ISO/IEC 27000 Information Security for Use of Cloud Services, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information security for use of cloud services.

Assessment Step

1
Information Security for Use of Cloud Services (InformationSecurityforUseofCloudServices)
Has the organization established processes for acquisition, use, management, and exit from cloud services in accordance with its information security requirements?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Information Security for Use of Cloud Services
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.
Citations
27001
Annex A, Control 5.23
27002
Section 5.23