CSA STAR (Security, Trust, Assurance, and Risk)
The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 — SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
Assessment Findings
| Code | Title |
|---|---|
| STAR-NONCONF-01 | Nonconformity Management |
Control Mapping
| Code | Title |
|---|---|
| STAR-CCM-01 | CCM Mapping Completeness |
Customer Transparency
| Code | Title |
|---|---|
| STAR-COMM-01 | Customer Communication of Status |
| STAR-INCIDENT-01 | Incident Notification to Registry Users |
| STAR-SHARED-01 | Shared Responsibility Disclosure |
Data Security and Privacy
Data lifecycle management, encryption, and privacy
| Code | Title |
|---|---|
| CSA-DATA-01 | Data Classification and Handling |
| CSA-DATA-02 | Encryption and Key Management |
| CSA-DATA-03 | Data Retention and Deletion |
| CSA-DATA-04 | Privacy by Design |
Infrastructure and Operations Security
Cloud infrastructure, identity, and operational security
| Code | Title |
|---|---|
| CSA-INF-01 | Information Sharing Agreements |
| CSA-INF-02 | Infrastructure and Virtualization Security |
| CSA-INF-03 | Security Monitoring and Logging |
| CSA-INF-04 | Incident Management |
| CSA-INF-05 | Business Continuity and Disaster Recovery |
Internal Assurance
| Code | Title |
|---|---|
| STAR-INTERNAL-01 | Internal Audit Coverage of STAR Scope |
Level 1 Self-Assessment
| Code | Title |
|---|---|
| STAR-L1-01 | Level 1 Self-Assessment Submission |
| STAR-L1-02 | Self-Assessment Refresh Cadence |
| STAR-L1-03 | Yeti or CAIQ Lite Option |
Level 2 Attestation
| Code | Title |
|---|---|
| STAR-L2-02 | STAR Attestation (SOC 2 + CCM) |
Level 2 Certification
| Code | Title |
|---|---|
| STAR-L2-01 | STAR Certification (ISO/IEC 27001 + CCM) |
| STAR-L2-04 | Accredited Assessor Selection |
| STAR-L2-05 | Maturity Model Scoring |
| STAR-L2-06 | Surveillance and Recertification Cycle |
Level 2 Regional
| Code | Title |
|---|---|
| STAR-L2-03 | STAR C-STAR (China Market) |
Level 3 Continuous
| Code | Title |
|---|---|
| STAR-L3-01 | Continuous Auditing Capability |
| STAR-L3-02 | STARWatch / Continuous Evidence |
Program
| Code | Title |
|---|---|
| STAR-PROG-01 | STAR Program Eligibility |
| STAR-RETIRE-01 | Status Withdrawal and Suspension |
Registry
| Code | Title |
|---|---|
| STAR-REG-01 | STAR Registry Listing |
| STAR-REG-02 | Registry Update Process |
Risk Management
| Code | Title |
|---|---|
| STAR-RISK-01 | Risk Treatment Alignment |
Scoping
| Code | Title |
|---|---|
| STAR-SCOPE-01 | Service Scope Definition |
Self-Assessment Quality
| Code | Title |
|---|---|
| STAR-CAIQ-01 | CAIQ Response Accuracy |
Supply Chain Transparency
| Code | Title |
|---|---|
| STAR-SUPPLY-01 | Subservice Provider Disclosure |
Threat and Vulnerability Management
Vulnerability management, penetration testing, and DevSecOps
| Code | Title |
|---|---|
| AESCSF-TVM-1 | Vulnerability Assessment |
| AESCSF-TVM-2 | Threat Intelligence |
| AESCSF-TVM-3 | Patch Management |
| CSA-TVM-01 | Vulnerability Management |
| CSA-TVM-02 | Penetration Testing |
| CSA-TVM-03 | Application Security (DevSecOps) |
Your Compliance Coverage
If you comply with CSA STAR (Security, Trust, Assurance, and Risk), you already cover:
CSA CCM v4
35%
14 controls mapped
Compare →Singapore Government Instruction Manual on ICT&SS Management (IM8)
35%
14 controls mapped
Compare →PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments
33%
13 controls mapped
Compare →+ 661 more: Oman National Cybersecurity Framework (33%), TISAX — Trusted Information Security Assessment Exchange (33%)
See all 664 mapped frameworks ↓Maps to 664 other frameworks
Frequently Asked Questions
What is CSA STAR (Security, Trust, Assurance, and Risk)?
CSA STAR (Security, Trust, Assurance, and Risk) is a compliance framework from International with 18 domains and 40 controls. The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 — SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CSA STAR (Security, Trust, Assurance, and Risk) have?
CSA STAR (Security, Trust, Assurance, and Risk) has 40 controls organised across 18 domains. The largest domains are Threat and Vulnerability Management (6 controls), Infrastructure and Operations Security (5 controls), Data Security and Privacy (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CSA STAR (Security, Trust, Assurance, and Risk) map to?
CSA STAR (Security, Trust, Assurance, and Risk) maps to 664 other compliance frameworks. The top mapping partners are CSA CCM v4 (35% coverage), Singapore Government Instruction Manual on ICT&SS Management (IM8) (35% coverage), PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CSA STAR (Security, Trust, Assurance, and Risk) compliance?
Start your CSA STAR (Security, Trust, Assurance, and Risk) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CSA STAR (Security, Trust, Assurance, and Risk) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required