Prequalification register · Last verified
Security, Trust, Assurance and Risk (STAR)
CSA STAR is the Cloud Security Alliance's cloud assurance program, built around a publicly accessible registry of provider security submissions. Level 1 is a self-assessment based on the Consensus Assessments Initiative Questionnaire; Level 2 adds third-party audit as STAR Certification, STAR Attestation or C-STAR.
- Class
- Prequalification register
- Owner
- Cloud Security Alliance (CSA)
- Public register
- Verified working
- Last verified
What it is
STAR — "Security, Trust, Assurance and Risk" — is a two-level cloud assurance programme run by the Cloud Security Alliance, and its public face is a register: "The Security, Trust, Assurance, and Risk (STAR) Registry is a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings."
The two levels are not the same kind of evidence. Level 1 is a self-assessment in the CSA's own words: "At level one, organizations can submit the Consensus Assessments Initiative Questionnaire based on the Cloud Controls Matrix to evaluate and document their security controls." Level 2 adds independent audit — "Level 2 of STAR allows organizations to build off of other industry certifications and standards to make them specific for the cloud" — through three named routes: "STAR Attestation: For SOC 2", "STAR Certification: For ISO/IEC 27001" and "C-STAR: For the Greater China Market". A Level 1 entry in the registry is therefore not a third-party assessment.
Who owns it
The programme and the registry are run by the Cloud Security Alliance (CSA), which also publishes the Cloud Controls Matrix and the Consensus Assessments Initiative Questionnaire that the assessments are built on.
STAR levels
- Level 1 — Self-Assessment —
At level one, organizations can submit the Consensus Assessments Initiative Questionnaire based on the Cloud Controls Matrix to evaluate and document their security controls.
- Level 2 — Third-Party Audit (overview) —
Level 2 of STAR allows organizations to build off of other industry certifications and standards to make them specific for the cloud. The listed routes are "STAR Attestation: For SOC 2", "STAR Certification: For ISO/IEC 27001" and "C-STAR: For the Greater China Market".
- Level 2 — STAR Certification (ISO 27001-based) —
The CSA STAR Certification is a rigorous third-party independent assessment of the security of a cloud service provider. Certification certificates follow normal ISO/IEC 27001 protocol and expire after three years unless updated.
- Level 2 — STAR Attestation (SOC 2-based) —
The CSA STAR Attestation is a collaboration between CSA and the AICPA to provide guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix. Attestation listings will expire after one year unless updated.
Sources
- Cloud Security Alliance — STAR (scheme owner) ↗ — accessed
- CSA — STAR Registry ↗ — accessed
- CSA — STAR Certification ↗ — accessed
- CSA — STAR Attestation ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.