Skip to content
Artwork for CSA Security Update

CSA Security Update

John DiMaria; Director of Operations Excellence

CSA STAR is the industry's most powerful program for security assurance in the cloud.The Security Trust Assurance and Risk (STAR) Program encompasses key principles of transparency, rigorous auditing, and harmonization of standards. Companies who use STAR indicate best practices and validate the security posture of their cloud offerings.This podcast series explores CSA STAR as well as CSA best practices and research along with associated technologies and tools. 

Play
  • 20 episodes
  • Avg 31 min
  • English
  • April 17 · 38 min

    Beyond the Black Box: An AppSec Guide to AI

    Most organizations are still securing AI like traditional systems, but AI changes the rules entirely. In this episode, leading security experts Jim Rotan and Manish Kumar Yadav from SAP reveal how AI’s probabilistic nature, supply chain risks, and emerging attack surfaces like prompt injection demand a complete overhaul of modern security strategy. From model poisoning to AI-driven data exfiltration, they break down the real risks in AI-powered environments—and what security teams must do differently. You’ll gain practical insights on adapting threat modeling, securing model provenance, implementing AI-specific guardrails, and embedding security early in the development lifecycle. This episode cuts through the hype to deliver actionable strategies for rethinking risk, strengthening defenses, and building resilient AI systems. If you’re responsible for protecting modern applications, this is essential listening. https://cloudsecurityalliance.org/star/

  • March 16 · 24 min

    The Importance of AI Ready Data - How AI Is Changing Data Security and Quality

    This episode explores how AI is transforming data management, governance, and security. Ben Wilcox, CTO with extensive cloud experience, discusses the shift from data sprawl to quality, the security implications, and best practices for organizations to prepare for AI-driven data strategies. Key Topics Impact of AI on data sprawl and governance Importance of data quality for AI effectiveness Security risks associated with uncontrolled data sprawl Best practices for AI data environment architecture The role of data governance and lifecycle management in AI https://cloudsecurityalliance.org/star/

  • March 10 · 28 min

    The importance of Cybersecurity in Education

    Cyberattacks dominate today’s headlines, and in many cases, the weakest link isn’t technology—it’s people. In this episode, cybersecurity leader and educator Francisco Garcia Martinez, a member of the Technical Operations Committee of the Cloud Security Alliance, Spanish Chapter (CSA-ES), explores why cybersecurity education must evolve to meet the realities of an AI-driven world. As some countries introduce AI into high school curricula, many education systems still rely on outdated programs that fail to teach the critical thinking and security awareness needed in today’s digital landscape. Fran discusses how universities, governments, and industry can better prepare the next generation by focusing on foundational security principles, analytical thinking, and real-world technologies like cloud and AI, ensuring cybersecurity becomes a core skill for everyone, not just technical professionals. https://cloudsecurityalliance.org/star/

  • February 24 · 21 min

    From Pilot to Production: Preventing Breaches in AI Platforms

    Artificial intelligence is no longer confined to innovation labs or pilot programs. As enterprises deploy GenAI and MLOps platforms across Azure, AWS, and hybrid environments, AI is becoming a first-class cloud workload, and that shift is exposing security models that were never designed for autonomous, adaptive systems. In this episode, we’re joined by Milan Rana, Principal AI Architect at Headstorm, to explore what actually breaks when organizations scale AI in production. Drawing from hands-on experience building secure AI landing zones for regulated enterprises, Milan moves beyond theory to highlight real-world failure points, architectural tradeoffs, and governance gaps. https://cloudsecurityalliance.org/star/

  • January 28 · 39 min

    Beyond Encryption: Quantum Computing and the Future of Cyber Risk

    In this episode, we delve into the transformative world of quantum computing and its implications for cybersecurity. Join us as William (Bill) Genovese, Chief Quantum Officer at Cyber Eagle Project, shares insights on how quantum technology is reshaping cyber risk, governance, and resilience. Discover why organizations must prepare now for a quantum future, the challenges of transitioning to post-quantum encryption, and the strategic steps leaders should take to safeguard their digital assets. Tune in to explore the intersection of quantum advancements and cybersecurity with industry experts. https://cloudsecurityalliance.org/star/

  • January 23 · 26 min

    The New Mandate for Internal Audit in Cloud & AI Environments

    As organizations accelerate their adoption of cloud and AI technologies, internal audit teams face mounting pressure to evaluate increasingly complex hybrid and multi-cloud environments. In this episode, the Cloud Security Alliance’s John DiMaria sits down with Jerrad Bartczak of Advantage Partners to examine the rapidly evolving cloud risk landscape—spanning unclear shared responsibility, governance gaps, misconfigurations, credential sprawl, insecure APIs, and limited visibility into cloud data flows. Listeners will gain practical guidance on establishing strong cloud governance, clarifying accountability, assessing cloud and data security posture, evaluating identity and access controls, securing application development, and addressing third-party cloud risk. The conversation also explores how frameworks such as the CSA Cloud Controls Matrix can support a structured, multi-year cloud audit strategy. Ultimately, this episode reinforces that cloud security is a strategic business imperative that requires collaboration, continuous monitoring, and a unified approach to risk management. https://cloudsecurityalliance.org/star/

