CSA STAR (Security, Trust, Assurance, and Risk)
The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 - SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations.
CSA STAR (Security, Trust, Assurance, and Risk) is a compliance framework from International with 6 domains and 24 controls that map to 13 other frameworks. The largest domains are CSA STAR: Level 2 Third-Party Assurance (6 controls), CSA STAR: Assurance Quality and Lifecycle (4 controls), CSA STAR: Level 1 Self-Assessment (CAIQ) (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
CSA STAR: Assurance Quality and Lifecycle
| Code | Title |
|---|---|
| STAR-INTERNAL-01 | Internal audit coverage of STAR scope |
| STAR-NONCONF-01 | Nonconformity and corrective action management |
| STAR-RETIRE-01 | Status withdrawal and suspension |
| STAR-RISK-01 | Risk treatment alignment with CCM |
CSA STAR: Level 1 Self-Assessment (CAIQ)
| Code | Title |
|---|---|
| STAR-CAIQ-01 | CAIQ response accuracy and completeness |
| STAR-CCM-01 | CCM control mapping completeness |
| STAR-L1-01 | Level 1 CAIQ self-assessment submission |
| STAR-L1-02 | Self-assessment refresh cadence |
CSA STAR: Level 2 Third-Party Assurance
| Code | Title |
|---|---|
| STAR-L2-01 | STAR Certification (ISO/IEC 27001 + CCM) |
| STAR-L2-02 | STAR Attestation (SOC 2 + CCM) |
| STAR-L2-03 | C-STAR assessment (Greater China market) |
| STAR-L2-04 | Accredited assessor / auditor selection |
| STAR-L2-05 | Maturity model scoring |
| STAR-L2-06 | Surveillance and recertification cycle |
CSA STAR: Level 3 Continuous
| Code | Title |
|---|---|
| STAR-L3-01 | Continuous auditing capability |
| STAR-L3-02 | Continuous evidence publication |
CSA STAR: Program, Scope and Shared Responsibility
| Code | Title |
|---|---|
| STAR-PROG-01 | STAR Program eligibility and assurance-level selection |
| STAR-SCOPE-01 | Service scope definition for the assessment |
| STAR-SHARED-01 | Shared responsibility disclosure |
| STAR-SUPPLY-01 | Subservice and supply chain disclosure |
CSA STAR: Registry and Customer Transparency
| Code | Title |
|---|---|
| STAR-COMM-01 | Customer communication of assurance status |
| STAR-INCIDENT-01 | Incident notification to registry users |
| STAR-REG-01 | STAR Registry listing |
| STAR-REG-02 | Registry update process |
Your Compliance Coverage
If you comply with CSA STAR (Security, Trust, Assurance, and Risk), you already cover:
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
46%
11 controls mapped
Compare →ISO 9001:2015
8%
2 controls mapped
Compare →ISO 31000:2018
4%
1 controls mapped
Compare →+ 10 more: ISO/IEC 23894:2023 (4%), ISO 22301:2019 (4%)
See all 13 mapped frameworks ↓Maps to 13 other frameworks
What is CSA STAR (Security, Trust, Assurance, and Risk) and who does it apply to?
CSA STAR (Security, Trust, Assurance, and Risk) is a compliance framework from International with 6 domains and 24 controls. The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 - SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). The CCM provides 197 control objectives across 17 domains mapped to major standards and regulations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does CSA STAR (Security, Trust, Assurance, and Risk) actually require?
CSA STAR (Security, Trust, Assurance, and Risk) has 24 controls organised across 6 domains. The largest domains are CSA STAR: Level 2 Third-Party Assurance (6 controls), CSA STAR: Assurance Quality and Lifecycle (4 controls), CSA STAR: Level 1 Self-Assessment (CAIQ) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of CSA STAR (Security, Trust, Assurance, and Risk) do I already cover?
CSA STAR (Security, Trust, Assurance, and Risk) maps to 13 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (46% coverage), ISO 9001:2015 (8% coverage), ISO 31000:2018 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement CSA STAR (Security, Trust, Assurance, and Risk)?
Start your CSA STAR (Security, Trust, Assurance, and Risk) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CSA STAR (Security, Trust, Assurance, and Risk) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required