Cloud Security Alliance CAIQ 4.0 Updates - July 2022

Atlassian maintains submissions to the Cloud Security Alliance (CSA) STAR Registry for our major Cloud Services. The STAR Registry hosts the Consensus Assessment Initiative Questionnaire (CAIQ), which is a spreadsheet made up of questions and responses to common cloud security practices.

Atlassian originally completed the CAIQ for Jira and Confluence Cloud in early 2016, and have updated the responses as there have been changes to our operations, expanded our products or our internal processes. Over time, we have also extended the CAIQ submissions for each of our major cloud services, creating responses for Opsgenie, Bitbucket, Statuspage, Trello, Jira Align and most recently Halp. More recently, we put a program in place to update the CAIQ for each of our cloud services on a quarterly basis.

The CAIQ also serves as our primary response for our customers asking us to complete a Vendor Security and Risk Review.

Download the current Cloud Security Alliance CAIQ 4.0 questionnaires

Most notably, this quarter we have updated all of our CSA STAR entries to the new CAIQ version 4.0, which includes additional responses for each question that detail which organisation (either Cloud Provider, Cloud Customer, or third party) a control is owned by, and any guidance we provide for controls that are partially or fully owned by a Cloud Customer. The new version has also cut down on overall questions, totalling around 260 questions and responses.

We published updates to the CAIQ responses to the STAR registry in July 2022 to add any changes that have occurred over the last quarter as well as changing from CAIQ version 3.1 to CAIQ version 4.0.

Go to our CSA Resource page, or the Atlassian CSA STAR registry entry and download our current questionnaires. Please let us know if you have questions.

1 comment

Comment

Log in or Sign up to comment
Siggy Sveinsson
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 7, 2022

I like your article and there are good lessons here. I am curious though, how effective is it to use CAIQ 4 document to be used instead of answering customer/prospect questionnaires? Do they accept the document as a fulfilling response to their internal supplier evaluation for security?

TAGS
AUG Leaders

Atlassian Community Events