  • January 9 · 16 min

    Navigating AI Governance Insights - ISO 42001: The Future of AI Compliance

    In this episode of CSA Security Update, host John DiMaria speaks with Walter Haydock, founder of StackAware, about the critical role of AI governance and compliance in today's rapidly evolving regulatory landscape. They discuss the importance of ISO 42001 as a framework for managing AI-related risks while fostering innovation. Walter shares insights on how certification can build trust with customers and streamline sales processes, as well as the challenges organizations face in navigating a patchwork of regulations. Drawing from his military background, Walter emphasizes the necessity of making informed decisions in risk management. The conversation concludes with a forward-looking perspective on the future of AI in business. https://cloudsecurityalliance.org/star/

  • Dec 11, 2025 · 26 min

    AI Governance Gets Real: How ISO/IEC 42001 Elevates Cloud GRC

    As AI rapidly integrates into cloud environments, organizations are facing governance, risk, and compliance challenges that traditional frameworks like ISO 27001 were never designed to address. In this episode, we explore how ISO/IEC 42001, the new international standard for an Artificial Intelligence Management System (AIMS), provides a structured and auditable approach to responsible AI governance. You’ll learn how this standard helps organizations operationalize AI risk management while ensuring accountability, transparency, and compliance across modern cloud ecosystems. We break down practical strategies for integrating ISO/IEC 42001 into existing GRC programs—without duplicating effort or creating parallel processes. John DiMaria interviews Tanya Tandon, Senior GRC & Risk Advisor for VISO TRUST, who draws on real-world experience as an ISO/IEC 42001 Lead Auditor, offers actionable guidance for building trustworthy AI systems, preparing for certification, and managing third-party AI risks. Whether you’re a security leader, auditor, compliance professional, or AI practitioner, you’ll gain practical insights on embedding ISO 42001 requirements into daily AI operations and aligning them with broader enterprise GRC strategies. https://cloudsecurityalliance.org/star/

  • Dec 11, 2025 · 31 min

    Internal Audit in the Age of Cloud & AI: Navigating the New Risk Frontier

    As organizations accelerate their adoption of cloud and AI technologies, internal audit teams are being pushed into a new era of complexity. In this episode, Cloud Security Alliance’s John DiMaria and Grant Thornton’s Vik Rai unpack the evolving risk landscape across hybrid and multi-cloud environments—and what auditors must do to keep pace. We explore today’s most critical cloud security challenges, including unclear shared responsibility, governance gaps, misconfigurations, credential sprawl, insecure APIs, and limited visibility into cloud data flows. Listeners will gain practical, actionable guidance on strengthening cloud governance, evaluating security posture, assessing identity and access controls, securing application development, and managing third-party cloud risk. You’ll also hear how frameworks like the CSA Cloud Controls Matrix (CCM) help internal audit teams build scalable, multi-year audit programs that align to modern cloud architectures. https://cloudsecurityalliance.org/star/

  • Nov 4, 2025 · 38 min

    Continuous verifiable proof is the new standard

    In this episode of CSA Security Update, host John DiMaria and guest Scott Fuhriman of Invary discuss the evolving landscape of cloud security, focusing on the critical vulnerabilities posed by implicit trust in foundational components like kernels and hypervisors. They explore the limitations of traditional security tools and the necessity of continuous integrity measurement as a proactive defense against modern threats, including zero-day attacks. The conversation underscores the importance of integrating integrity validation into existing security frameworks, while striking a balance between performance and security. Real-world use cases demonstrate the effectiveness of these measures, particularly in critical infrastructure. The episode concludes with insights into the future of cloud security, emphasizing the need for continuous verifiable proof to enhance trust and security in cloud environments. https://cloudsecurityalliance.org/star/

  • Oct 23, 2025 · 26 min

    The Human Side of AI Security: Leadership, Culture, and Change

    Summary In this episode, John DiMaria and John Earle discuss the rapid rise of AI in cybersecurity, drawing parallels to the early adoption of cloud security. They explore the importance of organizational culture, change management, and team dynamics in shaping security initiatives. The conversation emphasizes the need for effective communication and the role of security champions in overcoming resistance to change. Looking ahead, they highlight the qualities that will define successful security leaders in the evolving landscape of technology. Key takeaways AI is transforming cybersecurity at an unprecedented pace. Organizational culture significantly impacts security performance. Change management is essential for security leaders. Understanding team dynamics can enhance security initiatives. Building security champions is crucial for program success. Effective communication fosters collaboration and trust. Resistance to change is a natural reaction that needs addressing. Security leaders must empathize with team concerns. Data engineering knowledge will be vital for future leaders. Proactive security measures are more effective than reactive ones. https://cloudsecurityalliance.org/star/

