Skip to content
Cyber Horizon
All frameworks

// Cloud

CSA STAR Cloud Security Compliance Software

Cloud Security Alliance Security, Trust, Assurance and Risk programme.

Framework at a glance

Short name

CSA STAR

Version

Category

Cloud

Controls

50

What CSA STAR covers

50 controls across 32 domains — every one tracked, owned and evidenced in Cyber Horizon.

Policy

12 controls
  • AIS-01 Application and Interface Security Policy
  • CCC-01 Change Management Policy
  • CEK-01 Encryption and Key Management Entitlement Policy
  • DSP-01 Data Security and Privacy Lifecycle Management
  • HRS-01 Human Resources Policy

Standards

2 controls
  • AIS-02 Application Security Baseline Requirements
  • CEK-04 Encryption Algorithm

Metrics

2 controls
  • AIS-03 Application Security Metrics
  • BCR-04 Business Continuity Metrics

SDLC

1 controls
  • AIS-04 Secure Application Design and Development

Testing

2 controls
  • AIS-05 Automated Application Security Testing
  • BCR-03 Business Continuity Testing

Automation

1 controls
  • AIS-06 Automated Secure Development

BCM

1 controls
  • BCR-01 Business Continuity Planning

BIA

1 controls
  • BCR-02 Risk Assessment and Impact Analysis

Tools

1 controls
  • CCC-02 Change Management Technology

Baseline

1 controls
  • CCC-03 Change Management Baseline

Key Management

2 controls
  • CEK-02 Key Generation
  • CEK-06 Key Generation Best Practices

Encryption

1 controls
  • CEK-03 Sensitive Data Encryption

Change Management

1 controls
  • CEK-05 Encryption Change Management

Inventory

2 controls
  • DSP-02 Data Inventory and Classification
  • UEM-02 Endpoint Inventory

Data Flows

1 controls
  • DSP-03 Data Flow Documentation

Governance

2 controls
  • DSP-04 Data Governance
  • GRC-01 Governance Framework

Protection

2 controls
  • DSP-05 Sensitive Data Protection
  • UEM-03 Endpoint Protection

Risk

1 controls
  • GRC-02 Risk Management Program

Compliance

1 controls
  • GRC-03 Legal Requirements

Screening

1 controls
  • HRS-02 Background Screening

MFA

1 controls
  • IAM-02 Strong Authentication

Credentials

1 controls
  • IAM-03 Credentials Management

Network

1 controls
  • IVS-02 Network Security

Architecture

1 controls
  • IVS-03 Network Architecture

Hardening

1 controls
  • IVS-04 OS Hardening and Base Controls

Logging

1 controls
  • LOG-02 Security Event Logging

Reporting

1 controls
  • SEF-02 Security Incident Reporting

Response

1 controls
  • SEF-03 Incident Response Planning

Third-Party

1 controls
  • STA-01 Supply Chain Management

Assessment

1 controls
  • STA-02 Third-Party Assessment

Malware

1 controls
  • TVM-02 Malware Protection

Vulnerabilities

1 controls
  • TVM-03 Vulnerability Management

How Cyber Horizon automates CSA STAR

Every CSA STAR control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is CSA STAR Cloud Security?

Cloud Security Alliance Security, Trust, Assurance and Risk programme.

How many controls does CSA STAR Cloud Security have?

CSA STAR Cloud Security has 50 controls in Cyber Horizon's catalogue, organised across 32 domains.

How does Cyber Horizon help with CSA STAR Cloud Security?

Cyber Horizon maps CSA STAR Cloud Security into a shared control library alongside every other framework you run, so evidence collected once counts towards CSA STAR and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See CSA STAR mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of CSA STAR in Cyber Horizon.