Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
CSA Security Update

CSA Security Update

John DiMaria; Director of Operations Excellence

CSA STAR is the industry's most powerful program for security assurance in the cloud.The Security Trust Assurance and Risk (STAR) Program encompasses key principles of transparency, rigorous auditing, and harmonization of standards. Companies who use STAR indicate best practices and validate the security posture of their cloud offerings.This podcast series explores CSA STAR as well as CSA best practices and research along with associated technologies and tools.

bookmark
Share icon

All episodes

Best episodes

Top 10 CSA Security Update Episodes

Goodpods has curated a list of the 10 best CSA Security Update episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to CSA Security Update for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite CSA Security Update episode by adding your comments to the episode page.

CSA Security Update - The Business Value of STAR Attestation
play

10/16/20 • 37 min

As organizations look to cloud services to process more sensitive and critical data, security, and risk management teams require tools to quickly assess and understand the types and rigor of security controls applied by cloud service providers. CSA STAR Attestation is the first cloud-specific attestation program designed to meet this need. Based on the CSA’s Cloud Controls Matrix (CCM), STAR is the only meta-framework of cloud-specific security controls, mapped to leading standards, that enables third party audit review to give security teams the support and trust they require to enable this move to the cloud.
Listen as we interview Ashwin Chaudhary Director and CEO of Accedere group and discuss STAR Attestation, the advantages of SOC2 plus CCM, and the business value it brings to organizations.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode
CSA Security Update - Sneak Preview of CSA Summit and RSA February 24 - 27 2020
play

02/11/20 • 5 min

Excerpt from the most recent PODCAST interview with Jim Reavis; Co-Founder and CEO of Cloud Security Alliance discussing the activities and speakers at the upcoming CSA Summit at RSA!

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

As organizations look to cloud services to process more sensitive and critical data, security and risk management teams require tools to quickly assess and understand the types and rigor of security controls applied by cloud service providers. CSA STAR Attestation is the first cloud-specific attestation program designed to meet this need. CSA STAR Attestation is a collaboration between CSA and the AICPA to provide guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Services Criteria) and the CSA Cloud Controls Matrix.
Listen as we interview Debbie Zaller; Principal, practice leader, and SME for Schellman & Company, LLC who leads the Midwest Region along with the Privacy, SOC 2 and SOC 3 service lines. We take you inside a STAR attestation engagement following the process from start to finish along with discussing the value having successfully completed a STAR Attestation audit.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

In this insightful episode, we explore the intricate world of GDPR compliance and how tools like codes of conduct can support cloud service providers. Our special guest, Gabriela Mercuri, Managing Director of SCOPE Europe, shares her expertise on the EU Cloud Code of Conduct (EU Cloud CoC), a pivotal GDPR compliance tool designed specifically for the cloud industry.

Join us as we discuss the significance of these codes of conduct, their role in ensuring data protection, and how they offer a practical framework for companies striving to meet GDPR requirements. We will also delve into the ongoing collaboration between the EU Cloud CoC and the CSA, highlighting how this partnership enhances transparency, trust, and compliance across the cloud services landscape.

Whether you’re a cloud service provider, a data protection professional, or simply interested in GDPR compliance, this episode will provide valuable insights into the evolving landscape of data protection and the practical steps companies can take to ensure compliance.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

As organizations look to cloud services to process more sensitive and critical data, security and risk management teams require tools to quickly assess and understand the types and rigor of security controls applied by cloud service providers. CSA STAR Attestation is the first cloud-specific attestation program designed to meet this need. CSA STAR Attestation is a collaboration between CSA and the AICPA to provide guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles,AT 101) and the CSA Cloud Controls Matrix.
Requirements for the cloud can be quite different than non-cloud environments, so a generic approach to security compliance is not a viable solution for providing evidence of assurance in the cloud. Unique considerations must be given to:
• Understanding the scope of the cloud computing environment.
• Do the current security controls cover the unique aspects of the cloud environment?
• Can the current risk assessment capture the risks correctly?
• Audit trails that prove the effectiveness
Join me as I interview two Principles from Schellman, Ryan Mackie and Gary Nelson as they take you on a journey down the road to Cloud Attestation and provide details of the audit, advice on implementation and the value proposition.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

As we’re seeing more cyber attacks in software, open-source software, etc., there is a crucial need for businesses to future-proof against emerging threats.
- How can companies take preventative (vs reactive) measures, including embedding security into the software as it’s being built (security by design)
- Urgency for daily scans
- How the CCM and STAR Program can facilitate reducing risk and understanding the Shared Responsibility Model.
- What to expect in 2022 (more supply chain attacks expected)
Get the answers to all these topics and more as we interview Farshad Abasi, Founder and Chief Security Officer of Forward Security. In this episode, we discuss software design and development, network and system architecture and cybersecurity, management.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

STAR Certification is the internationally recognized cloud security certification program from CSA that specifies comprehensive and stringent cloud security requirements on CSPs. The CSA Cloud Controls Matrix (CCM) is the de-facto standard for cloud security assurance and compliance, widely used in assessing cloud security performance of cloud implementations.
Ribose Achieved the world’s first STAR Certification with CSA Cloud Controls Matrix v4 that was released in January 2021.
Recorded live from Hong Kong, Ronald Tse; CEO and founder of RIBOSE, takes us through their journey with STAR over the years and discusses the value, ROI and future of STAR and the work being done to increase the value of the auditing and compliance landscape.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

As the businesses change the world changes and so does the standards industry. Being up to speed on those changes and paying attention to such changes can help company's succeed.
CSA is dedicated to keep our followers up-to-date on these changes and how they may affect the users and provide guidance and information on what can be expected moving forward as well as what organizations should be concerned about as well as tips on preparing for these changes.
Listen as we interview Ryan Mackie of Schellman and Eric Hibbard of Samsung, both members of SC27 and discuss the most critical changes already released as well as those yet to come and what organizations can expect as well as what you should be thinking about.

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode
CSA Security Update - Fighting Ransomeware in the Cloud
play

03/11/22 • 19 min

In order to fight against ransomware in the cloud, you need to have a multifaceted strategy so you can be better prepared to protect against and respond to attacks. But IT organizations often struggle to understand the priorities and the appropriate approach to mitigate risk and minimize the impact of ransomware. With more tools and software, organizations many times throw money at technology solutions and do not address people and processes not to mention sector-specific controls to help detect, prevent, respond to ransomware not to mention other malware attacks.
Listen as we discuss the subject and solutions with Greg Edwards; CEO of CryptoStopper.
In this episode we get into:

  • Practical steps to defend against Ransomeware
  • The importance of implementing sector-specific controls as there is no "Onesize fits all solution".
  • The powerful impact you can have by including all of People, Process and Technology

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

https://cloudsecurityalliance.org/star/

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does CSA Security Update have?

CSA Security Update currently has 47 episodes available.

What topics does CSA Security Update cover?

The podcast is about Cloud, Security, Training, Saas, Podcasts, Arts and Privacy.

What is the most popular episode on CSA Security Update?

The episode title 'Application Security - The Importance of Future Proofing Your Process' is the most popular.

What is the average episode length on CSA Security Update?

The average episode length on CSA Security Update is 32 minutes.

How often are episodes of CSA Security Update released?

Episodes of CSA Security Update are typically released every 26 days.

When was the first episode of CSA Security Update?

The first episode of CSA Security Update was released on May 13, 2019.

Show more FAQ

Toggle view more icon

Comments