An operator using a cloud service provider, as the regulator allows, to hold, move or handle sensitive information undergoes a specific audit reviewing the provider against cloud security principles such as ISO/IEC 27017 and 27018 or equivalent: the applicable requirements apply to the cloud environment, checking both what the provider runs and how the operator uses it; the shared responsibility allocation does not relieve the operator of ensuring sensitive information is secured; and clear agreed policies and procedures define responsibilities for operation, management and reporting for each requirement.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.