Key Takeaways
  • ISO 27017 and CSA STAR are complementary rather than competing frameworks — they serve different purposes in cloud security assurance.
  • CSA STAR Level 2 actually builds on ISO 27001 certification, making ISO 27001 + ISO 27017 a natural stepping stone to STAR.
  • CSA CCM v4 provides explicit mapping to ISO 27001 and ISO 27017 controls, enabling efficient cross-framework implementation.
  • The CSA STAR Registry provides public visibility that ISO certification alone does not — it is a searchable directory buyers actively use.
  • For maximum cloud security credibility, pursue ISO 27001 + ISO 27017 as the foundation, then add CSA STAR Level 2 for public registry visibility.

Overview

When positioning your cloud security posture, two frameworks frequently appear alongside SOC 2: ISO 27017 (as part of ISO 27001) and CSA STAR with the Cloud Controls Matrix (CCM). While some organizations view these as alternatives, they are actually highly complementary frameworks that, when combined, provide the strongest cloud security positioning available.

This article explains what each framework provides, how they map to each other, and the optimal strategy for pursuing them based on your market and customer requirements.

What is CSA STAR?

CSA STAR (Security Trust Assurance and Risk) is a cloud security assurance program developed by the Cloud Security Alliance (CSA). It provides a framework for cloud service providers to demonstrate their security posture through a tiered certification program.

Key characteristics of CSA STAR:

  • Cloud-focused: Designed exclusively for cloud service providers and their security practices
  • Tiered approach: Three levels of assurance from self-assessment to continuous monitoring
  • Public registry: Certified providers are listed on the publicly searchable CSA STAR Registry
  • Built on existing frameworks: Levels 2 and 3 build on ISO 27001 or SOC 2 rather than replacing them
  • Industry-driven: Developed by the CSA, a leading cloud security industry organization with broad industry participation

What is the Cloud Controls Matrix (CCM)?

The Cloud Controls Matrix (CCM) is the control framework that underpins CSA STAR. Currently in version 4, the CCM provides a comprehensive set of cloud security controls organized into 17 domains:

CCM v4 Control Domains

  1. Audit & Assurance (A&A) — Independent audit, compliance, and assurance processes
  2. Application & Interface Security (AIS) — Secure development and API security
  3. Business Continuity Management (BCM) — Resilience and recovery planning
  4. Change Control & Configuration Management (CCC) — Change processes and configuration baselines
  5. Cryptography, Encryption & Key Management (CEK) — Cryptographic controls and key lifecycle
  6. Datacenter Security (DCS) — Physical security of data center facilities
  7. Data Security & Privacy Lifecycle Management (DSP) — Data classification, protection, and lifecycle
  8. Governance, Risk & Compliance (GRC) — Governance structures and risk management
  9. Human Resources (HRS) — Personnel security and awareness
  10. Identity & Access Management (IAM) — Access control and identity lifecycle
  11. Interoperability & Portability (IPY) — Data portability and service interoperability
  12. Infrastructure & Virtualization Security (IVS) — Virtual infrastructure and network security
  13. Logging & Monitoring (LOG) — Security event logging and monitoring
  14. Security Incident Management (SEF) — Incident response and forensics
  15. Supply Chain Management (STA) — Third-party and supply chain security
  16. Threat & Vulnerability Management (TVM) — Vulnerability management and threat intelligence
  17. Universal Endpoint Management (UEM) — Endpoint security management

The CCM is designed as a meta-framework — it maps to multiple standards and regulations including ISO 27001, ISO 27017, ISO 27018, SOC 2, NIST CSF, PCI DSS, and GDPR. This cross-mapping capability is one of its greatest strengths.

CSA STAR Certification Levels

Level Name Assessment Type Prerequisite Output
Level 1 Self-Assessment CSP completes CAIQ (Consensus Assessments Initiative Questionnaire) or CCM self-assessment None Published on STAR Registry
Level 2 Third-Party Assessment Independent audit against CCM controls combined with ISO 27001 or SOC 2 ISO 27001 or SOC 2 CSA STAR Certification or Attestation + STAR Registry
Level 3 Continuous Monitoring Continuous automated monitoring and assessment Level 2 + continuous monitoring capability STAR Continuous certification + STAR Registry
CSA STAR Level 2 + ISO 27001

The most common path to CSA STAR Level 2 is through ISO 27001. The certification body audits your ISMS against both ISO 27001 requirements and CCM controls in a single engagement. If you already include ISO 27017 controls in your SoA, you will have significant coverage of CCM requirements already in place.

Side-by-Side Comparison

Aspect ISO 27017 (via ISO 27001) CSA STAR (with CCM)
Developer ISO/IEC (international standards body) Cloud Security Alliance (industry organization)
Type International standard (code of practice) Industry certification program
Cloud Specificity High — 7 cloud controls + extended guidance Very high — entirely cloud-focused
Control Framework ISO 27002 + 7 CLD controls CCM v4 (197 controls across 17 domains)
Assessment Third-party certification audit Self-assessment (L1), third-party audit (L2), continuous (L3)
Public Visibility Certificate can be published Listed on searchable STAR Registry
Relationship Extension to ISO 27001 Built on ISO 27001 or SOC 2
Shared Responsibility Required (CLD.6.3.1) Addressed through CCM control domains
Cross-Framework Mapping Aligns with ISO 27002 directly Maps to ISO 27001, ISO 27017, SOC 2, NIST, PCI DSS, GDPR
Market Recognition Strong globally (ISO brand) Strong in cloud procurement (CSA brand)
Cost (incremental) $5,000-15,000 (added to ISO 27001 audit) $5,000-20,000 (Level 2 added to ISO 27001 audit)

CCM to ISO 27017 Control Mapping

CSA CCM v4 includes explicit mapping to ISO 27001 and ISO 27017. Here are the key alignments between ISO 27017 CLD controls and CCM domains:

ISO 27017 CLD Control CCM v4 Domain(s) Key CCM Controls
CLD.6.3.1 — Shared Responsibilities GRC, STA GRC-02, GRC-03, STA-02
CLD.8.1.5 — Asset Removal DSP, IPY DSP-04, DSP-17, IPY-01, IPY-04
CLD.9.5.1 — Virtual Segregation IVS IVS-03, IVS-06, IVS-09
CLD.9.5.2 — VM Hardening IVS, CCC IVS-04, IVS-05, CCC-01, CCC-02
CLD.12.1.5 — Admin Security IAM IAM-02, IAM-04, IAM-07, IAM-14
CLD.12.4.5 — Monitoring LOG LOG-01, LOG-03, LOG-05, LOG-09
CLD.13.1.4 — Network Alignment IVS IVS-01, IVS-06, IVS-09

This mapping demonstrates significant overlap. Organizations that have implemented ISO 27017 controls will find that a substantial portion of CCM requirements are already addressed. The incremental effort to achieve CSA STAR Level 2 is therefore relatively modest.

How ISO 27017 and CSA STAR Complement Each Other

ISO 27017 Provides the Certification Foundation

ISO 27001 with ISO 27017 provides a globally recognized, accredited certification. This carries the weight of an ISO standard — universally understood and accepted in procurement, regulation, and governance. It provides:

  • Formal management system certification with 3-year validity
  • Accredited third-party audit by a certification body
  • Cloud-specific controls audited as part of the ISMS
  • Global recognition and regulatory acceptance

CSA STAR Adds Cloud-Specific Visibility

CSA STAR adds several dimensions that ISO certification alone does not provide:

  • Public registry: The CSA STAR Registry is a searchable directory where buyers actively look for cloud provider security information. Your listing appears alongside major cloud providers.
  • CAIQ transparency: The published CAIQ responses provide buyers with detailed answers to cloud security questions without requiring NDA-protected reports.
  • Cloud-specific brand: The CSA brand is synonymous with cloud security, adding cloud-focused credibility beyond what "ISO 27001" conveys.
  • Maturity scoring: CSA STAR provides a maturity model that allows organizations to demonstrate improvement over time.

Together: Complete Cloud Security Positioning

The combination of ISO 27001 + ISO 27017 + CSA STAR Level 2 provides:

  • Formal management system certification (ISO 27001)
  • Cloud-specific security controls (ISO 27017)
  • Public registry visibility (CSA STAR)
  • Detailed cloud security transparency (CAIQ/CCM)
  • Cross-framework coverage for diverse buyer requirements

Which to Pursue: Decision Framework

Scenario 1: You Already Have ISO 27001

Recommended path: Add ISO 27017 controls to your SoA at the next surveillance or recertification audit. Then pursue CSA STAR Level 2, which builds directly on your ISO 27001 certification.

