Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.23

Information Security for Use of Cloud Services: A Practical Implementation Guide

Govern cloud acquisition, configuration, operation and exit with clear shared responsibilities.

This control addresses processes for acquiring, using, managing and exiting cloud services in accordance with information security requirements.

Practical interpretation: Cloud risk is not solved by provider certification. The customer retains responsibilities for configuration, identities, data, monitoring and service selection.

What should the control achieve?

  • Cloud use follows approved acquisition and risk processes.
  • Shared responsibilities are documented.
  • Configuration and activity are monitored.
  • Exit, portability and deletion are planned.

Step-by-step implementation

1

Discover cloud use

Inventory sanctioned and unsanctioned services, owners, data and integrations.

2

Classify and assess

Evaluate service model, data, locations, resilience, provider assurance and lock-in.

3

Define shared responsibility

Map provider, customer and subprocessor obligations control by control.

4

Establish secure baselines

Configure identity, logging, encryption, network, backup and administrative controls.

5

Monitor continuously

Review posture, activity, incidents, provider changes and cost anomalies.

6

Plan exit

Test data export, dependency removal, account closure and deletion evidence.

What this could look like in practice

A company approves cloud services through architecture and security review. Each service has an owner and configuration baseline. Central identity and logging are mandatory, posture findings create tickets and annual exit tests confirm data can be exported.

ActivityPractical implementationEvidence
AcquisitionRisk and architecture review precede contract.Approval record
ConfigurationBaseline is deployed and drift monitored.Posture report
OperationLogs feed central monitoring and incidents follow shared playbooks.Log and incident evidence
ExitData export and deletion are tested.Exit test

Implementation evidence

  • Cloud policy
  • Cloud inventory
  • Risk assessments
  • Shared-responsibility matrix
  • Configuration baselines
  • Posture reports
  • Provider assurance
  • Exit plan and tests

Useful metrics

  • Cloud services with owners
  • Critical configuration findings
  • Unsanctioned services discovered
  • Services with tested exit plans

Common mistakes

  • Assuming the provider secures customer configurations.
  • No inventory of team-purchased services.
  • Using provider defaults without review.
  • Failing to centralize identity and logs.
  • Discovering lock-in only during exit.

Questions an auditor may ask

  • How are cloud services approved?
  • Show shared responsibilities for one service.
  • How is configuration drift detected?
  • How would you exit and verify deletion?
Implementation test: Choose one critical cloud service and trace acquisition, data, configuration, monitoring, incident duties and exit.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.