According to the Cloud Security Alliance (CSA), the Security, Trust, Assurance, and Risk (STAR) program encompasses “key principles of transparency, rigorous auditing, and harmonization of standards outlined in the Cloud Control Matrix (CCM).” As a CSA STAR certification-approved assessment firm, BARR Advisory partners with cloud service providers (CSPs) to provide an efficient way to demonstrate their commitment to security and privacy best practices.
CSA STAR is a benchmark assurance framework for CSPs, helping organizations align with the industry’s evolving changes. Your organization can choose to complete two levels of the CSA STAR program, where CSA STAR Level 1 serves as a foundation for the more advanced CSA STAR Level 2.
“For CSPs that have already completed assessments through other compliance frameworks, CSA STAR Level 2 is a seamless addition that brings with it a unique opportunity to hone in on the security principles most relevant in cloud environments,” said Brad Thies, founder and president of BARR.
Let’s take a detailed look at the benefits of CSA STAR Level 2 and how to integrate the framework into your compliance strategy.
CSA STAR Level 1 is the first step toward CSA STAR attestation or certification and includes a self-assessment phase. Level one is a good fit for CSPs that operate in a low-risk environment and want to boost trust by demonstrating the transparency of the security controls in place. If your organization has completed a CSA STAR Level 1 self-assessment, you can benefit by scaling to CSA STAR Level 2 and increasing security assurance and privacy in your cloud environment.
Other benefits to CSA STAR Level 2 include:
As an accredited certification body, BARR can perform rigorous, independent security assessments for CSPs seeking to achieve CSA STAR Level 2. Prior to starting, you’ll want to consider factors like your company location, the regulations and standards you’re subject to, and previously completed standards and frameworks.
Organizations are a good fit for CSA STAR Level 2 if they:
Once you’re ready to start CSA STAR Level 2, your organization can choose to accomplish one or both of the following third-party audits:
CSA STAR Attestation (for SOC 2): The CSA STAR attestation is a combination of CSA and AICPA Trust Service Criteria used for SOC 2 engagements. CSA STAR attestations last one year with a minimum period of six months.
CSA STAR Certification (for ISO 27001): Certification under the CSA STAR program is an assessment of the security of a CSP. The certification process leverages the requirements of ISO 27001 with the CCM. CSA STAR certifications last three years.
Organizations that certify to CSA STAR Level 2 are invited to publish as STAR Certified to the CSA STAR registry, a publicly accessible registry of over 2,000 providers that documents the security and privacy controls provided by popular cloud computing offerings. Publishing to the registry allows organizations to establish their security and compliance posture, building trust with potential and current customers. Ultimately, this visibility reduces complexity and helps alleviate the need to fill out multiple customer questionnaires.
While taking the first steps toward CSA STAR Level 2 may seem like a big task, know that BARR is here to simplify the process. If you already have a SOC 2 report or an ISO 27001 certification under your belt, BARR can adjust the scope of your existing audits to include the CCM, leading you to achieve CSA STAR Level 2 in a timely and cost-effective manner.
Take a look at the six major steps for achieving CSA STAR Level 2:
When getting started, your organization can determine the level of transparency and assurance you would like to pursue and visit the CSA STAR website for detailed resources and information on steps toward CSA STAR Level 2.
If you’re a CSP looking to demonstrate your commitment to security and privacy, contact us today to speak with a CSA STAR specialist.