Cloud assurance

Build transparent cloud assurance for customers.

The Cloud Security Alliance STAR program uses the Cloud Controls Matrix and offers different assurance levels. We help cloud teams map controls, prepare an accurate self-assessment, and plan for independent assessment where the chosen level requires it.

Our implementation focus

Make the requirements operational.

  1. 01

    Define the cloud service and applicable STAR level

  2. 02

    Map current controls to the Cloud Controls Matrix

  3. 03

    Prepare CAIQ responses with supporting owners and evidence

  4. 04

    Close cloud security gaps and establish review cadence

  5. 05

    Coordinate a separate approved assessment where needed

Independent assessment

STAR Level 1 is a provider self-assessment. Level 2 involves independent assessment; Normstone does not issue STAR certification or attestation.

Questions we hear

Get the distinctions right.

Does every STAR path require a third-party audit?

No. CSA STAR Level 1 is a self-assessment. Level 2 paths involve independent assessment or certification under CSA program rules.

How does STAR relate to ISO/IEC 27001?

CSA STAR Certification combines an ISO/IEC 27001 management system assessment with the Cloud Controls Matrix. Its outcome depends on the selected CSA scheme and independent assessor.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation