News

@cloudsa
cloudsecurityalliance.org > articles > checkbox-tprm-is-dead-start-engineering-risk

From Box Checker to Risk Engineer in TPRM | CSA

3+ day, 13+ hour ago  (530+ words) Let's say the quiet part out loud:Checkbox TPRM is a waste of time. Third-Party Risk Management (TPRM) used to be manageable. You had 20 critical vendors. You sent 20 spreadsheets. You received 20 PDFs. You looked at some fake security scores. You…...

@cloudsa
cloudsecurityalliance.org > articles > token-sprawl-in-the-age-of-ai

Token Sprawl in the AI Era | CSA

1+ mon, 6+ day ago  (503+ words) If your organization is experimenting with AI agents, copilots, or AI services accessed via API, you've probably created more identities than you intended. These non-human identities (service accounts and their associated API keys, tokens, etc.) keep modern systems talking to…...

@cloudsa
cloudsecurityalliance.org > articles > ai-governance-framework-adoption-in-cloud-native-ai-systems-phased-approach-and-considerations

AI Governance for Cloud-Native AI Systems | CSA

1+ mon, 3+ week ago  (207+ words) Create a cross-functional team to establish governance and accountability (AI/ML, DevOps, Security, and Legal) Map both the frameworks for close integration to establish common AI security framework Align governance and risk controls at each stage of the cloud native…...

@cloudsa
cloudsecurityalliance.org > blog > 12/10/2025 > how-to-build-ai-prompt-guardrails-an-in-depth-guide-for-securing-enterprise-genai

How to Build AI Prompt Guardrails: An In-Depth Guide | CSA

3+ mon, 1+ week ago  (938+ words) This challenge becomes much harder when organizations lack visibility into how third-party AI providers operate. Organizations often do not know how providers handle prompts. They also don't know if the model retains those prompts or how outputs might recreate sensitive…...

@cloudsa
cloudsecurityalliance.org > blog > 11/19/2025 > understanding-star-for-ai-level-2-a-practical-step-toward-ai-security-compliance

STAR for AI Level 2: AI Security Path | CSA

4+ mon, 7+ hour ago  (431+ words) STAR for AI Level 2 is a designation launched by CSA on November 20, 2025. STAR for AI Level 2 recognizes organizations that demonstrate a commitment to AI security through three key components: Organizations submit these components to the STAR Registry to receive the…...

CSA
cloudsecurityalliance.org > education > taise

Trusted AI Safety Expert (TAISE) Certificate | CSA

6+ mon, 3+ week ago  (539+ words) The industry-leading credential covers the full AI lifecycle from generative AI fundamentals and architecture to governance, risk management, privacy, and cloud security. Through a 10-module course and final exam, you'll gain the frameworks, tools, and practices needed to navigate regulatory…...

@cloudsa
cloudsecurityalliance.org > blog > 09/11/2025 > the-hidden-security-threats-lurking-in-your-machine-learning-pipeline

Threats Lurking in Your Machine Learning Pipeline | CSA

6+ mon, 1+ week ago  (880+ words) Machine learning operations (MLOps) have rapidly evolved from experimental workflows to production-critical systems powering everything from fraud detection to autonomous vehicles. But as organizations rush to deploy ML models at scale, they're discovering that traditional cybersecurity approaches fall woefully short…...

@cloudsa
cloudsecurityalliance.org > blog > 09/10/2025 > from-policy-to-prediction-the-role-of-explainable-ai-in-zero-trust-cloud-security

Explainable AI for Zero Trust Cloud Security | CSA

6+ mon, 1+ week ago  (1544+ words) You trust AI to protect your systems. It spots threats, blocks risks, and makes fast calls. But do you know how it reaches those decisions? In a Zero Trust model, that question becomes critical. You can't afford to just trust…...

@cloudsa
cloudsecurityalliance.org > articles > ai-model-scanning-vs-ai-red-teaming

Securing AI: Model Scanning & Red Teaming | CSA

9+ mon, 4+ week ago  (968+ words) Originally published by TrojAI. Written by Julie Peterson. Self-driving cars, facial recognition software, automated hiring tools, AI chatbots. AI is everywhere. And like any transformative technology, it brings with it a whole new set of security challenges. We're not just…...