Cloud assurance
Build transparent cloud assurance for customers.
The Cloud Security Alliance STAR program uses the Cloud Controls Matrix and offers different assurance levels. We help cloud teams map controls, prepare an accurate self-assessment, and plan for independent assessment where the chosen level requires it.
Our implementation focus
Make the requirements operational.
- 01
Define the cloud service and applicable STAR level
- 02
Map current controls to the Cloud Controls Matrix
- 03
Prepare CAIQ responses with supporting owners and evidence
- 04
Close cloud security gaps and establish review cadence
- 05
Coordinate a separate approved assessment where needed
STAR Level 1 is a provider self-assessment. Level 2 involves independent assessment; Normstone does not issue STAR certification or attestation.
Questions we hear
Get the distinctions right.
Does every STAR path require a third-party audit?
No. CSA STAR Level 1 is a self-assessment. Level 2 paths involve independent assessment or certification under CSA program rules.
How does STAR relate to ISO/IEC 27001?
CSA STAR Certification combines an ISO/IEC 27001 management system assessment with the Cloud Controls Matrix. Its outcome depends on the selected CSA scheme and independent assessor.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.