Skip to main content
Cloud Security Alliance

Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through the 501(c)3 CSAI Foundation, vendor-neutral research, globally-accepted standards, and award-winning education programs that unite technical experts, industry practitioners, and varied associations, governments, chapters, and corporate members across six continents, CSA bridges the gap between innovation and pragmatic security execution. CSA is the home of the industry-staple Cloud Controls Matrix (CCM), AI Controls Matrix (AICM), and Security, Trust, Assurance, and Risk (STAR) program, which help to create a common security language between providers and consumers. CSA also publishes freely accessible research publications, leads influential industry initiatives such as the AI Safety Initiative and Zero Trust Advancement Center, creates vendor-neutral educational offerings for cybersecurity professionals, and hosts high-impact events both around the world and online to help professionals enhance their skills and foster connections. In 2026, CSA launched CSAI, a 501(c)3 non-profit foundation dedicated exclusively to AI security and safety. Collectively, CSA represents a global movement committed to solving the security industry’s problems of both today and tomorrow. Together we can ensure that the cyber space remains secure, trustworthy, and accessible to all. Visit the CSA website to explore educational resources, join the community, and discover how to accelerate your own organization's secure digital transformation: https://www.cloudsecurityalliance.org/www.cloudsecurityalliance.org

Search complete. 24 mentions across 18 episodes found for "Cloud Security Alliance".

