ISO 27001 Annex A 5.23Cloud Service Security Management
Official control statement
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Ensure secure cloud service use with proper procedures for acquisition, management, and exit.
What this means in practice
This control is about making sure that any cloud services your organisation uses are secure. It means setting clear rules and processes for choosing, using, managing, and leaving these services. Without it, sensitive data could be at risk, contracts might be unclear, and exiting a cloud service could become complicated, potentially causing disruptions or data breaches.
Framework
ISO/IEC 27001:2022
Control effect (Control Stack)
Preventative
ISO 27001 domain
Organisational controls
Classifications
N/A
Official last update
24 Oct 2022
Control Stack last updated
29 Sept 2026
Why it matters
Poorly managed cloud services can lead to data breaches or loss of data access, affecting operational continuity and reputational integrity.
Operational notes
Regularly review cloud security needs and update agreements with providers to manage risks and maintain current service requirements.
Implementation tips
- The IT Manager should develop a cloud service policy. This policy should include security requirements and protocols for cloud service use, and ensure its communication to all employees.
- The Procurement team should establish criteria for selecting cloud services. They should evaluate potential cloud providers based on these criteria, which could include security standards, compliance with Australian regulations, and service level agreements.
- The IT Manager should define roles and responsibilities for managing cloud services. Assign specific tasks such as monitoring security controls and handling data migration during the exit.
- The Risk Management team should perform a risk assessment for potential cloud services. This involves identifying and evaluating risks to confidentiality, integrity, and availability of data on the cloud.
- The IT Manager should establish procedures for cloud service exit strategies. These should cover data retrieval, service shut down processes, and ensure continuity while maintaining security during the transition.
Audit / evidence tips
- AskAsk for the organisation's cloud service policy document.Look atLook at the specified security requirements and the management processes it defines for cloud services.GoodA good document details the protocols for acquiring, using, managing and exiting cloud services and is well communicated across the organisation.
- AskAsk to see records of cloud service selection criteria and the decisions made against them.Look atCheck that the criteria reflect the organisation's security and regulatory requirements and that each decision applied them.GoodGood records show thorough evaluations against predefined criteria before a cloud service was acquired.
- AskRequest documentation of the defined roles and responsibilities for managing cloud services.Look atCheck that roles are clearly assigned and documented, including who oversees each cloud service.GoodA good structure details specific responsibilities and the oversight mechanisms for cloud service use.
- AskAsk for the latest risk assessment report covering cloud services.Look atLook for the identified risks and the mitigation strategies for data protection in each cloud service.GoodA good report clearly outlines the potential risks and the planned responses to them.
- AskAsk for the cloud service exit procedures and records of any past service exits.Look atExamine how data was securely retrieved and how the service was discontinued.GoodGood evidence shows a planned, secure and documented approach to exiting cloud services.
Cross-framework mappings
How Annex A 5.23 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ASD ISM
| Control | Notes | Details |
|---|---|---|
open_in_fullBroader than(1)expand_less | ||
| ISM-1437 | ISM-1437 requires cloud service providers to be used for hosting online services | |
sync_altPartially overlaps(1)expand_less | ||
| ISM-1529 | ISM-1529 requires that outsourced SECRET and TOP SECRET cloud services are only delivered using community or private cloud deployment models | |
handshakeSupports(1)expand_less | ||
| ISM-1638 | ISM-1638 requires documenting outsourced cloud services and key governance attributes such as purpose, data classification, contractual a... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ISO 27001 controls in Organisational controls
See all Organisational controls controls, or browse the full ISO 27001 library. You can also track all 93 controls with the free ISO 27001 Annex A checklist.
Want to implement this control?
Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.