Subject
Cloud technologies and related services combines the infrastructure, platforms, or software that are hosted by third-party providers and made available to users through the internet.
Cloud services facilitate the flow of user data from front-end clients (e.g., users’ servers, tablets, desktops, laptops—anything on the users’ ends), through the internet, to the provider’s systems, and back.
Cloud services promote the building of cloud-native applications and the flexibility of working in the cloud. Users can access cloud services with nothing more than a computer, operating system, and internet connectivity.
Cloud technologies has become an integral part of the current business processes as it offers flexibility, scalability, and a cost-cutting advantage. However, although the promises to businesses from the adoption of the technology are diversified, tremendous security risks of cloud computing accompany them. In the process of transitioning to the cloud, many organizations fail to address essential security requirements that can compromise their cloud-based systems. About 45% of information security incidents are reported to have originated from cloud environments, which calls for enhanced security measures. This shift, therefore, requires organizations to adopt proactive security measures, including security audits, security awareness for employees, and advanced threat identification systems.
Applied standards
ISO/IEC 27017 Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services provides guidelines supporting the implementation of information security controls for cloud service customers and cloud service providers.
Some guidelines are for cloud service customers who implement the controls, and others are for cloud service providers to support the implementation of those controls. The selection of appropriate information security controls and the application of the implementation guidance provided, will depend on a risk assessment and any legal, contractual, regulatory or other cloud-sector specific information security requirements.
The guidelines of this standard are in addition to and complement the guidelines given in ISO/IEC 27002.
Our services
The SSA provides the high quality services of Assessment of cloud security system based on ISO/IEC 27017 in addition to ISO 27001 certification. The service will include a complex of onsite and off-site assessment of how organisation incorporated the Code of practices for information security controls towards cloud services based on ISO 27017. In case of positive results of the Assessment an Extra Certificate will be issued (in addition to ISO 27001 Certification).
Links
- ISO/IEC 27017:2015 - Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services
- ISO/IEC 27018:2019 - Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
- ISO/IEC 27036-4:2016 - Information technology — Security techniques — Information security for supplier relationships — Part 4: Guidelines for security of cloud services
- ISO/IEC 30118-12:2021 - Information technology – Open Connectivity Foundation (OCF) Specification — Part 12: Cloud security specification
- ISO/IEC 19086-1:2016 - Information technology — Cloud computing — Service level agreement (SLA) framework — Part 1: Overview and concepts
- ISO/IEC 19086-4:2019 - Cloud computing — Service level agreement (SLA) framework — Part 4: Components of security and of protection of PII
- ISO/IEC TS 23167:2020 - Information technology — Cloud computing — Common technologies and techniques
- ISO/IEC TR 23188:2020 - Information technology — Cloud computing — Edge computing landscape
- ISO/TR 21332:2021 - Health informatics — Cloud computing considerations for the security and privacy of health information systems
- ISO/TS 23535:2022 - Health informatics — Requirements for customer-oriented health cloud service agreements