// Level 3 · Controls

Cloud Service Extensions

Cloud-specific controls extending ISO/IEC 27002.

6.1.1Medium

Information security roles and responsibilities (cloud)

Allocate cloud-specific roles for the cloud customer and cloud service provider, including cloud asset ownership and risk responsibilities.

6.1.3Low

Contact with authorities (cloud)

Cloud customer should agree procedures for the cloud service provider to contact relevant authorities on its behalf.

7.2.2Medium

Information security awareness, education and training (cloud)

Provide training that addresses cloud-specific security responsibilities of users in both customer and provider organizations.

9.2.1High

User registration and de-registration (cloud)

Manage cloud service customer user registration including federation, single sign-on, and removal upon contract termination.

9.2.4High

Management of secret authentication information (cloud)

Provide secure mechanisms for managing administrative credentials for cloud services.

10.1.1High

Cryptographic controls policy (cloud)

Define which cryptographic controls are used by the cloud service customer and which by the provider.

10.1.2High

Key management (cloud)

Define key management responsibilities between cloud customer and provider, including BYOK options.

12.1.2Medium

Change management (cloud)

Cloud service provider must inform cloud service customer of changes that may adversely affect the customer.

12.4.1High

Event logging (cloud)

Cloud service provider should provide logging capabilities and access to logs to the cloud service customer.

13.1.3High

Segregation in networks (cloud)

Enforce segregation between virtual networks of different cloud service customers.

15.1.2High

Addressing security in supplier agreements (cloud)

Cloud customer agreements with cloud providers must address all relevant security requirements.