Who uses it
It suits cloud service providers and organisations moving their systems to the cloud.
How it is applied
- Cloud services in use are listed with their providers.
- Shared responsibilities between customer and provider are set out.
- Controls for access, encryption and logging are put in place.
- Provider contracts and assurance reports are reviewed.
Cost drivers
The number of cloud services and providers drives the cost. Contract reviews and security tooling add to it.
Timeline
A first programme usually runs over several months. The work then continues as systems and threats change.
Certification
These guides extend ISO/IEC 27001 and ISO/IEC 27002. Some certification bodies assess them as part of an ISO/IEC 27001 audit.


