ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.23: Information security for use of cloud services

Processes for buying, using, managing and leaving cloud services are to be set up so that they satisfy what the organization requires for information security. Purpose: specify and manage the security of the organization's cloud service use. Guidance: publish a topic-specific cloud policy to relevant parties and state how cloud risks will be managed, possibly as part of the wider approach to external services (5.21, 5.22). Cloud use usually means shared responsibility, so the provider's and customer's duties must be defined and carried out. The organization defines its security requirements for cloud use; selection criteria and scope of use; roles and responsibilities; which controls the provider runs and which it runs itself; how to obtain and use provider security capabilities; how to gain assurance over provider controls; how controls, interfaces and service changes are handled when several services or providers are in use; incident procedures for cloud-related incidents; how ongoing use is monitored, reviewed and evaluated; and how to change or stop using a service, including exit strategies. Cloud agreements are often fixed, but each should be reviewed and should address confidentiality, integrity, availability and handling needs with suitable quantitative and qualitative service objectives; risk assessments should be done and residual risk explicitly accepted by the right managers. Agreements should provide for: architecture and infrastructure built on accepted industry standards; access control meeting the organization's needs; malware monitoring and protection; processing and storing sensitive information in approved countries, regions or jurisdictions; dedicated support during incidents in the cloud environment; the organization's requirements holding if the provider subcontracts, or a ban on subcontracting; help with gathering digital evidence across jurisdictions; support and availability for a suitable period during exit; backup of data and configuration with secure handling of backups as the provider's capabilities allow; and return of configuration files, source code and data the organization owns, on request or at termination. Consider requiring advance notice of substantive changes such as infrastructure relocation or reconfiguration, processing in a new geography or jurisdiction, and use of new or changed peer providers or subcontractors. Keep close contact with providers so both sides can exchange security information, monitor service characteristics and report missed commitments. Other information: this is the customer's view; ISO/IEC 17788, 17789, 22123-1, 19941 (portability), 27017, 27018, 27036-4 and the 19086 series (19086-4 for security and privacy) give more.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 95 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • 12.6.1 12.6.1 Formal security awareness program
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 9.4.1 9.4.1 Physical security of all media

FedRAMP High · 7 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • AC-20(2) Portable Storage Devices Restricted Use
  • CA-7 Continuous Monitoring
  • RA-9 Criticality Analysis (RA-9)
  • SA-9 External System Services
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))

FedRAMP Moderate · 7 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • AC-20(2) Portable Storage Devices Restricted Use
  • CA-7 Continuous Monitoring
  • RA-9 Criticality Analysis (RA-9)
  • SA-9 External System Services
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))

NIST SP 800-53 Rev 5 · 6 controls

SOC 2 · 6 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • ISM-1574 Portable data storage in contracts
  • ISM-1575 Notice of service cessation
  • ISM-1637 Outsourced cloud service register
  • ISM-1638 Cloud service register contents
  • ISM-1972 ASD assessment of TOP SECRET cloud services
  • SEC01-BP01 Separate workloads using accounts
  • SEC01-BP05 Reduce security management scope
  • SEC01-BP08 Evaluate and implement new security services and features regularly
  • SEC03-BP05 Define permission guardrails for your organization
  • AM-2 Use only approved services
  • AM-3 Ensure security of asset lifecycle management
  • ASBv3-PA-8 Determine access process for cloud provider support
  • PV-2 Audit and enforce secure configurations

CIS Controls v8 · 4 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.6 Monitor Service Providers
  • CIS-15.7 Securely Decommission Service Providers
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • 2.3.25.C.02 2.3.25.C.02 Required content of a cloud adoption plan
  • 22.1.21.C.07 22.1.21.C.07 Documented risk assessment and GCDO endorsement for cloud use
  • 22.1.22.C.03 22.1.22.C.03 Endorsement for offshore cloud linked to All-of-Government systems
  • 22.1.22.C.06 22.1.22.C.06 Conditions before using offshore cloud services

ISO/IEC 42001:2023 · 3 controls

  • A.4 Resources for AI systems
  • A.9 Use of AI systems
  • A.9.2 Processes for responsible use of AI systems

MTCS (Singapore) · 3 controls

  • A.11 Disclosure: Shared responsibility
  • A.16 Disclosure: Data portability
  • A.5 Disclosure: Data sovereignty

NIST SP 800-161 Rev 1 · 3 controls

DORA · 2 controls

ISO 27701:2019 · 2 controls

  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.2 Countries and international organizations to which PII can be transferred

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement

APRA CPS 234 · 1 control

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • SEC.HOST Onshore data hosting with hosting provider details given to the ATO
  • MYHR-REG-8 Copyright conditions on handling old records for operators and service providers

C5 (Germany) · 1 control

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

ISO 27001:2022 · 1 control

  • 5.23 Information security for use of cloud services

NIS2 Directive · 1 control

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.23 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 95 it maps to, and the evidence behind each claim, over MCP and REST.