CSA looks to incident management and forensics

The Cloud Security Alliance’s newest working group releases its first whitepaper on Conducting Forensic Investigation in Cloud Environments

The Cloud Security Alliance(CSA) has created a new Working Group targeting  Incident Management and Forensics, that will focus on the examination of incident handling and forensics in cloud environments.

As start point for its work the Group conducted an assessment of current issues and published its findings in the Working Group's first white paper, entitled: `Mapping the Forensic Standard ISO/IEC 27037 to Cloud Computing.’

This is aimed at helping researchers, data governance experts, and forensic practitioners define standardised processes for conducting forensic investigations, eDiscovery, and other critical aspects of security that are inherent in a multi-tenant, highly virtualised environment.

The paper covers topics such as Forensic Requirements for CSPs, a detailed analysis of ISO 27037(an international standard that seeks to create a common baseline for the practice of digital forensics and explores how this standard should be mapped to the cloud.

"The objective of this new CSA Working Group is to define best practices that consider the legal, technical, and procedural elements of responding to security incidents in the cloud in a forensically sound way," said Dominik Birk, co-chair of the CSA Incident Management and Forensics Working Group. "This initial whitepaper represents a significant effort on behalf of numerous individuals and marks an important first step in conducting proper forensic investigations in Cloud Environments following a security incident."

The Incident Management and Forensic Working Group is co-chaired by Dominik Birk of Zurich Insurance Company Ltd. and Michael Panico of Stroz Frieberg LLC. It plans to release another research paper , `Developing a Capability Maturity Model (CMM) for Incident Management and Forensics in Cloud Environments’ during in Q4 of this year.

The CSA, which is a not-for-profit organisation set up to promote the use of best practices for providing security assurance within Cloud Computing, is also keen to hear from any companies and individuals interested in supporting the group's research and initiatives. A secondary objective is to provide education on the uses of Cloud Computing to help secure all other forms of computing. It is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders.

Kiteworks and Kasm partner to provide secure data management for distributed teams and partner...
Red Cactus and Tollring launch AI conversation analytics to support CRM integration across over 200...
F5 reveals new AI-driven security features in its ADSP that aim to enhance application protection...
Teleport’s infrastructure identity platform has been named a 2026 SC Awards Finalist in the Best...
WSO2 unveils a fresh focus on supporting agentic enterprises, aiming to strengthen AI deployment...
ServiceNow introduces AI innovations, Autonomous Workforce and EmployeeWorks, aiming to enhance...
NTT DATA and Ericsson collaborate to deploy enterprise private 5G networks, enabling edge AI and...
ElevenLabs and Google Cloud strengthen collaboration to offer advanced AI voice tools for global...