Skip to content
arrow_back
search
Annex A 5.23 verified ISO/IEC 27001:2022

Cloud Service Security Management

Ensure secure cloud service use with proper procedures for acquisition, management, and exit.

record_voice_over

Plain language

This control is about making sure that any cloud services your organisation uses are secure. It means setting clear rules and processes for choosing, using, managing, and leaving these services. Without it, sensitive data could be at risk, contracts might be unclear, and exiting a cloud service could become complicated, potentially causing disruptions or data breaches.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

30 Mar 2026

Maturity levels

N/A

Official control statement

Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization''s information security requirements.
verified ISO/IEC 27001:2022 Annex A 5.23
priority_high

Why it matters

Poorly managed cloud services can lead to data breaches or loss of data access, affecting operational continuity and reputational integrity.

settings

Operational notes

Regularly review cloud security needs and update agreements with providers to manage risks and maintain current service requirements.

Mapping detail

Mapping

Direction

Controls