  • Sep 22, 2025 · 25 min

    Guardrails for Generative AI: Balancing Innovation with Responsibility

    As organizations embrace generative AI, ensuring applications align with safeguards is critical. Today, we are here to explore how proper Guardrails can enable responsible AI by filtering harmful content, enforcing policies, and supporting compliance—all without slowing innovation. Join us as we interview Saptarshi Banerjee, Senior Solutions Architect at Amazon Web Services (AWS Listeners will hear real-world use cases, governance best practices, and how to build AI solutions that are powerful, secure, and aligned with enterprise values. https://cloudsecurityalliance.org/star/

  • Sep 26, 2024 · 31 min

    Empowering Cloud Providers: The EU Cloud Code of Conduct and GDPR Explained

    In this insightful episode, we explore the intricate world of GDPR compliance and how tools like codes of conduct can support cloud service providers. Our special guest, Gabriela Mercuri, Managing Director of SCOPE Europe, shares her expertise on the EU Cloud Code of Conduct (EU Cloud CoC), a pivotal GDPR compliance tool designed specifically for the cloud industry. Join us as we discuss the significance of these codes of conduct, their role in ensuring data protection, and how they offer a practical framework for companies striving to meet GDPR requirements. We will also delve into the ongoing collaboration between the EU Cloud CoC and the CSA, highlighting how this partnership enhances transparency, trust, and compliance across the cloud services landscape. Whether you’re a cloud service provider, a data protection professional, or simply interested in GDPR compliance, this episode will provide valuable insights into the evolving landscape of data protection and the practical steps companies can take to ensure compliance. https://cloudsecurityalliance.org/star/

  • Aug 21, 2024 · 41 min

    Real-talk: Opportunities for Security Teams to Fight AI with AI

    The attack surface has expanded and evolved dramatically in an era where the industry is investing nearly a trillion dollars in cloud infrastructure, operations, and applications. Modern cloud development enables faster application building and introduces complex security challenges. As generative AI becomes increasingly integrated into our tools and processes, it promises to transform how we approach cybersecurity. But what does that mean for security and development teams today? Join us in this episode as we interview Tomer Schwartz, CTO and Co-founder, Dazz, and explore how AI can be a game-changer for security teams, especially resource-constrained teams, offering the ability to automatically discover and resolve cloud vulnerabilities at their root. We'll discuss whether human oversight will still be necessary before changes go live and when the true potential of GenAI is realized. We will also discuss how we can use AI to outsmart adversaries using it for malicious purposes. This is a must-listen for anyone interested in leveraging AI to enhance their security posture and protect against the next generation of cyber threats. https://cloudsecurityalliance.org/star/

  • Jul 23, 2024 · 43 min

    ISO/IEC 27001:2022 Unpacked: Embracing Auditing Themes

    In our latest episode, we delve into the innovative approach of auditing "themes" as introduced in the ISO/IEC 27001:2022 revision. This reorganization of domains marks a significant shift in how we think about and implement information security management. By centering our conversation on auditing themes, we explore how this new structure enhances the alignment of security practices with organizational goals and risks. We'll discuss the rationale behind this change, practical insights on transitioning to the new model, and the benefits it brings to ensuring a robust and comprehensive security audit. Join us as we interview David Forman, founder of Mastermind, as we unpack the implications of this pivotal update and provide guidance on how to prepare for your next certification body audit. https://cloudsecurityalliance.org/star/

  • Jun 27, 2024 · 41 min

    From Concept to Competence: The Impact of CSA's Zero Trust Training

    In this exclusive interview, we have the honor of speaking with a representative from the Cloud Security Alliance (CSA), the esteemed recipient of the 2024 Global InfoSec Award for Cutting-Edge Cybersecurity Training. This award acknowledges CSA's groundbreaking Certificate of Competence in Zero Trust (CCZT), the industry's first authoritative training and certification program dedicated to Zero Trust architecture, components, and best practices. During this session, we will delve into the development and significance of the CCZT, exploring the motivations behind its creation and the goals CSA aimed to achieve. Our discussion will highlight the unique features of the CCZT program, its impact on professionals and organizations, and the feedback received from those who have completed the training. We will also examine the broader implications of Zero Trust in the current cybersecurity landscape, the challenges organizations face in adopting Zero Trust principles, and how the CCZT addresses these challenges. Join us as we uncover the reasons behind CSA's commitment to creating a trusted cloud ecosystem and its vision for the future of cybersecurity training. This conversation will provide valuable insights for professionals and organizations seeking to enhance their cybersecurity strategies and achieve excellence in the field. https://cloudsecurityalliance.org/star/

