Maintain an Outsourced Cloud Service Register
Keep an up-to-date register of cloud services used, and regularly check it.
Plain language
This control is about keeping a detailed list of all cloud services your organisation uses and checking it regularly. It's important because if you don't know which services you're using, you risk losing track of sensitive data or facing unexpected security issues.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
An outsourced cloud service register is developed, implemented, maintained and regularly verified.
Why it matters
Without this control, your organisation might lose control over cloud services, risking data security issues or financial inefficiencies.
Operational notes
Ensure regular reviews and updates of the cloud service register remain a routine part of the team's tasks to prevent oversight.
Implementation tips
- The office manager or IT lead should create an initial list of all current cloud services being used by your organisation. Start by checking invoices, subscriptions, and current software contracts to identify these services.
- Procurement officers and finance team members should help track new cloud services by noting all new purchases. They can do this by ensuring purchase processes include a step to document any new cloud service in the register.
- The IT team should set a regular schedule to review the cloud service register. They can do this by setting reminders in the company calendar to revisit the list every quarter, making sure to confirm that the list is up to date.
- Department heads should communicate any use of new cloud tools or services to the IT lead. This can be done through a monthly check-in meeting or an internal newsletter update to ensure services are not missed.
- The organisation's executive team should periodically review the cloud service register during board meetings. Regular board discussions on IT systems can increase accountability and ensure resources remain aligned with the organisation's risk profile.
Audit / evidence tips
- Askthe cloud service register: Request the most recent version of the document listing all cloud services the organisation usesLook ata comprehensive list with cloud service names and purposeGoodis a complete list updated within the past three months
- Askto see purchase records for cloud services: Request invoices or contracts related to cloud servicesLook atthe dates and ensure they align with the service register entriesGoodis if each recent purchase has an entry in the register
- Asklogs of any quarterly review meetings for the service register: Request meeting minutes or notesLook atevidence of discussion around changes or updatesGoodshows the register was reviewed as scheduled, with actions noted
- Askcommunication records regarding new cloud service use: Request emails or memos sent to team leadsLook atclear communications about updates or changes to the registerGoodwill show proactive steps in maintaining current records
- AskIT policy documents regarding cloud services: Request the policy guiding cloud service managementLook atsections explicitly covering service tracking and updates to the registerGoodincludes specific guidelines on maintaining the register
Cross-framework mappings
How ISM-1637 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 5.9 | Annex A 5.9 requires an organisation-wide inventory of information and associated assets with ownership | |
handshakeSupports(2)expand_less | ||
| Annex A 5.19 | ISM-1637 requires an organisation to maintain and regularly verify a register of outsourced cloud services | |
| Annex A 5.22 | Annex A 5.22 requires monitoring and review of supplier services and security practices, including managing changes | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Procurement and outsourcing
See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.