ISO 27002:2022. 5.23 Information security for use of cloud services  

ISO 27002:2022 introduces several new information security controls including A5.23 – Information security for use of cloud services. 

This blog takes a brief look at what is required.

Information security for use of cloud services in ISO 27002:2022

The new control id 5.23 – Information security for use of cloud services has been added to ISO/IEC 27002:2022 to specify and manage information security for the use of cloud services.

The control is regarding the processes for acquisition, use, management and exit from cloud services, which should be established in accordance with the organisation’s information security requirements.

The new control gives guidance for the organisation on how to establish and communicate a policy on the use of cloud services to all relevant interested parties, and the organisation should also define and communicate how it intends to manage information security risks associated with the use of cloud services.

The use of cloud services can involve shared responsibility for information security and collaborative effort between the cloud service provider and the organisation acting as the cloud service customer. It is essential that the responsibilities for both the cloud service provider and the organisation, acting as the cloud service customer, are defined, and implemented appropriately.

Cloud service agreements are often pre-defined and not open to negotiation. For all cloud services, the organisation should review cloud service agreements with the cloud service provider(s).

How to Evidence A5.23 of ISO 27002:2022

Organisations can evidence control A5.23 in several ways, including:

  • An agreement between the cloud service provider and the organisation. Which includes:
  1. Which information security controls are managed by the cloud service provider, and which are managed by the organisation as the cloud service customer.
  2. Roles and responsibilities related to the use and management of cloud services.
  3. How to change or stop the use of cloud services including exit strategies for cloud services.

Implement A5.23 – Information security for use of cloud services. 

If you need assistance with control A5.23, Assent’s ISO 27002 Consultants can help.Contact us to discuss how we can help with this ISO 27002 Control and the ISO 27001 Information Security Management System in general.