Cloud Security Alliance
The Cloud Security Alliance (CSA) is a non-profit organization whose mission is to "promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing."
The CSA’s Security, Trust & Assurance Registry Program (CSA STAR) is designed to help customers assess a Cloud Service Provider (CSP) through a three-step program of self-assessment, third-party audit, and continuous monitoring.
STAR provides three levels of assurance:
- Level 1: Self-Assessment based on Cloud Controls Matrix (CCM) or Common Assessment Initiative Questionnaire (CAIQ)
- Level 2: Independent third-party certifications such as CSA STAR Certification and CSA STAR Attestation
- Level 3: Certifications based on continuous monitoring
As part of the CSA STAR Self-Assessment, CSPs can submit two different types of reports to indicate their compliance with CSA best practices: a completed CAIQ, or a report documenting compliance with CCM.
Atlassian is both a Corporate Member of the Cloud Security Alliance, as well as listed on the Cloud Security Alliance Trusted Cloud Provider.
Atlassian provides Level 1 Self-Assessment for our Cloud Products.
Note: CSA has released CCM v4, a major update to the CCM that has 197 control objectives structured in 17 domains. CSA STAR CAIQ Self-Assessmenthas been updated to version 4 of the CAIQ at the end of 2021. CSA has also provided a CCM v4 transition timeline for cloud service providers and other organizations to start using version 4.
Atlassian has now updated all of our CAIQ Self-Assessments to CAIQ 4.0.
Relevant products
Project and issue tracking
Jira
enterprise agile planning
Jira Align
document collaboration
Confluence Cloud
Git code management
Bitbucket Cloud
VISUAL COLLABORATION
Trello
modern incident response
Opsgenie
incident communication
Statuspage
Our team is here to help
Have more questions about our compliance program?
Do you have cloud certifications? Can you complete my security & risk questionnaire? Where can I download more information?
Trust & security community
Join the Trust & Security group on the Atlassian Community to hear directly from our Security team and share information, tips, and best practices for using Atlassian products in a secure and reliable way.
Atlassian support
Reach out to one of our highly-trained support engineers to get answers to your questions.