ISO 27001:2022 Annex A 5.23 Information Security for Use of Cloud Services Explained

In this guide you will learn how to implement ISO 27001 Annex A 5.23 Information security for use of cloud services and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.23 is an ISO 27001 control that requires an organisation to specify and manage information security for the use of cloud services.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.23 is a preventive control that ensures you specify and manage information security for the use of cloud services.

The ISO 27001 standard defines ISO 27001 Annex A 5.23 as:

Processes for acquisition, use, management and exit from cloud services should be established in accordance with the organisation’s information security requirements.

ISO/IEC 27001:2022 Annex A 5.23 Information Security For Use Of Cloud Services

FREE ISO 27001 Annex A 5.23 Training Video

In this free training video you will learn How to implement ISO 27001 Information Security Of Cloud Services (Annex A 5.23) & Pass Your Audit.

Implementation Guide

Cloud services can be treated to all intents and purposes like any supplier. The standard calls them out, because, in some ways it feels like they felt they had to. It gives a list of requirements that are unrealistic and then acknowledges it is unlikely you can meet them.

Before we look at what you can do let us paraphrase what the standard thinks as the get out.

It absolutely acknowledges that yes, cloud service agreements are pre defined and not open to negotiation on the whole. So why give a list of requirements? Who knows. This is about basic good practice of supplier management. They could have said that. But they did not.

You will ensure

ISO 27001 Cloud Security Policy Template

The cloud services security policy sets out your approach to cloud supplier security.

ISO 27001 Cloud Security Policy Template - ISO 27001 Annex A 5.23 Information Security for Use of Cloud Services Template
Cloud Security Policy Template

How to write a Cloud Security Policy

For a deeper understanding of the ISO 27001 Cloud Security Policy see the ultimate guide: Cloud Security Policy: Ultimate Guide (+ template)

ISO 27001 Cloud Security Policy

How to implement ISO 27001 Annex A 5.23

Implementing ISO 27001 Annex A 5.23 requires a strategic shift from managing physical infrastructure to governing virtualised environments and shared responsibility models. As a Lead Auditor, I look for evidence that you have defined clear security requirements for your cloud providers and that those requirements are consistently monitored throughout the service lifecycle. Follow these ten steps to secure your use of cloud services and satisfy the requirements of the 2022 standard update.

1. Establish a Cloud Security Policy

  • Define the organisational rules for the acquisition, use, and management of cloud services to ensure a consistent security posture.
  • Specify the types of data permitted in different cloud environments, such as Public, Private, or Hybrid, based on data classification levels.
  • Document the roles and responsibilities for both the organisation and the cloud service provider within a formal policy framework.

2. Build a Comprehensive Cloud Asset Register

  • Identify and record every SaaS, PaaS, and IaaS solution used across the business to eliminate “Shadow IT” risks.
  • Link each cloud service to an internal Service Owner who is accountable for the security and performance of that specific platform.
  • Include technical metadata such as data residency locations, primary IAM administrators, and the criticality of the service to business operations.

3. Conduct Pre-Onboarding Security Risk Assessments

  • Evaluate the security capabilities of prospective cloud providers against organisational requirements before any contracts are signed.
  • Review independent assurance reports, such as SOC 2 Type II or ISO 27001 certificates, to verify the provider’s claims of security effectiveness.
  • Identify potential security gaps in the provider’s infrastructure and document how these will be mitigated through internal controls.

4. Formalise Cloud Service Agreements

  • Provision specific information security requirements into contractual agreements to ensure the provider is legally bound to your standards.
  • Include clauses regarding data breach notification timelines, the “Right to Audit”, and the return or destruction of data upon termination.
  • Ensure the shared responsibility model is explicitly documented, defining exactly where the provider’s security duties end and yours begin.

5. Provision Identity and Access Management (IAM) Roles

  • Configure granular IAM roles based on the principle of least privilege to ensure users only access the specific resources required for their job.
  • Enforce Multi-Factor Authentication (MFA) for all administrative and privileged accounts to prevent unauthorised access to cloud consoles.
  • Review access logs and user permissions quarterly to identify and revoke dormant or over-privileged accounts.

6. Enforce Data Encryption and Protection

  • Authorise the use of industry-standard encryption protocols for data at rest and data in transit within the cloud environment.
  • Establish secure key management procedures, ensuring that the organisation maintains control over encryption keys where technically feasible.
  • Verify that cloud-native backup solutions are configured and tested periodically to ensure data availability and resilience.

7. Implement Cloud Monitoring and Alerting

  • Set up automated monitoring for security-relevant events, such as changes to firewall rules, bucket permissions, or administrative logins.
  • Ingest cloud audit logs into a central Security Information and Event Management (SIEM) tool for real-time analysis and alerting.
  • Define technical thresholds for security alerts to ensure the incident response team is notified of potential threats immediately.

8. Authorise Cloud Service Change Management

  • Formalise a process to monitor and assess changes made by the cloud provider, such as updates to their software or changes in data hosting locations.
  • Evaluate the impact of provider-side changes on your existing security controls and update your internal configurations accordingly.
  • Document any significant changes in your internal Change Management system to maintain a clear audit trail of the cloud environment’s evolution.

