Skip to content
arrow_back
verifiedISO/IEC 27001:2022

ISO 27001 Annex A 5.23Cloud Service Security Management

Official control statement

Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.
verifiedISO/IEC 27001:2022Annex A 5.23

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Ensure secure cloud service use with proper procedures for acquisition, management, and exit.

Organisational controlsISO/IEC 27001:2022
Control Stack classificationPreventativeCloud security
record_voice_over

What this means in practice

This control is about making sure that any cloud services your organisation uses are secure. It means setting clear rules and processes for choosing, using, managing, and leaving these services. Without it, sensitive data could be at risk, contracts might be unclear, and exiting a cloud service could become complicated, potentially causing disruptions or data breaches.

Framework

ISO/IEC 27001:2022

Control effect (Control Stack)

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

29 Sept 2026

priority_high

Why it matters

Poorly managed cloud services can lead to data breaches or loss of data access, affecting operational continuity and reputational integrity.

settings

Operational notes

Regularly review cloud security needs and update agreements with providers to manage risks and maintain current service requirements.

build

Implementation tips

  • The IT Manager should develop a cloud service policy. This policy should include security requirements and protocols for cloud service use, and ensure its communication to all employees.
  • The Procurement team should establish criteria for selecting cloud services. They should evaluate potential cloud providers based on these criteria, which could include security standards, compliance with Australian regulations, and service level agreements.
  • The IT Manager should define roles and responsibilities for managing cloud services. Assign specific tasks such as monitoring security controls and handling data migration during the exit.
  • The Risk Management team should perform a risk assessment for potential cloud services. This involves identifying and evaluating risks to confidentiality, integrity, and availability of data on the cloud.
  • The IT Manager should establish procedures for cloud service exit strategies. These should cover data retrieval, service shut down processes, and ensure continuity while maintaining security during the transition.
fact_check

Audit / evidence tips

  • AskAsk for the organisation's cloud service policy document.Look atLook at the specified security requirements and the management processes it defines for cloud services.GoodA good document details the protocols for acquiring, using, managing and exiting cloud services and is well communicated across the organisation.
  • AskAsk to see records of cloud service selection criteria and the decisions made against them.Look atCheck that the criteria reflect the organisation's security and regulatory requirements and that each decision applied them.GoodGood records show thorough evaluations against predefined criteria before a cloud service was acquired.
  • AskRequest documentation of the defined roles and responsibilities for managing cloud services.Look atCheck that roles are clearly assigned and documented, including who oversees each cloud service.GoodA good structure details specific responsibilities and the oversight mechanisms for cloud service use.
  • AskAsk for the latest risk assessment report covering cloud services.Look atLook for the identified risks and the mitigation strategies for data protection in each cloud service.GoodA good report clearly outlines the potential risks and the planned responses to them.
  • AskAsk for the cloud service exit procedures and records of any past service exits.Look atExamine how data was securely retrieved and how the service was discontinued.GoodGood evidence shows a planned, secure and documented approach to exiting cloud services.
link

Cross-framework mappings

How Annex A 5.23 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ASD ISM

ControlNotesDetails
open_in_fullBroader than(1)expand_less
ISM-1437ISM-1437 requires cloud service providers to be used for hosting online services
sync_altPartially overlaps(1)expand_less
ISM-1529ISM-1529 requires that outsourced SECRET and TOP SECRET cloud services are only delivered using community or private cloud deployment models
handshakeSupports(1)expand_less
ISM-1638ISM-1638 requires documenting outsourced cloud services and key governance attributes such as purpose, data classification, contractual a...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Organisational controls controls, or browse the full ISO 27001 library. You can also track all 93 controls with the free ISO 27001 Annex A checklist.

school

Want to implement this control?

Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.

Mapping detail

Mapping

Direction

Controls