Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Cloud Security Alliance CAIQ 4.0 Update - October 2022

Atlassian maintains submissions to the Cloud Security Alliance (CSA) STAR Registry for our major Cloud Services. The STAR Registry hosts the Consensus Assessment Initiative Questionnaire (CAIQ), which is a spreadsheet made up of questions and responses to common cloud security practices.

Atlassian originally completed the CAIQ for Jira and Confluence Cloud in early 2016 and has updated the responses as there have been changes to our operations, expanded our products, or our internal processes. Over time, we have also extended the CAIQ submissions for each of our major cloud services, creating responses for Opsgenie, Bitbucket, Statuspage, Trello, Jira Align, and most recently Halp. More recently, we put a program in place to update the CAIQ for each of our cloud services on a quarterly basis.

The CAIQ also serves as our primary response for our customers asking us to complete a Vendor Security and Risk Review.

Download the current Cloud Security Alliance CAIQ 4.0 questionnaires

Most notably, last quarter, we updated all of our CSA STAR entries to the new CAIQ version 4.0, which includes additional responses for each question that detail which organization (either Cloud Provider, Cloud Customer, or third party) a control is owned by, and any guidance we provide for controls that are partially or fully owned by a Cloud Customer. The new version has also cut down on overall questions, totaling around 260 questions and responses.

We published updates to the CAIQ responses to the STAR registry in October 2022 to add any changes that have occurred over the last quarter.

Go to our CSA Resource page, or the Atlassian CSA STAR registry entry to download our current questionnaires. Please let us know if you have questions.

3 comments

Comment

Log in or Sign up to comment
Vish Reddy _Revyz_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 24, 2022

Thank you for sharing the update @pknowlton.

The changes from v3.1 to v4.0 of the CAIQ are primarily focussed on addressing the the lack of understanding of the shared responsibility model - reference this very good blog post from the Cloud Security Alliance. 

Atlassian has two very good documents which talk to about the shared responsibility model:

- Atlassian Shared Responsibility

- Atlassian Security Practices

Like # people like this
Vikki Ulmer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 24, 2022

Hi @Vish Reddy _Revyz_ - I am happy to hear you find these documents helpful!

I wanted to let you know that we recently updated the Shared Responsibility document, and the most up-to-date version can be found at the link below:

https://www.atlassian.com/whitepapers/cloud-security-shared-responsibilities

We are working to make sure all links go to this version, and please let me know if you have any questions!

Best, Vikki

Like # people like this
Vish Reddy _Revyz_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 24, 2022

Thank you so much @Vikki Ulmer for sharing the updated link.

It would be great if the customer responsibilities are somehow called out as part of the Cloud migration guide.

Lot of folks seem to be under the wrong impression that -  when they migrate to the cloud all the responsibilities are somehow belonging to the vendor, specially when it comes to managing their "information / data", which is incorrect.

Atlassian as well as other SaaS vendors like Microsoft and others clearly state that customers need to protect their data as called in the Atlassian shared responsibilities doc - "Create backups of your data" as these backups help customers recover back their data lost due to "customer-initiated destructive changes".

Thank you

Vish

TAGS
AUG Leaders

Atlassian Community Events