Sep 14, 2026

Drew Connery-MurrayHOST
3:36
Yeah.
Drew Connery-MurrayHOST
3:37
And I'll note in our most recent human infrastructure newsletter, the Cloud Security Alliance just released a blueprint or a framework around implementing Zero Trust.
Drew Connery-MurrayHOST
3:46
I believe it's fairly vendor neutral.
Drew Connery-MurrayHOST
3:48
It's more about principles and practices than it is about products, which I think is the way to go.
Scott RobohnGUEST
3:19
Think, think about, think about the whole remember the industry for mobile device management? Where is that today? It's gone 'cause we've given up, right? Um, and networking is more important and more built in to everything we do, so zero trust operational principle, don't forget it.
Drew Conry-MurrayHOST
3:36
Yeah, and I'll note in our most recent, um, Human Infrastructure newsletter, uh, the Cloud Security Alliance just released, uh, a blueprint or a framework around implementing zero trust.
Drew Conry-MurrayHOST
3:46
I believe it's fairly vendor neutral.
Drew Conry-MurrayHOST
3:48
It's more about principles and practices than it is about products, which I think is the way to go.
Scott RobohnHOST
3:24
Where is that today? It's gone 'cause we've given up, right? Um, and networking is more important and more built in to everything we do, so zero trust operational principle, don't forget it.
Drew Conry-MurrayHOST
3:36
Yeah, and I'll note in our most recent, um, Human Infrastructure newsletter, uh, the Cloud Security Alliance just released, uh, a blueprint or a framework around implementing zero trust.
Drew Conry-MurrayHOST
3:46
I believe it's fairly vendor neutral.
Drew Conry-MurrayHOST
3:48
It's more about principles and practices than it is about products, which I think is the way to go.
Jennifer JabushHOST
4:39
Now, I think the...
Jennifer JabushHOST
4:40
So the Cloud Security Alliance has some good guidance around this and some procurement guidance that I think is interesting, um, that we've got linked in here.
Jennifer JabushHOST
4:46
Um, but it look...
Jennifer JabushHOST
4:47
So they're saying, I think, they noted like they think hundreds of thousands of devices, 100,000 devices could be the number that are impacted.
Jennifer JabushHOST
6:40
There's German brands, there's RV, there's re- remote, remote things.
Jennifer JabushHOST
6:44
There's, like, on-the-go wireless router.
Jennifer JabushHOST
6:47
Um, so there's a whole list in the Cloud Security Alliance, um, where they've dug through, like, model numbers and firmware versions and patents and ev- everything that they could find related to supply chain.
Drew Connery-MurrayHOST
6:57
Yeah.
Jennifer JabushHOST
4:39
Now, I think the...
Jennifer JabushHOST
4:40
So the Cloud Security Alliance has some good guidance around this and some procurement guidance that I think is interesting, um, that we've got linked in here.
Jennifer JabushHOST
4:46
Um, but it look...
Jennifer JabushHOST
4:47
So they're saying, I think, they noted like they think hundreds of thousands of devices, a hundred thousand devices could be the number that are impacted.
Jennifer JabushHOST
6:40
There's German brands, there's RV, there's re-remote, remote things.
Jennifer JabushHOST
6:44
There's, like, on-the-go wireless router.
Jennifer JabushHOST
6:47
Um, so there's a whole list in the Cloud Security Alliance, um, where they've d-dug through, like, model numbers and firmware versions and patents and ev-everything that they could find related to supply chain.
Drew Connery-MurrayHOST
6:57
Yeah.
Jennifer JabuschHOST
4:34
So it looks like what happened... based on the larger population.
Jennifer JabuschHOST
4:40
So the Cloud Security Alliance has some good guidance around this and some procurement guidance that I think is interesting that we've got linked in here.
Jennifer JabuschHOST
4:47
So they're saying, I think, they noted like they think hundreds of thousands of devices, 100,000 devices could be the number that are impacted.
Jennifer JabuschHOST
4:55
The researchers were able to tell how many, like a small population based on they were able to take and purchase a domain that was involved in some of what these things were calling out to, but it's a backup domain that only some of the devices were using and not...
Jennifer JabuschHOST
6:42
There's remote things.
Jennifer JabuschHOST
6:44
There's like on-the-go wireless router.
Jennifer JabuschHOST
6:47
So there's a whole list in the Cloud Security Alliance where they've dug through like model numbers and firmware versions and patents and everything that they could find related to supply chain.
Drew Conry-MurrayHOST
6:57
Yeah.
Michelle MartinHOST
4:12
Just earlier this month, Nvidia announced a plan with six Wall Street firms, you remember, to raise up to five hundred billion from asset managers to fund the deals through bonds and private capital loans.
Michelle MartinHOST
4:22
So Cloud Security Alliance published interesting research that showed Nvidia's market dominance may be a major component of an overall AI industry systemic security threat.
Michelle MartinHOST
4:35
It concluded making that fragility visible and managing it systematically is the work of the security community, and that's what the community needs to undertake before the next cascading failure makes the stakes undeniable.
Michelle MartinHOST
4:49
All right.
Lorena RuizNARRATOR
5:01
The role of control frameworks, AACM, and AI governance.
Lorena RuizNARRATOR
5:09
One of the central messages is the importance of adopting control frameworks, such as the Artificial Intelligence, Controls Matrix, AICM, from the Cloud Security Alliance.
Lorena RuizNARRATOR
5:22
These types of frameworks allow innovation to occur securely, auditably, and aligned with business objectives.
Lorena RuizNARRATOR
5:30
The speed of innovation cannot outpace the capacity to govern it.
Renee GuttmannGUEST
9:21
And they may or may not have had a lot of security training.
Renee GuttmannGUEST
9:24
They may think an eight character password's okay for anything you want to do, right? And so what else is factual potentially? Well, let's assume that the CSA, the Cloud Security Alliance, who did a study in January of this year.
Renee GuttmannGUEST
9:42
And there was an online study and they surveyed, they got responses from 228 organizations.
Renee GuttmannGUEST
9:48
And those organizations from around the globe of various sizes said that 68% of organizations can't differentiate or can't distinguish an action, whether it was taken by a human, an AI action, or an agentic AI.
Sandip WadjeGUEST
44:50
As you know, I'm quite passionate about governance of AI.
Sandip WadjeGUEST
44:53
I'm part of the Cloud Security Alliance, AI Safety Council, various AI governance forums.
Sandip WadjeGUEST
44:58
So very happy for people to reach out to me on LinkedIn and I'm happy to answer their questions.
Sandip WadjeGUEST
45:03
I'll put the LinkedIn link on the show notes as well.

8 more episodes mention Cloud Security Alliance.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.