-

Cloud Security Alliance Releases Report on Corda Blockchain Framework and Security Controls

Report offers security and risk management leaders and financial regulators ways to proactively prevent, detect, and respond to potential risks

SEATTLE--(BUSINESS WIRE)--The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released Corda Enterprise 4.8 – Architecture Security Report and an accompanying security controls checklist. Drafted by the CSA Blockchain/Distributed Ledger Working Group, the report examines the security of r3’s blockchain framework, Corda Enterprise 4.8 Permissioned Network, and offers ways to mitigate negative business impacts that could arise from such threats as improper business logic flow and insecure network implementation, among others.

“Our aim when drafting this paper was to bring security and risk management leaders new to Corda DLT implementations quickly up to speed with respect to associated organizational risks so that they, in turn, can better estimate operational costs while simultaneously balancing their security needs with business priorities,” said Bill Izzo, chair of the Blockchain/DLT Working Group.

The researchers, led by Urmila Nagvekar, one of the paper’s co-authors, sought ways to help security and risk management leaders, as well as regulators in the financial sector, proactively prevent, detect, and respond to potential risks by:

  • identifying Corda’s architectural risks to cybersecurity attributes (privacy, confidentiality, integrity, availability) when implemented as a permissioned enterprise network for a trade finance business in a cloud-based environment
  • delivering a fully implementable security controls checklist aligned with the NIST Cybersecurity Framework’s Controls.

Key takeaways from the report include an overview of how Corda 4.8 was used to depict a transaction within a trade finance workflow; the steps, method, and results of the Corda 4.8 risk identification process; and cryptography module recommendations for a Corda 4.8 permissioned network.

The Blockchain/Distributed Ledger Working Group works to produce useful content to educate different industries on blockchain and its proper use, as well as define blockchain security and compliance requirements based upon different industries and use cases. Individuals interested in becoming involved in Blockchain/Distributed Ledger future research and initiatives are invited to join the working group.

Learn more about this blockchain framework and its use in this pre-recorded webinar or download the full Corda Enterprise 4.8 – Architecture Security Report and the accompanying security controls checklist.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Contacts

Kristina Rundquist
ZAG Communications for the CSA
kristina@zagcommunications.com

Cloud Security Alliance


Release Summary
The report examines the security of r3’s blockchain framework and offers ways to mitigate negative impacts that might arise from various threats.
Release Versions

Contacts

Kristina Rundquist
ZAG Communications for the CSA
kristina@zagcommunications.com

More News From Cloud Security Alliance

New Study from Cloud Security Alliance Finds AI Improves Analyst Accuracy, Speed, and Consistency in Security Investigations

SEATTLE--(BUSINESS WIRE)--A new CSA survey found that AI-assisted security analysts demonstrate greater speed and accuracy compared to those working manually....

Cloud Security Alliance’s AI Safety Initiative Named a 2025 CSO Awards Winner

SEATTLE--(BUSINESS WIRE)--The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, is excited to announce that its AI Safety Initiative has been named a winner of the 2025 CSO Awards, which recognize organizations for their exceptional security projects and initiatives that showcase substantial business value and innovative thought leadership. The AI Safety Initiat...

Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

SEATTLE--(BUSINESS WIRE)--CSA introduces an innovative addition to its suite of STAR Registry assessments with Valid-AI-ted, an AI-powered, automated validation system....
Back to Newsroom