ISO 27001 in the cloud
ISO 27001 does not care which cloud you use. It cares that you chose it deliberately, manage it as a supplier, and can show the Annex A controls you apply to it. Control 5.23 is where that is written down.
For ISO 27001:2022 in the cloud, three things matter beyond the usual ISMS work. Control 5.23 requires a documented process for acquiring, using, managing and exiting cloud services. Your Statement of Applicability must say how each relevant Annex A control is implemented in the cloud and what you inherit from the provider. And the certification body will test the technical controls in your cloud account much as a SOC 2 auditor would.
Control 5.23: information security for use of cloud services
Added in the 2022 revision. It expects:
- Criteria for selecting cloud services and assessing their security.
- A clear split of responsibilities between you and each provider, as in the shared responsibility model.
- How you obtain assurance from the provider: its ISO certificates and SOC 2 reports.
- How you manage changes the provider makes.
- An exit strategy: how you would retrieve data and move if you had to.
This applies to your IaaS provider and to every SaaS tool holding information in scope, so the record is a list, not a paragraph.
Annex A controls your cloud answers
| Control | Title | Cloud implementation |
|---|---|---|
| 5.15, 5.18 | Access control, access rights | Federated identity, role design, access reviews |
| 5.23 | Cloud services | Provider selection, responsibility matrix, exit plan |
| 8.2 | Privileged access rights | Just-in-time admin, break-glass accounts |
| 8.5 | Secure authentication | MFA through the identity provider |
| 8.9 | Configuration management | Infrastructure as code, policy baselines, configuration monitoring |
| 8.13 | Information backup | Backup plans, immutability, restore tests |
| 8.15, 8.16 | Logging, monitoring activities | Audit logs, retention, alerting |
| 8.20, 8.22 | Network security, segregation | Account boundaries, private subnets, security groups |
| 8.24 | Use of cryptography | Encryption at rest and in transit, key management |
| 8.8 | Technical vulnerabilities | Native scanners, remediation targets |
| 8.32 | Change management | Pull requests, pipeline deployment |
The full list of 93 controls is on ISO27K's Annex A guide.
ISO 27017 and 27018
ISO 27017 adds cloud-specific guidance for both providers and customers. ISO 27018 covers protection of personal information in public clouds, mainly for providers acting as processors. A cloud customer rarely needs certification to either. They are useful as extensions of your ISMS if a buyer asks, and you should confirm your provider holds them. ISO27K covers both.
Writing the Statement of Applicability for a cloud estate
For each applicable control, say how it is implemented and where the evidence is. For controls the provider handles, such as physical security controls 7.1 to 7.14, say they are applicable and met through the provider's certification, which you have reviewed. Excluding physical controls entirely because you have no data centre is a common mistake: you still have offices, laptops and a provider whose controls you rely on.
Does my cloud provider's ISO 27001 certificate cover me?
No. It covers the provider's ISMS. Your certification covers yours, which includes how you use the cloud. You rely on the provider's certificate as assurance for the controls it operates.
Is ISO 27001 easier than SOC 2 in the cloud?
The cloud controls are much the same. ISO 27001 adds more management system requirements, such as the risk process, internal audit and management review, and results in a certificate rather than a report. Which one you need depends on who is asking.
Do we need an exit plan for AWS to pass ISO 27001?
Control 5.23 expects you to consider exit. A short documented plan stating how data would be exported, in what format, and how long it would take is enough. Nobody expects a tested migration to another provider.
Getting ISO 27001 on a cloud estate?
Firms in the network build the ISMS and the cloud controls together.
Get matched