CSA CCM position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • Cloud-specific control content where general frameworks generic.
  • Cross-framework mapping reduces vendor due-diligence overhead.
  • STAR Registry provides public-facing cloud-provider transparency.
  • CAIQ questionnaire standardized vendor evaluation.

What it does poorly

  • Voluntary participation — not all cloud providers in STAR.
  • Self-assessment depth varies (Level 1).
  • Multiple STAR levels confusion sometimes.
  • Update cadence trails cloud architecture evolution.

Evidence

  • Major cloud providers (AWS, Azure, GCP, Salesforce, others) submit STAR.
  • CAIQ widely used in vendor due diligence.
  • Combined ISO 27001 + STAR Certification common.

Personal calibration

  • For cloud-vendor evaluation: CAIQ + STAR useful.
  • For cloud-customer compliance: CCM mapping reduces dual implementation overhead.

See also