CloudCompliance

ISO 27001 in the cloud

ISO 27001 does not care which cloud you use. It cares that you chose it deliberately, manage it as a supplier, and can show the Annex A controls you apply to it. Control 5.23 is where that is written down.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

For ISO 27001:2022 in the cloud, three things matter beyond the usual ISMS work. Control 5.23 requires a documented process for acquiring, using, managing and exiting cloud services. Your Statement of Applicability must say how each relevant Annex A control is implemented in the cloud and what you inherit from the provider. And the certification body will test the technical controls in your cloud account much as a SOC 2 auditor would.

Control 5.23: information security for use of cloud services

Added in the 2022 revision. It expects:

  • Criteria for selecting cloud services and assessing their security.
  • A clear split of responsibilities between you and each provider, as in the shared responsibility model.
  • How you obtain assurance from the provider: its ISO certificates and SOC 2 reports.
  • How you manage changes the provider makes.
  • An exit strategy: how you would retrieve data and move if you had to.

This applies to your IaaS provider and to every SaaS tool holding information in scope, so the record is a list, not a paragraph.

Annex A controls your cloud answers

ISO 27001:2022 Annex A controls with heavy cloud implementation
ControlTitleCloud implementation
5.15, 5.18Access control, access rightsFederated identity, role design, access reviews
5.23Cloud servicesProvider selection, responsibility matrix, exit plan
8.2Privileged access rightsJust-in-time admin, break-glass accounts
8.5Secure authenticationMFA through the identity provider
8.9Configuration managementInfrastructure as code, policy baselines, configuration monitoring
8.13Information backupBackup plans, immutability, restore tests
8.15, 8.16Logging, monitoring activitiesAudit logs, retention, alerting
8.20, 8.22Network security, segregationAccount boundaries, private subnets, security groups
8.24Use of cryptographyEncryption at rest and in transit, key management
8.8Technical vulnerabilitiesNative scanners, remediation targets
8.32Change managementPull requests, pipeline deployment

The full list of 93 controls is on ISO27K's Annex A guide.

ISO 27017 and 27018

ISO 27017 adds cloud-specific guidance for both providers and customers. ISO 27018 covers protection of personal information in public clouds, mainly for providers acting as processors. A cloud customer rarely needs certification to either. They are useful as extensions of your ISMS if a buyer asks, and you should confirm your provider holds them. ISO27K covers both.

Writing the Statement of Applicability for a cloud estate

For each applicable control, say how it is implemented and where the evidence is. For controls the provider handles, such as physical security controls 7.1 to 7.14, say they are applicable and met through the provider's certification, which you have reviewed. Excluding physical controls entirely because you have no data centre is a common mistake: you still have offices, laptops and a provider whose controls you rely on.

Does my cloud provider's ISO 27001 certificate cover me?

No. It covers the provider's ISMS. Your certification covers yours, which includes how you use the cloud. You rely on the provider's certificate as assurance for the controls it operates.

Is ISO 27001 easier than SOC 2 in the cloud?

The cloud controls are much the same. ISO 27001 adds more management system requirements, such as the risk process, internal audit and management review, and results in a certificate rather than a report. Which one you need depends on who is asking.

Do we need an exit plan for AWS to pass ISO 27001?

Control 5.23 expects you to consider exit. A short documented plan stating how data would be exported, in what format, and how long it would take is enough. Nobody expects a tested migration to another provider.

Getting ISO 27001 on a cloud estate?

Firms in the network build the ISMS and the cloud controls together.

Get matched