// Cloud
CSA STAR Cloud Security Compliance Software
Cloud Security Alliance Security, Trust, Assurance and Risk programme.
Framework at a glance
Short name
CSA STAR
Version
—
Category
Cloud
Controls
50
What CSA STAR covers
50 controls across 32 domains — every one tracked, owned and evidenced in Cyber Horizon.
Policy
12 controls- AIS-01 Application and Interface Security Policy
- CCC-01 Change Management Policy
- CEK-01 Encryption and Key Management Entitlement Policy
- DSP-01 Data Security and Privacy Lifecycle Management
- HRS-01 Human Resources Policy
Standards
2 controls- AIS-02 Application Security Baseline Requirements
- CEK-04 Encryption Algorithm
Metrics
2 controls- AIS-03 Application Security Metrics
- BCR-04 Business Continuity Metrics
SDLC
1 controls- AIS-04 Secure Application Design and Development
Testing
2 controls- AIS-05 Automated Application Security Testing
- BCR-03 Business Continuity Testing
Automation
1 controls- AIS-06 Automated Secure Development
BCM
1 controls- BCR-01 Business Continuity Planning
BIA
1 controls- BCR-02 Risk Assessment and Impact Analysis
Tools
1 controls- CCC-02 Change Management Technology
Baseline
1 controls- CCC-03 Change Management Baseline
Key Management
2 controls- CEK-02 Key Generation
- CEK-06 Key Generation Best Practices
Encryption
1 controls- CEK-03 Sensitive Data Encryption
Change Management
1 controls- CEK-05 Encryption Change Management
Inventory
2 controls- DSP-02 Data Inventory and Classification
- UEM-02 Endpoint Inventory
Data Flows
1 controls- DSP-03 Data Flow Documentation
Governance
2 controls- DSP-04 Data Governance
- GRC-01 Governance Framework
Protection
2 controls- DSP-05 Sensitive Data Protection
- UEM-03 Endpoint Protection
Risk
1 controls- GRC-02 Risk Management Program
Compliance
1 controls- GRC-03 Legal Requirements
Screening
1 controls- HRS-02 Background Screening
MFA
1 controls- IAM-02 Strong Authentication
Credentials
1 controls- IAM-03 Credentials Management
Network
1 controls- IVS-02 Network Security
Architecture
1 controls- IVS-03 Network Architecture
Hardening
1 controls- IVS-04 OS Hardening and Base Controls
Logging
1 controls- LOG-02 Security Event Logging
Reporting
1 controls- SEF-02 Security Incident Reporting
Response
1 controls- SEF-03 Incident Response Planning
Third-Party
1 controls- STA-01 Supply Chain Management
Assessment
1 controls- STA-02 Third-Party Assessment
Malware
1 controls- TVM-02 Malware Protection
Vulnerabilities
1 controls- TVM-03 Vulnerability Management
How Cyber Horizon automates CSA STAR
Every CSA STAR control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is CSA STAR Cloud Security?
Cloud Security Alliance Security, Trust, Assurance and Risk programme.
How many controls does CSA STAR Cloud Security have?
CSA STAR Cloud Security has 50 controls in Cyber Horizon's catalogue, organised across 32 domains.
How does Cyber Horizon help with CSA STAR Cloud Security?
Cyber Horizon maps CSA STAR Cloud Security into a shared control library alongside every other framework you run, so evidence collected once counts towards CSA STAR and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Cloud frameworks
See CSA STAR mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of CSA STAR in Cyber Horizon.