Latest news

The CSA Open Certification Framework is an industry initiative that offers cloud providers a trusted global certification scheme which will be created in line with the CSA’s security guidance and control objectives. The program will support an independent third-party assessment, as well as attestation statements developed within the public accounting community.
The Open Certification Framework is structured in three levels, each one of them will provide an incremental level of trust and transparency to the operations of cloud service providers and a higher level of assurance to the cloud consumer.
- The initial level is CSA STAR Self Assessment: Cloud providers can submit reports to the CSA STAR Registry to indicate their compliance with CSA best practices. This is available immediately.
- The second level, CSA STAR CERTIFICATION, is a third-party independent assessment: this certification leverages the requirements of the ISO/IEC 27001:2005 management systems standard together with the CSA Cloud Controls Matrix (CCM). These assessments will be conducted by approved certification bodies only. Availability is expected in H1 2013.
- The STAR Certification will be enhanced in the future by continuous monitoring-based certification: this third level is currently under development.
“The rise of cloud as a global compute utility creates a mandate to better harmonize compliance concerns,” said Daniele Catteddu, Managing Director EMEA of the CSA. “We share with BSI a commitment to improve transparency in the cloud ecosystem and create a market of trusted cloud services. BSI is one of the most relevant players in the area of information security standards, certification and assessment, and therefore they are the ideal partner for CSA in the development of the OCF. Consumers and providers alike will benefit from the knowledge that their CSA-backed compliance activities will be broadly applicable within global regulatory regimes."


Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