9. Standardise Joint Incident Response Procedures

  • Establish clear communication channels and Rules of Engagement (ROE) for managing security incidents that involve the cloud provider’s infrastructure.
  • Identify the specific technical triggers that require the provider to notify you of a potential compromise.
  • Integrate cloud-specific recovery steps into your Business Continuity and Disaster Recovery (BCDR) plans to ensure rapid restoration of services.

10. Validate Cloud Exit and Transition Plans

  • Develop a formal exit strategy for critical cloud services to prevent vendor lock-in and ensure business continuity during provider failure.
  • Define the technical requirements for data portability, ensuring that data can be extracted and migrated to an alternative provider securely.
  • Verify that the provider issues a certificate of destruction for organisational data once the contract has been terminated and the transition is complete.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

How to comply

To comply with ISO 27001 Annex A 5.23 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to include Cloud Services in supplier management and:

  • Implement a topic specific policy
  • Implement a supplier management process
  • Include in your supplier management process supplier acquisition and supplier transfer
  • Implement an ISO 27001 supplier register
  • Have agreements with all suppliers that cover information security requirements
  • Have information security assurances for critical suppliers as a minimum and ideally all relevant suppliers
  • Monitor those suppliers
  • Respond to adverse incidents in a structured way

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.23 Information Security for Use of Cloud Services Templates
ISO 27001 Templates

How to pass the audit

To pass an audit of ISO 27001 Annex A 5.23 Information security for use of cloud services you are going to make sure that you have supplier management that also covers cloud services and that you have followed the steps above in how to comply.

What the auditor will check

The audit is going to check a number of areas. Lets go through the most common

1. That you have a cloud supplier agreements in place

The auditor is going to check that you have agreements in place with cloud suppliers that cover the information security requirements. It will check that those agreements are in date and cover the products and / or services acquired.

2. That you have an ISO 27001 Cloud Supplier Register

You will need an ISO 27001 Supplier Register to record and manage your cloud suppliers. Make sure it is up to date and reflects your reality.

3. Documentation

They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.

Top 3 Mistakes People Make and How to Avoid Them

The top 3 Mistakes People Make For ISO 27001 Annex A 5.23 are

1. You have do not monitor cloud suppliers

Make sure that there are reviews and monitors in place. Perhaps meetings. Perhaps reports. Perhaps dashboards. Be sure to be able to evidence that you review and monitor those suppliers. You will have processes for adverse advents so do not be surprised if you are asked to evidence an adverse event, problem or issue and that you followed your process.

2. You have no assurance they are doing the right thing for information security

Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO 27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have acquired and are using form the supplier.

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

ISO 27001 Annex A 5.23 FAQ

What are the mandatory requirements for cloud security in ISO 27001?

To comply with Annex A 5.23, organisations must formalise security requirements within their contracts and maintain a “Topic-Specific Policy on Cloud Services.”
Perform a risk assessment on every cloud service provider (CSP).
Define and agree upon the Shared Responsibility Model.
Implement monitoring for service changes or security incidents within the cloud.
Establish technical requirements for data residency and encryption.

How does the Shared Responsibility Model affect ISO 27001?

The Shared Responsibility Model is the framework that defines which security controls are managed by the cloud provider (e.g., physical security) and which are the responsibility of the organisation (e.g., IAM).
Provider: Responsible for the security of the cloud (Infrastructure, Hardware).
Customer: Responsible for security in the cloud (Data, Identity, Configurations).
Audit Requirement: You must document this split to prove you aren’t neglecting “customer-side” configurations.

What should be included in a Cloud Service Agreement (CSA)?

A Cloud Service Agreement must explicitly state security obligations, right-to-audit clauses, and data handling requirements to meet ISO 27001 standards.
Service Level Agreements (SLAs) for availability and performance.
Specific incident notification timeframes in the event of a breach.
Transparency regarding sub-contractors and secondary processors.
Security measures for data at rest and data in transit.

Is a cloud service exit strategy required for ISO 27001?

Yes, Annex A 5.23 requires organisations to have a formalised exit strategy to ensure data can be migrated or deleted securely when a service is terminated.
Definition of data portability and transfer formats.
Verification processes for the secure deletion of data from provider systems.
Business continuity planning for service transition.
Return of intellectual property and assets.

How do you monitor cloud service providers for compliance?

Monitoring is achieved through regular reviews of provider audit reports (such as SOC 2 or ISO 27001 certificates) and continuous tracking of service changes.
Annual review of the provider’s independent security certifications.
Monitoring for changes in data hosting locations or jurisdictions.
Tracking of administrative access and privileged user logs.
Reviewing vulnerability disclosure reports from the provider.

Does ISO 27001 apply to AWS, Azure, and Google Cloud?

Yes, while major providers like AWS and Azure are ISO 27001 certified, your organisation is still responsible for securing the specific configurations and data you host on their platforms.
Infrastructure is covered by the provider’s certification.
Virtual network, OS hardening, and app security are your responsibility.
Auditors will check your “Security Groups” and “IAM Roles” regardless of the provider’s status.

ISO 27001 Cloud Security Policy: Explained + Template

ISO 27001 Controls and Attribute Values

Control typeInformation security propertiesOperational capabilitiesSecurity domains
PreventiveConfidentialitySupplier relationships securityProtection
IntegrityGovernance and ecosystem
Availability

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top