A.5.23
    Organizational Controls

    Information security for use of cloud services

    Processes for acquisition, use, management and exit from cloud services should be established in accordance with the organization's information security requirements.

    Purpose

    To ensure cloud services meet the organization's information security requirements.

    Implementation Guidance

    Assess security controls of cloud service providers

    Understand the shared responsibility model

    Ensure data location and sovereignty requirements are met

    Implement strong authentication and access controls for cloud services

    Plan for data extraction and service exit

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.23 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.23 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.23 Information security for use of cloud services. Built for compliance professionals.

    Try ISMS Copilot free