A.5.23 Information security for use of cloud services
Govern acquisition, use, management and exit of cloud services against your security requirements.
16
artefacts
5
held by a system
4
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Service level agreement detailing security metrics · Vendor register / contract repository
- Contractual change management log · SIEM / log platform
- Cloud security monitoring logs · SIEM / log platform
- Configuration baseline reports · SIEM / log platform
- Records of data export verification · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Risk assessment report for the selected cloud service · Cloud console / configuration management
- Signed cloud service agreement with security clauses · Vendor register / contract repository
- Access control review records · Identity provider / directory
- Exit audit report · Cloud console / configuration management
governing documentDocuments that govern the control
- Cloud service provider evaluation matrix · Policy repository / GRC workspace
- Business case including security requirements · Policy repository / GRC workspace
- Approved cloud service selection checklist · Policy repository / GRC workspace
- Data processing addendum · Vendor register / contract repository
- Incident response reports for cloud-related incidents · Policy repository / GRC workspace
- Cloud service termination checklist · HR system / LMS
- Data migration and destruction plan · Policy repository / GRC workspace
First move
Start with the 5 of 16 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Relying solely on provider's security assurances
- No documented exit or data migration procedures
- Insufficient risk assessment before cloud onboarding
- Contracts missing specific security and audit clauses
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.22 Monitoring, review and change management of supplier services · A.5.24 Information security incident management planning and preparation