  • May 28, 2024 · 30 min

    Decoding Security Solutions: ASPM vs CSPM vs CNAPP

    In the ever-expanding digital world, securing applications and the infrastructure they rely on is critical. This episode tackles three key security field acronyms: Application Security Posture Management (ASPM), Cloud Security Posture Management (CSPM), and Cloud-Native Application Protection Platform (CNAPP). While all focused on bolstering security posture, these target different aspects of one's security program. Listen as we interview Karthik Swarnam, Chief Security and Trust Officer at Armorcode, a CSA member, and take a deep dive into this subject. We discuss: Distinguishing between ASPM, CSPM, and CNAPP: Understand their functionalities, target areas, and how they differ in safeguarding your digital assets. Navigating the ever-changing security landscape of security solutions and making informed decisions toward building a mature software security program and maintaining a robust security posture. How these solutions integrate with the Cloud Control Matrix and the CSA STAR Program best practices to facilitate better security and reduce risk. https://cloudsecurityalliance.org/star/

  • May 2, 2024 · 28 min

    Aligning Security Standards: Maximizing Synergy Between CSA STAR Level 2 and ISO 27001

    In this episode, John DiMaria & Cameron Kline, Director of Attest Services at BARR Advisory, delve into the relationship between CSA STAR Level 2 and ISO 27001 standards, emphasizing the significant overlap in best practices, procedures, and controls for cloud service providers (CSPs) operating in medium- to high-risk environments. They highlight how collaboration with an auditing firm certified in both frameworks can expedite the compliance process, offering practical tips for streamlining attestations. Discover why dual compliance against CSA STAR Level 2 and ISO 27001 is paramount for CSPs to demonstrate their commitment to robust security practices and gain a competitive advantage. Cameron also discusses the strategic benefits of integrating CSA STAR Level 2 certification into existing compliance programs post-ISO 27001 audit, providing actionable insights for organizations considering this journey. Whether you're navigating compliance complexities or seeking optimization strategies, this episode equips you with the knowledge to leverage the synergy between CSA STAR Level 2 and ISO 27001 standards effectively. https://cloudsecurityalliance.org/star/

  • Apr 30, 2024 · 37 min

    Navigating the New Age of Compliance

    In a world where the speed of business is only outpaced by the speed of regulatory changes, staying compliant without slowing down has become the new competitive edge. In this episode, we delve into the heart of agile compliance with a special guest Travis Howerton; Co-Founder and Chief Executive Officer of RegScale, a pioneering company at the forefront of compliance automation. Discover how automated technology and continuous monitoring is revolutionizing the way organizations approach compliance, risk management, and governance in both the private and government sectors. Our guest will share insights into the challenges businesses face in today's regulatory environment and how these innovative solutions are helping to navigate these complexities with greater ease and efficiency. In this interview, we explore: The evolving landscape of regulatory compliance and its impact on businesses across sectors. How technological advances allow organizations leverage automation to streamline compliance processes, reduce risks, and enhance operational agility as well as resilience. Success stories of organizations that have transformed their compliance journey. Tips and strategies for organizations looking to adopt a more proactive and automated approach to compliance. The future of compliance management: trends to watch and predictions for the evolving role of technology in governance and risk management. Listen to an enlightening conversation that sheds light on the future of compliance and how the latest technology is not just enabling businesses to keep up but to get ahead. Whether you're a business leader, a compliance professional, or just curious about the intersection of technology and regulation, this episode will provide valuable insights into making compliance a driver for innovation and growth. https://cloudsecurityalliance.org/star/

  • Jan 17, 2024 · 28 min

    Why CPA Firms Excel in Cybersecurity Attestations

    In the latest CSA Security Update Podcast episode, we delve into the fascinating world of cybersecurity attestations and explore why CPA firms are increasingly leading the charge in this domain. Host John DiMaria is joined by Pawel Wilczynski, Cybersecurity Manager at Baker Newman Noyes (BNN), a top-ranked tax, assurance, and advisory firm and an accredited CSA STAR Assessment Firm. The episode delves into why CPA firms, traditionally known for financial audits, are exceptionally well-suited for cybersecurity attestations and how they apply their expertise in ensuring rigorous processes and adherence to standards like CSA STAR when performing cybersecurity assurance over cloud systems. This episode is a must-listen for anyone interested in understanding the critical role of CPA firms in the evolving landscape of cybersecurity attestations. https://cloudsecurityalliance.org/star/

Showing 1–20 of 20 episodes