The Consensus Assessments
Initiative Questionnaire (CAIQ) is a series of yes/no questions provided
by the Cloud Security Alliance (CSA) to help organizations evaluate how
well a cloud provider follows best practices. The CAIQ questionnaire can be
customized to suit the security requirements of each cloud customer and help
potential customers build assessment processes for engaging with cloud
providers.
The questionnaire was designed to
address one of the leading concerns that companies have when moving to the
cloud: the lack of transparency into what technologies and tactics cloud
providers implement regarding data protection and risk management, and how they
implement them. Organizations use the CAIQ as a first-level filter, after which
potential cloud customers should ask individual vendors to provide more
specific demonstrations on controls that matter most to the customer.
CAIQ questions are meant to be used in
conjunction with the CSA Cloud Controls Matrix (CCM) and the results are shared
through a registry for security controls called the Security, Trust and
Assurance Registry (STAR). The CSA STAR program consists of three levels of
assurance (self-assessment, third-party certification and continuous auditing)
based on:
- the CAIQ
- the CSA Cloud Controls Matrix (CCM)
- the CSA Code of Conduct for GDPR
Comments
Post a Comment