CCSK

 View Only
  • 1.  What is the process to update the CSA security guidance V4 doc?

    Posted Sep 09, 2021 10:45:00 AM
    Team,
    Was wondering what is the process to suggest an update to the CSA security guidance V4 doc.
    Specifically, the document refers to NIST SP500-299 which AFAIK was retired 5/2018 and is no longer actively maintained or available. 
    Seems that we should remove the reference. 
    On a related note, will be great to have a pointer in the security guidance doc as to where someone reading the doc should go to suggest an update. my apologies if this pointer is already in the doc and I missed it.

    Your guidance appreciated,
    Mark

    ------------------------------
    Mark Carter
    General Manager
    AWS
    ------------------------------


  • 2.  RE: What is the process to update the CSA security guidance V4 doc?

    Posted Sep 10, 2021 11:06:00 AM
    Hello!
    Thanks for your question :) 
    There are two ways you can submit feedback for the Security Guidance.
    1. You can email any changes to: [email protected] 
    2. You can join our Security Guidance Working Group who is now working on V5 of the Security Guidance (planned to be released sometime next year): https://cloudsecurityalliance.org/research/working-groups/security-guidance/


    ------------------------------
    Jenna Morrison
    Training Department Intern
    Cloud Security Alliance
    ------------------------------