ISO 27001 Annex A 5.23 Information security for use of cloud services establishes security controls for buying, using, and exiting cloud solutions. Documented rules ensure organizations manage shared cloud risks, protect sensitive data, and maintain clear provider oversight.
Table of contents
Key Takeaways
- Manage cloud service lifecycles: Define clear processes for selecting, onboarding, running, and terminating external cloud solutions.
- Store rules centrally: Keep cloud security policies, risk assessments, and vendor contracts in a central document repository.
- Define shared responsibilities: Clarify which security duties belong to your team and which belong to the cloud service provider.
- Assess provider risks: Review third-party compliance certificates and security controls before purchasing any cloud services.
- Enforce strong access controls: Require multi-factor authentication and role-based permissions for all cloud service accounts.
- Protect data in the cloud: Enforce strong encryption for all business data stored in cloud tools and sent across public networks.
- Plan cloud exit strategies: Document exit steps and data return terms to ensure smooth migration if you leave a provider.
- Monitor cloud activity: Track user logins, administrative changes, and service health to spot unusual cloud behaviour fast.
How to Implement ISO 27001 Annex A 5.23
- Draft a cloud security policy: Write clear guidelines for using cloud platforms and store them in your central document repository.
- Maintain a central cloud register: Build an inventory listing all approved cloud solutions, business owners, and data sensitivity levels.
- Document shared responsibility models: Map out customer versus vendor security tasks for every software, platform, and infrastructure service.
- Review vendor security credentials: Inspect independent audit reports and security certifications before signing contracts with cloud providers.
- Mandate multi-factor authentication: Enforce two-step login checks for all staff and administrators accessing cloud business systems.
- Enforce cloud data encryption: Turn on default encryption for data at rest in cloud storage and in transit across networks.
- Create cloud exit plans: Document clear procedures to export data, remove accounts, and verify secure deletion upon contract end.
- Train staff on cloud security: Teach workers how to share files safely and warn against using unapproved shadow cloud tools.
- Review cloud configurations regularly: Run automated checks and periodic reviews to prevent misconfigured storage and open permissions.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.23
- Review cloud security policies: Inspect written procedures to verify clear rules exist for buying, configuring, and exiting cloud services.
- Audit the cloud service register: Sample entries in the cloud inventory to ensure all active solutions match recorded business approvals.
- Verify shared responsibility matrices: Check that teams clearly understand and manage their specific configuration duties for each cloud tool.
- Inspect provider audit reports: Verify that valid third-party security certificates and compliance proofs exist for key cloud providers.
- Test cloud access controls: Inspect administrator accounts to verify that multi-factor authentication and role limits are actively enforced.
- Verify cloud encryption settings: Check sample cloud storage resources to ensure data encryption remains turned on and correctly configured.
- Review cloud exit documentation: Inspect documented exit strategies to confirm data retrieval and secure deletion terms are defined.
- Check cloud monitoring logs: Confirm that teams review access logs and security alerts from cloud environments on a set schedule.
Audit Evidence Checklist
- Cloud security policy: Maintain a documented cloud usage policy with complete version history in your central document repository.
- Central cloud asset register: Supply an up-to-date inventory list of all approved cloud services, account owners, and data classes.
- Shared responsibility matrices: Provide documented charts outlining internal versus provider security tasks for active cloud systems.
- Provider assurance records: Maintain current third-party audit reports and compliance certificates from active cloud vendors.
- Cloud configuration review logs: Supply audit records from periodic reviews checking for cloud storage and access misconfigurations.
- Documented cloud exit plans: Provide formal exit procedures detailing data extraction and account termination steps for core services.
- Staff training logs: Show sign-off sheets proving workers completed security awareness training on safe cloud tool usage.
What to Teach Employees
- Use only approved cloud tools: Warn staff against adopting unvetted software or uploading work files to personal cloud storage.
- Set restrictive sharing links: Teach workers to share files with specific users only and avoid creating public or anonymous links.
- Protect login credentials: Instruct employees to use strong passwords and keep multi-factor authentication active on cloud accounts.
- Classify data before uploading: Remind staff to check data classification rules before placing sensitive records in cloud services.
- Report suspicious cloud alerts: Ensure workers know to flag unexpected password reset emails or unusual cloud file sync activity fast.
- Revoke old sharing permissions: Train staff to remove external access permissions once client projects or team tasks finish.
Common Implementation Challenges
- Shadow IT proliferation: Teams sign up for unapproved cloud tools on company cards. Enforce procurement checks and discovery scans.
- Misconfigured cloud storage: Storage repositories get created with public read access. Use automated policy guardrails to block public settings.
- Assuming vendors do everything: Teams forget their configuration duties. Define clear shared responsibility models for all cloud tools.
- Vendor lock-in without exit plans: Moving away from providers proves difficult later. Document data extraction formats before signing contracts.
- Overprivileged cloud accounts: Too many users hold broad administrative rights. Apply the principle of least privilege across all portals.
- Untracked cloud spending: Orphaned test services run indefinitely and expose systems. Audit active cloud resources and subscriptions monthly.
How to Measure Effectiveness (KPIs)
- MFA adoption rate: Measure the percentage of cloud service user accounts enforcing mandatory multi-factor authentication.
- Cloud register accuracy rate: Track the proportion of active cloud tools matching central tracking records during quarterly reviews.
- Misconfiguration remediation speed: Measure the average time taken to fix open or insecure cloud configuration settings.
- Provider assessment compliance: Track the percentage of active cloud vendors with valid security certificates on file.
- Unapproved cloud service count: Monitor the number of unauthorized shadow cloud services detected and closed each quarter.
- Cloud security audit finding count: Monitor the number of security gaps raised against cloud services during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.23 connects to several other ISO 27001 requirements:
Annex A 5.23 depends on Clause 5.19 for general supplier relationship rules. It supports Clause 5.20 regarding security within supplier agreements. This control also feeds into Clause 5.22 for supplier service monitoring. Together: these controls form a robust third-party risk framework. Each link must be documented in your internal wiki.

