ISO/IEC 27001:2022 Annex A · Control 5.23
Information Security for Use of Cloud Services: A Practical Implementation Guide
Govern cloud acquisition, configuration, operation and exit with clear shared responsibilities.
This control addresses processes for acquiring, using, managing and exiting cloud services in accordance with information security requirements.
What should the control achieve?
- Cloud use follows approved acquisition and risk processes.
- Shared responsibilities are documented.
- Configuration and activity are monitored.
- Exit, portability and deletion are planned.
Step-by-step implementation
Discover cloud use
Inventory sanctioned and unsanctioned services, owners, data and integrations.
Classify and assess
Evaluate service model, data, locations, resilience, provider assurance and lock-in.
Define shared responsibility
Map provider, customer and subprocessor obligations control by control.
Establish secure baselines
Configure identity, logging, encryption, network, backup and administrative controls.
Monitor continuously
Review posture, activity, incidents, provider changes and cost anomalies.
Plan exit
Test data export, dependency removal, account closure and deletion evidence.
What this could look like in practice
A company approves cloud services through architecture and security review. Each service has an owner and configuration baseline. Central identity and logging are mandatory, posture findings create tickets and annual exit tests confirm data can be exported.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Acquisition | Risk and architecture review precede contract. | Approval record |
| Configuration | Baseline is deployed and drift monitored. | Posture report |
| Operation | Logs feed central monitoring and incidents follow shared playbooks. | Log and incident evidence |
| Exit | Data export and deletion are tested. | Exit test |
Implementation evidence
- Cloud policy
- Cloud inventory
- Risk assessments
- Shared-responsibility matrix
- Configuration baselines
- Posture reports
- Provider assurance
- Exit plan and tests
Useful metrics
- Cloud services with owners
- Critical configuration findings
- Unsanctioned services discovered
- Services with tested exit plans
Common mistakes
- Assuming the provider secures customer configurations.
- No inventory of team-purchased services.
- Using provider defaults without review.
- Failing to centralize identity and logs.
- Discovering lock-in only during exit.
Questions an auditor may ask
- How are cloud services approved?
- Show shared responsibilities for one service.
- How is configuration drift detected?
- How would you exit and verify deletion?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.