Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.23 Information security for use of cloud services
ISO/IEC 27001:2022 Annex A 5.23 Information security for use of cloud services
Processes for buying, using, managing and leaving cloud services are to be set up so that they satisfy what the organization requires for information security. Purpose (stated in ISO/IEC 27002:2022): specifies and manages information security for the organization's use of cloud services.
Steps that cite it
- KC-01 S3 Decide whether cloud service requirements apply
Evidence commonly asked for
- Statement of Applicability entry for control A.5.23, showing inclusion or justified exclusion, implementation status and the risks it treats
- The topic-specific cloud services policy with selection criteria and scope of permitted use
- A shared responsibility matrix per cloud service showing which controls the provider operates and which the organization operates
- Cloud risk assessments with documented management acceptance of residual risk
Accepted citation forms are listed on the answer format page.