ISO 27002:2022 5.23: Information security for use of cloud services
Processes for buying, using, managing and leaving cloud services are to be set up so that they satisfy what the organization requires for information security. Purpose: specify and manage the security of the organization's cloud service use. Guidance: publish a topic-specific cloud policy to relevant parties and state how cloud risks will be managed, possibly as part of the wider approach to external services (5.21, 5.22). Cloud use usually means shared responsibility, so the provider's and customer's duties must be defined and carried out. The organization defines its security requirements for cloud use; selection criteria and scope of use; roles and responsibilities; which controls the provider runs and which it runs itself; how to obtain and use provider security capabilities; how to gain assurance over provider controls; how controls, interfaces and service changes are handled when several services or providers are in use; incident procedures for cloud-related incidents; how ongoing use is monitored, reviewed and evaluated; and how to change or stop using a service, including exit strategies. Cloud agreements are often fixed, but each should be reviewed and should address confidentiality, integrity, availability and handling needs with suitable quantitative and qualitative service objectives; risk assessments should be done and residual risk explicitly accepted by the right managers. Agreements should provide for: architecture and infrastructure built on accepted industry standards; access control meeting the organization's needs; malware monitoring and protection; processing and storing sensitive information in approved countries, regions or jurisdictions; dedicated support during incidents in the cloud environment; the organization's requirements holding if the provider subcontracts, or a ban on subcontracting; help with gathering digital evidence across jurisdictions; support and availability for a suitable period during exit; backup of data and configuration with secure handling of backups as the provider's capabilities allow; and return of configuration files, source code and data the organization owns, on request or at termination. Consider requiring advance notice of substantive changes such as infrastructure relocation or reconfiguration, processing in a new geography or jurisdiction, and use of new or changed peer providers or subcontractors. Keep close contact with providers so both sides can exchange security information, monitor service characteristics and report missed commitments. Other information: this is the customer's view; ISO/IEC 17788, 17789, 22123-1, 19941 (portability), 27017, 27018, 27036-4 and the 19086 series (19086-4 for security and privacy) give more.
This control maps to 95 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.23 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.