ISO27001:2022 – A5.23 Information Security for use of Cloud Services

Introduction to ISO 27001 – A5.23

ISO 27001 – A5.23 is one of the new controls in ISO27001:2022, and it emphasises the growing reliance organisations have on cloud-based services. Alongside Annex A5.19 to A5.22, it reinforces the need for robust supplier management — especially in the cloud.

What does ISO 27001 – A5.23 require?

The standard states:

“Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organisation’s information security requirements.” (ISO 27001 – A5.23)

Why is this required?

Almost every business today uses cloud services — from simple file storage to enterprise-level CRM, finance, and HR platforms. Cloud services offer convenience and scalability, but also introduce risk. Remember: the cloud is just someone else’s computer.

This control is designed to ensure that cloud service providers are assessed, selected, and managed in line with your information security needs.

For example, a cloud hosting provider may advertise “secure hosting,” but unless you evaluate their security (physical, logical, and procedural), you could be exposing your business to serious risks — like the case of a small hosting company with no access control, no air conditioning, and no security protocols in place.

What the auditor is looking for

The auditor won’t look for a standalone cloud policy, but they will expect to see:

  • A central supplier register (from A5.19) that includes all cloud service providers
  • Evidence of due diligence and security evaluation of cloud services
  • Monitoring and reviewing of cloud service performance and compliance (see A5.22)
  • A defined process for exiting or transitioning from one cloud provider to another

What do you need to do?

Go beyond just cloud storage providers like Google, Microsoft, or AWS. Identify departmental cloud apps across your organisation. For example:

  • Finance – Xero, Sage, QuickBooks, Zoho Books
  • HR – Personio, PeopleHR, BreathHR
  • Sales/CRM – Salesforce, HubSpot, Zoho, Zendesk
  • Marketing – Mailchimp, HubSpot, ActiveCampaign

This is not an exhaustive list by any imagine, and is only touching on the most obvious Cloud service providers. For example, your IT function may also be using a ticketing system (like Zendesk), or time management and network monitoring Cloud services (e.g. Workday, and NetApp).

 

Your auditor will expect to see evidence that there is some form of due diligence carried out on your Cloud providers, which should include an evaluation of their security capabilities.  They will expect to see monitoring and reviewing of your Cloud service providers (see A5.22 for more information), and they will expect to see a process for moving Cloud providers (if this is required).

 

If you have implemented a robust Supplier Management process, then this shouldn’t be difficult to evidence. We firmly believe that the purpose of this control is to elevate the need to evaluate all Cloud service providers (as described above). Therefore don’t neglect to speak to your departments about the different software packages they use, as they may not even consider these as Cloud providers (which they clearly are).

You should:

  • Document these services in your supplier register
  • Conduct a basic security review for each provider
  • Evaluate their published security capabilities
  • Define a change or exit process for cloud services

Q & A

Do I need to evaluate Google, Dropbox, Microsoft and Amazon?

In a word, yes.  They are Cloud providers, and you should still evaluate the use of them. The acquisition process should include an evaluation of their security capabilities, which can easily be completed by searching online for information about their security. Simply type “Security overview for Amazon AWS” and you’ll be presented a whole host of documents which will outline the positive security capabilities of Amazon AWS. You could also evaluate it by comparing it to another provider by searching for “Security for Microsoft Azure vs Amazon AWS” . You can then make an informed decision on which Cloud service is best for you.

 

All these platforms also offer dashboards which allow you to monitor and review their services, and should you wish to change the service then this should be discussed and a project planned developed which shows how you will carry it out.

Is the cloud secure?

That’s a big question, and deserves a whole blog of its own. But in short; Yes, the Cloud is secure because companies like Microsoft and Amazon spends billions on making sure the environment is secure. However the way we use Cloud is less secure. Think of it this way; Are banks secure? Yes, generally speaking they are. But bank accounts are still plundered on a daily basis! How? It’s the way they are accessed.. It’s people who don’t know how to protect their accounts. It’s technology that is not secured with malware protection etc.

 

So yes, the Cloud is secure, but the way we access it isn’t.

Difficulty rating

We rate this a 2 out of 5 difficulty rating. This means that it requires a little technical skill to understand the requirement. This is because you will need to evaluate the security capabilities of several providers, and some make it quite difficult to understand. Not because they purposely do this, but because they have so many options available, it becomes difficult to know what you need. This is where you need to work with your IT function, and others in the business, to evaluate what is right for you and what you need.

 

This is where your Management Review Team (MRT) are most useful as they can help you make an informed and fully round decision.

 

More questions?

Remember that nothing in ISO27001 sits in isolation, so you should review our FAQ to gain answers to other aspects of the standard. Follow the links in this control to see the relationship in other controls, but if you’re still confused about this control, then please get in touch.

 

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001which is available on Amazon. 

ISO 27001 – A5.23