CSA STAR (Security, Trust, Assurance, and Risk)
What is CSA STAR (Security, Trust, Assurance, and Risk)?
The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) programme provides a comprehensive framework for cloud security assurance. Based on the CSA Cloud Controls Matrix (CCM), STAR offers three levels of assurance: self-assessment (Level 1), third-party audit (Level 2 - SOC 2 or ISO 27001 based), and continuous monitoring (Level 3). It comprises 24 controls organised across 6 domains, published by Cloud Security Alliance, and applies in International.
How CSA STAR (Security, Trust, Assurance, and Risk) maps to other frameworks
All 24 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 6 domains CSA STAR (Security, Trust, Assurance, and Risk) groups its controls into
Where CSA STAR (Security, Trust, Assurance, and Risk) overlaps with the standards you already hold
What CSA STAR (Security, Trust, Assurance, and Risk) means in your sector
What CSA STAR (Security, Trust, Assurance, and Risk) means for your job
Questions people ask about CSA STAR (Security, Trust, Assurance, and Risk)
What is CSA STAR?
How many controls does CSA STAR have?
Where does CSA STAR apply?
What frameworks does CSA STAR map to?
How do I get started with CSA STAR compliance?
Query CSA STAR (Security, Trust, Assurance, and Risk) programmatically
CSA STAR (Security, Trust, Assurance, and Risk), its 24 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
CSA STAR (Security, Trust, Assurance, and Risk) API reference and MCP config →What CSA STAR (Security, Trust, Assurance, and Risk) requires, control by control
Each page carries the requirement text for one CSA STAR (Security, Trust, Assurance, and Risk) control and what an assessor expects to see as evidence.
- STAR-CAIQ-01 CAIQ response accuracy and completeness
- STAR-CCM-01 CCM control mapping completeness
- STAR-COMM-01 Customer communication of assurance status
- STAR-INTERNAL-01 Internal audit coverage of STAR scope
- STAR-L1-01 Level 1 CAIQ self-assessment submission
- STAR-L2-01 STAR Certification (ISO/IEC 27001 + CCM)
- STAR-L2-02 STAR Attestation (SOC 2 + CCM)
- STAR-L2-06 Surveillance and recertification cycle
- STAR-NONCONF-01 Nonconformity and corrective action management
- STAR-PROG-01 STAR Program eligibility and assurance-level selection
How ready are you for CSA STAR (Security, Trust, Assurance, and Risk)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.