ISO 27017:2015
Annex A – Cloud service extended control set – ISO 27017:2015

ISO 27017:2015 CLD.8.1.5: Removal of cloud service customer assets

Objective ISO/IEC 27002 8.1 applies. Control, in substance: when the cloud service agreement ends, whatever customer assets sit at the provider are to be taken off the provider's systems promptly and handed back where that is needed. Cloud service customer: request a documented description of the termination of service process covering return and removal of its assets and deletion of all copies from the provider's systems, listing all assets and documenting the timetable for termination, which should occur in a timely manner. Cloud service provider: provide information about the arrangements for returning and removing any customer assets on termination of the agreement, documented in the agreement, performed in a timely manner and specifying the assets to be returned and removed.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A – Cloud service extended control set – ISO 27017:2015

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.