Info Sheet: Security Guidance V.4
Info Sheet: Security Guidance V.4
org/guidance/
Introduction
This version, the first major update since 2011, is the culmination of over a year of dedicated
research and public participation from the CSA community, working groups, and the public at large.
The Cloud Security Alliance’s Security Guidance for Critical Areas of Focus in Cloud Computing acts as a
practical, actionable roadmap for individuals and organizations looking to safely and securely adopt
the cloud paradigm. Version 4 has been updated significantly to:
• Removal of “An editorial note on risk.” Risk management is instead addressed more deeply in the
appropriate domains and through other CSA GRC projects.
• A new “Regional Examples” section was added to DOMAIN 3 to provided a global perspective
on legal frameworks governing data protection and privacy.
• Data security and information governance are better structured. DOMAIN 5, Information
Governance, covers governance issues, while all operational data security issues are moved into
DOMAIN 11.
• DOMAIN 6 now addresses Management Plane Security and Business Continuity in the cloud. It
was previously Portability and Interoperability. Appropriate content from version 3 is integrated
in other areas and the rest is depreciated.
• DOMAIN 8 is now Virtualization and Containers. Data Center Operations from version 3 is fully
depreciated to focus the Guidance on cloud computing specific issues. CSA determined that the
community is better served by existing data center security standards.
• DOMAIN 11 has expanded from Encryption and Key Management to Data Security and
Encryption to incorporate non-governance material from DOMAIN 5 and expand additional
data security options.
• DOMAINS 10 AND 12 were extensively rewritten and restructured to remove overlapping IAM
recommendations and reflect real-world practices over unused standards.
• The content of DOMAIN 13 is now integrated into DOMAIN 8, Virtualization, and the previous
DOMAIN 14, Security as a Service, is now DOMAIN 13.
• DOMAIN 14 is a new domain for Related Technologies, including Big Data, IoT, mobile devices,
and serverless. Moving forward, this domain will enable the CSA to update the Guidance to
include emerging technologies and practices related to cloud computing that may later be
incorporated into other domains.