aws AWS Security Blog ·

AWS Releases CSA Compliance Guide for Cloud Security

blogsecuritycomplianceawsengineer
announcement

AWS has released a new guide that maps the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1 to AWS services and implementation practices. This resource helps organizations using AWS plan, implement, and evidence controls for CSA STAR certification. The guide details how to use the CCM's Shared Security Responsibility Model alongside AWS's own model, providing specific guidance for customer-owned and shared controls.

  • New CSA Compliance Guide on AWS Available
  • Purpose of the CSA Compliance Guide
  • Guide Details Implementation and Evidence
Notes (3)
  • New CSA Compliance Guide on AWS Available

    AWS Security Assurance Services has released the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS). This guide maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 (CCM) to AWS services and recommended implementation practices.

  • Purpose of the CSA Compliance Guide

    The guide is designed to assist organizations using AWS in planning, implementing, and evidencing controls relevant to their CCM scope, particularly those pursuing or maintaining CSA STAR certification. It clarifies how to use the CCM's Shared Security Responsibility Model in conjunction with the AWS Shared Responsibility Model.

  • Guide Details Implementation and Evidence

    For each control, the guide outlines applicability, implementation methods on AWS, common pitfalls, and examples for evidence during assessments. It highlights that while using a CSA STAR-certified AWS service is beneficial, customers remain responsible for service configuration, access management, data protection, and additional controls.

Read the original announcement →

https://aws.amazon.com/blogs/security/announcing-the-cloud-security-alliance-on-aws-compliance-guide/

Related releases