Cloud Security Alliance Blog
Blog
CSA Cloud Files is an easily accessible repository of research and organizational downloads from the Cloud Security Alliance. Source
Actions
Media Outlet details
| Scope | Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesCSA Welcomes NVIDIA Open Agent Safety Platform
Cloud Security Alliance is building industry consensus around governance and security controls for autonomous AI. We welcome the launch of the NVIDIA Open Agent Safety Platform and NVIDIA’s commitment to making autonomous AI safer to deploy at enterprise scale.
Post-Quantum Key Management Starts at the Root
IT teams often view post-quantum cryptography (PQC) migration as a simple algorithm replacement. You swap RSA or ECC for a quantum-resistant alternative and move on. However, the process is more complex for cloud key management. In this domain, the order in which you migrate your key hierarchy matters just as much as the algorithms. In an envelope encryption architecture, you must prioritize the root of the key hierarchy. (This would be the master key or key encryption key [KEK]).
The Vital Trifecta
AI agents are moving through three stages. They began on the endpoint: Claude Code or Cursor in a terminal on a developer's laptop, a local process with local credentials, and a person watching output scroll past and pressing approve. They are moving into sandboxed cloud containers: cloud agents and background branches, ephemeral environments with repo credentials that are spun up and destroyed inside a single task while the developer files the work and closes the tab.
Lessons Learned on Securing Multi-Agent Systems: NIST Agent Security RFI
Five practical security lessons distilled from public responses on how increasingly autonomous agents change trust, authority, observability, and system assurance. In January 2026, the National Institute of Standards and Technology (NIST) Center for AI Standards and Innovation issued a Request for Information (RFI) on Security Considerations for Artificial Intelligence Agents, seeking input on security risks, mitigations, measurement, evaluation, and the secure adoption of AI agent systems.
A New Security Challenge: The Curious Case of Prompt Language Analysis
Why prompt analysis is emerging as a key AI security challenge If securing AI has been one of the defining cybersecurity conversations of the past year, prompt analysis is quickly becoming one of its most interesting frontiers. Security leaders are under pressure to understand how AI is being used across the business. In some organizations, that means governing employee use of chatbots.
The DNS Risks Your DDI Was Never Designed to Find
Written by Rajdatta Rokade. Why Your Network Strategy Needs Both DDI and DNSPM — Not One or the Other Most enterprise IT teams already run some form of DDI — DNS, DHCP, and IPAM — either as a dedicated platform or built into their broader network management stack.
The Human-Machine Partnership: Architectures for Reliable AI
Agentic AI for balancing speed, resilience and human authority in automation. Part I: Never Put All Your Eggs In One Basket The Human-In-The-Loop (HITL) concept went through its own history of becoming a milestone for humanity: from the human in the role of a controller to supervisor to model trainer, the human has lately been assigned the role of an ethical or legal safeguard and in its most recent job description it is a collaborator and system governor [Figure 1].
A Framework for AI Threat Readiness
AI models now find and exploit zero-days autonomously. This 4-pillar framework accelerates patching, analysis, and threat response. Recent and continued advancements in AI models have fundamentally changed how vulnerabilities are found and exploited.
Cloud Security 2026: When AI is the Weapon and the Target
Artificial intelligence has changed the cloud threat landscape in two distinct ways. Attackers are using AI to make established attack methods faster, more scalable, and more convincing. At the same time, the AI systems that organizations deploy have become assets that attackers can manipulate. CSA’s Top Threats to Cloud Computing 2026 report captures this distinction. It separates AI-Enhanced Attacks and AI System Compromise into two distinct categories (spots #2 and #6, respectively).
Enterprise Reality: Why Organizations Aren't as Prepared for AI Governance as They Think They Are
Written by Danny Manimbo. If you ask most enterprise leaders, 74% would say their organization could pass an AI compliance audit today. Yet if you ask about the maturity of their AI governance program, only 27% say their programs are fully mature. That gap is the finding at the center of Schellman's new research, The 2026 State of AI Governance Report, based on a survey of more than 500 U.S. enterprise leaders.