps to 661 other frameworks
Frequently Asked Questions
What is CAIQ (CSA)?
CAIQ (CSA) is a compliance framework from International with 22 domains and 45 controls. Consensus Assessment Initiative Questionnaire for cloud providers It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CAIQ (CSA) have?
CAIQ (CSA) has 45 controls organised across 22 domains. The largest domains are CAIQ (CSA): Cloud Governance (5 controls), CAIQ (CSA): Cloud Infrastructure Security (5 controls), CAIQ (CSA): Cloud Operations & Monitoring (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CAIQ (CSA) map to?
CAIQ (CSA) maps to 661 other compliance frameworks. The top mapping partners are C5 (Germany) (44% coverage), Azure Security Benchmark (44% coverage), AWS Well-Architected Security Pillar (44% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CAIQ (CSA) compliance?
Start your CAIQ (CSA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CAIQ (CSA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required