> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CSA STAR

> Demonstrate cloud security assurance with the Cloud Security Alliance STAR program.

> Demonstrate cloud security assurance with the Cloud Security Alliance STAR program.

The Cloud Security Alliance (CSA) Security, Trust, Assurance and Risk (STAR) program is a cloud-specific assurance framework. It is built on the Cloud Controls Matrix (CCM) and offers multiple levels of certification, from self-assessment to third-party audit, for cloud service providers.

<Note>
  CSA STAR is purpose-built for cloud service providers and is recognized globally as a mark of cloud security maturity.
</Note>

## Who needs CSA STAR?

<CardGroup cols={2}>
  <Card title="Cloud service providers" icon="cloud">
    SaaS, PaaS, and IaaS providers demonstrating security and transparency to customers.
  </Card>

  <Card title="Cloud customers" icon="users">
    Organizations evaluating the security posture of their cloud vendors via the STAR Registry.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Cloud Controls Matrix" icon="table-cells">
    A cybersecurity control framework with domains covering all key cloud security areas.
  </Card>

  <Card title="STAR Level 1" icon="1">
    Self-assessment based on the CCM and CAIQ, published to the public STAR Registry.
  </Card>

  <Card title="STAR Level 2" icon="2">
    Third-party certification or attestation combined with ISO 27001 or SOC 2.
  </Card>

  <Card title="CAIQ" icon="clipboard-question">
    The Consensus Assessments Initiative Questionnaire for documenting CCM compliance.
  </Card>
</CardGroup>

## How DSALTA helps with CSA STAR

<Steps>
  <Step title="Activate CSA STAR">
    Select CSA STAR from the Frameworks page. DSALTA maps Cloud Controls Matrix domains to controls.
  </Step>

  <Step title="Complete the CAIQ">
    Answer the Consensus Assessments Initiative Questionnaire with DSALTA's guidance.
  </Step>

  <Step title="Collect evidence automatically">
    Connect cloud integrations to gather evidence for CCM controls.
  </Step>

  <Step title="Approve policies">
    Review and approve policies mapped to CCM domains.
  </Step>

  <Step title="Submit to the STAR Registry">
    Prepare your self-assessment or third-party attestation for the public registry.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What is the Cloud Controls Matrix?" icon="table-cells">
    The CCM is CSA's cybersecurity control framework for cloud computing, with control domains mapped to many other standards and regulations.
  </Accordion>

  <Accordion title="Can I combine STAR with SOC 2?" icon="layer-group">
    Yes. STAR Level 2 is often pursued alongside ISO 27001 or SOC 2, reusing much of the same evidence.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
