SecFrame Explorer
controls.intelligence
SearchPricing
AI lookups:3/3left
3/3
Sign in
FrameworksISO 27017Additional Cloud Controls
// Level 3 · Controls

Additional Cloud Controls

Controls unique to cloud environments (CLD.* clauses).

CLD.6.3.1High

Shared roles and responsibilities within a cloud computing environment

Define and document shared security responsibilities between cloud customer and cloud service provider.

CLD.8.1.5High

Removal of cloud service customer assets

Customer assets must be removed and returned within agreed timeframes when the cloud service contract terminates.

CLD.9.5.1Critical

Segregation in virtual computing environments

Customer's virtual environment running on cloud infrastructure must be segregated from other customers and the provider.

CLD.9.5.2High

Virtual machine hardening

Virtual machines should be hardened to meet business needs.

CLD.12.1.5High

Administrator's operational security

Procedures for administrative operations of a cloud service should be defined, documented, and monitored.

CLD.12.4.5Medium

Monitoring of cloud services

Customer should have capability to monitor specified aspects of operation of cloud services it uses.

CLD.13.1.4Medium

Alignment of security management for virtual and physical networks

Configuration of virtual networks should be aligned with the information security policy of the physical network.

// SecFrame Explorer — security frameworks, decoded
TermsPricingRefundsPrivacy·Powered by arnav.au