New Zealand Information Security Manual (NZISM)
Chapter 2: Information Security Services within Government – New Zealand Information Security Manual (NZISM)

New Zealand Information Security Manual (NZISM) 2.3.25.C.02: 2.3.25.C.02 Required content of a cloud adoption plan

An agency's cloud adoption plan should address: (1) the outcomes and benefits cloud adoption will deliver; (2) risks that cloud use introduces or reduces, and the agency's risk tolerance; (3) financial and cost accounting models; (4) shared responsibility models; (5) cloud deployment models; (6) the cloud security strategy; (7) resilience and recovery approaches; (8) recovering data when a contract ends; (9) the strategy for exiting the cloud, plus other contractual arrangements; and (10) a high level outline of the enabling foundation services for cloud use, namely identity for users, devices and systems; key management and encryption; management of information; alerting and logging; incident management; management of privileged activities; and cost management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.23 Information security for use of cloud services

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter 2: Information Security Services within Government – New Zealand Information Security Manual (NZISM)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.