ISO 27017:2015
Annex A – Cloud service extended control set – ISO 27017:2015

ISO 27017:2015 CLD.12.4.5: Monitoring of cloud services

Objective ISO/IEC 27002 12.4 applies. Control, in substance: the customer is to be able to observe defined aspects of how the cloud services it uses are operating. Cloud service customer: request information from the provider on the service monitoring capabilities available for each cloud service. Cloud service provider: provide capabilities that let the customer monitor specified aspects of the service's operation relevant to the customer, for example whether the service is being used as a platform to attack others or whether sensitive data is leaking from it; protect use of the monitoring capabilities with access controls so that they give access only to information about the customer's own service instances; document the capabilities for the customer; and provide monitoring data consistent with the event logs of 12.4.1 that assists with SLA terms.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 1 control

  • C5-OPS-13 Logging and Monitoring - Identification of Events

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A – Cloud service extended control set – ISO 27017:2015

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.