惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
WordPress大学
WordPress大学
H
Help Net Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
MyScale Blog
MyScale Blog
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
博客园 - 【当耐特】
P
Proofpoint News Feed
D
DataBreaches.Net

Cloud Security Alliance

SearchLeak: Copilot Data Exfiltration Exploited | CSA Zero-Trust AI Governance for Multi-Agent Systems | CSA Dangling CNAMEs: Hidden Cloud Risk | CSA Agentic Payments in Financial Services | CSA Mythos and the Future of Cybersecurity | CSA AI-Driven Cloud Risk: Defenders Lose Ground | CSA Financial Services Industry Shifts from AI Adoption to | CSA CSAI Foundation Announces RiskRubric V2 as the Next Key | CSA RiskRubric Updates: AI Risk Assessment | CSA Over 80% of Organizations that Miss 24-Hour Patch Window Report | CSA ORCHIDEAS & MAESTRO: Secure AI Design | CSA Top 6 Claude Security Risks to Watch | CSA Cloud Cost Optimization in 2026 | CSA HIPAA Rule Overhaul in 2026 | CSA AI-Driven Exploits Outsmart Detection | CSA MCP Risks CISOs Should Prepare For | CSA AI Governance for Trust and Compliance | CSA MTTP: Patch Cycles Too Slow | CSA Cloud Security Evolution: Security Teams Lead | CSA Misconfigurations Break Customer Trust in Apps | CSA Taming Shadow AI: C-Suite Strategies | CSA Agentic AI Threats: Five Powers | CSA AIUC-1: Agentic AI Governance | CSA 2026 Threat Report for CISOs | CSA Securing AI in AWS: Runtime Detection & Response | CSA SLMs, LLMs, and the DSPM Difference | CSA OT Security Timeline: Mythos and Patch Pace | CSA Blast Radius and Cloud Threat Detection | CSA State of AI Cybersecurity 2026: 92% Concerned | CSA AI in MDR for Franchise & Multi-Location Ops | CSA
Cloud to AI: Building Secure Programs | CSA
2026-04-24 · via Cloud Security Alliance

Written by Sean Martin, Co-Founder of ITSPmagazine.

At RSAC Conference 2026, Sean Martin caught up with Rich Mogull at the Cloud Security Alliance (CSA) booth for a candid on-site conversation about where enterprise security programs stand today -- and what it actually takes to keep pace with AI. Mogull, who joined CSA as Chief Analyst in October 2025, brings a practitioner's instinct to a research-first organization. The result is a new membership model designed not just to produce guidance, but to help organizations act on it.

What Does the Cloud Security Alliance Actually Cover?

CSA is best known for cloud security, but Mogull is quick to point out that the organization operates across three distinct pillars: cloud, zero trust, and AI. The connection is not arbitrary. Zero trust principles emerged in large part as a response to cloud adoption, and AI workloads are predominantly cloud-native. Each pillar represents a transformational technology that security teams have had to absorb without a clear roadmap -- and that is precisely where CSA has tried to fill the gap.

"Our sweet spot is these transformational, disruptive technologies," Mogull explains. He traces his own journey back to 2009, when cloud was still a fringe concept, and notes that existing security practices rarely translate cleanly into new paradigms. The frameworks that work well for on-premises environments do not map neatly onto cloud-native architectures, and the same challenge is now repeating itself with AI. CSA's role, as Mogull sees it, is to get ahead of that curve through rigorous, practitioner-informed research.

What Is the AI Security Maturity Model and Why Does It Matter?

The AI Security Maturity Model gives enterprise security teams a structured lens for assessing and improving their AI security posture. Unlike generic capability frameworks, it is built around measurable outcomes, key performance indicators, and categories specific to AI environments -- including model security, AI infrastructure, agentic applications, MCP servers, and AI developer enablement. The model is currently in its final review phase after receiving more than 600 comments from 60 international reviewers.

Mogull designed the model as a practical companion to CSA's existing Cloud Security Maturity Model, which he also authored. The approach is consistent: define the journey, build in measurable KPIs, and make the outputs as automatable as possible so organizations can connect tools like cloud security posture management platforms directly to their maturity tracking. "My focus is always how do I make something a usable tool, not just an interesting piece of research," he says. The AI model extends that philosophy into a domain where practitioners often feel they are flying blind.

How Is CSA Helping Organizations Move From Research to Implementation?

Producing research is one thing. Helping organizations apply it is another. Mogull joined CSA in part because he recognized that gap firsthand -- spending years as an independent consultant helping clients implement the very frameworks CSA had produced. That model does not scale. So one of his primary mandates is to build scalable support structures directly into the membership program.

CSA's new Enterprise Membership tiers -- announced in March 2026 -- center on what Mogull calls the Operational Maturity Roadmap. Members begin with an onboarding assessment, then work with CSA analysts on a monthly basis to receive specific, structured guidance tied to their maturity level across cloud, AI, and zero trust. The program culminates in an annual progress report tracking measurable improvement against defined goals. "I want to deliver better outcomes," Mogull says. "Not just research on a shelf, but evidence that an organization has actually moved." The three-year arc runs from foundational through operationalization to external communications -- including support for completing STAR registry entries and the Consensus Assessment Initiative Questionnaire.

Watch the full Brand Spotlight conversation with Rich Mogull and explore the Cloud Security Alliance's research, maturity models, and membership programs. Connect with Rich Mogull on LinkedIn.