Incremental effort: Low to moderate. ISO 27017 adds 2-4 months of preparation; CSA STAR Level 2 adds 1-2 months beyond that.

Scenario 2: You Have Neither

Recommended path: Start with ISO 27001 + ISO 27017 as an integrated implementation. Once certified, add CSA STAR Level 1 (self-assessment) immediately for public registry presence, then pursue Level 2 at the next audit cycle.

Total timeline: 6-12 months for ISO 27001 + ISO 27017, then 1-3 months to add STAR Level 2.

Scenario 3: You Primarily Serve US Markets

Recommended path: Prioritize SOC 2 for US buyer requirements, then add CSA STAR Level 2 (attestation track) which builds on SOC 2. Consider ISO 27001 + ISO 27017 when international expansion is planned.

Scenario 4: You Need Maximum Credibility Fast

Recommended path: Pursue ISO 27001 + ISO 27017 and register for CSA STAR Level 1 (self-assessment) immediately. The self-assessment provides public STAR Registry presence while the ISO certification is in progress. Upgrade to STAR Level 2 once ISO 27001 is achieved.

Market Positioning Strategy

For Cloud Service Providers

The optimal cloud security positioning stack for CSPs serving global markets:

  1. Foundation: ISO 27001 certification — management system credibility
  2. Cloud Layer: ISO 27017 controls in SoA — cloud-specific security assurance
  3. Visibility Layer: CSA STAR Level 2 — public registry and cloud brand association
  4. US Market Layer: SOC 2 Type II — North American buyer satisfaction

This four-layer approach covers every major buyer requirement globally. Each layer builds on the previous one, making the incremental effort for each subsequent certification relatively modest.

For Cloud Service Customers

CSCs can use these frameworks as evaluation criteria when assessing providers:

  • Minimum bar: ISO 27001 certification with cloud services in scope
  • Better: ISO 27001 + ISO 27017 controls referenced on the certificate
  • Best: ISO 27001 + ISO 27017 + CSA STAR Level 2 listing on the registry
  • US-focused: SOC 2 Type II with Security + Availability criteria

The STAR Registry is a particularly useful tool for cloud service customers. It provides a centralized, searchable directory where you can evaluate potential providers' cloud security posture before engaging in formal procurement. Use it early in vendor evaluation to shortlist providers.

Frequently Asked Questions

What is the difference between ISO 27017 and CSA STAR?

ISO 27017 provides cloud-specific security controls within the ISO 27001 framework. CSA STAR is a cloud security assurance program with multiple levels based on the Cloud Controls Matrix (CCM). ISO 27017 is a standard; CSA STAR is a certification program that builds on existing certifications like ISO 27001.

Can I map ISO 27017 controls to CSA CCM?

Yes. CSA CCM v4 includes explicit mapping to ISO 27001 and ISO 27017. Many controls overlap, and the CCM mapping can be used to demonstrate coverage across both frameworks. This is particularly useful when pursuing CSA STAR Level 2 based on ISO 27001.

Should I pursue ISO 27017 or CSA STAR?

They complement rather than replace each other. ISO 27001 with ISO 27017 provides the certification foundation. CSA STAR adds cloud-specific visibility through the public STAR Registry. CSA STAR Level 2 actually requires ISO 27001 or SOC 2, making ISO 27001 + ISO 27017 a natural stepping stone.

What is CSA STAR Level 2?

CSA STAR Level 2 is a third-party assessment that combines ISO 27001 certification or SOC 2 attestation with assessment against the CSA Cloud Controls Matrix (CCM). It results in a CSA STAR Certification or Attestation listed on the public CSA STAR Registry, providing buyers with verified cloud security assurance.

Is CSA STAR recognized internationally?

Yes. CSA STAR has global recognition, particularly in cloud-focused procurement. The STAR Registry is publicly accessible and used by buyers worldwide to evaluate cloud provider security. It is most recognized in North America and Europe but has growing adoption in APAC and Middle East.