Expert Advice Community

Guest

Assets of IaaS

  Quote
Guest
Guest user Created:   Apr 17, 2019 Last commented:   Apr 18, 2019

Assets of IaaS

I have a question regarding assets of IaaS: Our virtual infrastructure is hosted on MS Azure. MS Data Centers are ISO 27001 compliant. Do we have to assess the risks of the IaaS part keeping in mind that DCs are compliant? Is it possible to not include physical infrastructure (which belongs to Microsoft) in to the asset list in order to reduce the number of risks (it's obvious that they will have acceptable level). And if it‘s necessary to assess the risks of those assets, what could be the applied controls – IaaS agreement with Microsoft, or anything else?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 17, 2019

Answer:

You still have to access the risks, even for physical assets, as if the IaaS was being managed by your organization because you need to identify and understand which risks are relevant to you, so you can ensure that those risks are being treated properly by your IaaS provider. The fact that your provider is ISO 27001 certified greatly improves the chances that they will be treating risks relevant to you, but only by means of a risks assessment you will be sure of this situat ion (for a certification auditor it will not be obvious that your risks will be on acceptable levels only because of the providers' certification).

Once you have identified unacceptable risks your provider has to treat, you can apply controls from section A.15 (relationship with suppliers), so proper clauses will be included on service agreements.

These articles will provide you further explanation about ensuring security with providers:
- 6-step process for handling supplier security according to ISO 27001 https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/
- Which security clauses to use for supplier agreements? https://advisera.com/27001academy/blog/2017/06/19/which-security-clauses-to-use-for-supplier-agreements/

Quote
0 0
Guest
mariusc Apr 18, 2019

And what about the situation when there is only online agreement which is default for all the customers and you "sign" it only by ticking the check-box under the Terms and Conditions. It is not possible to request to include any clauses to the agreement with the 3rd party service provider as they don't agree to do unique agreements for different customers. For example it could be online payments platform, which is PCI-DSS compliant and you integrate that solution on your website.

Quote
0 0
Expert
Rhand Leal Apr 20, 2019

Answer:

In situations where you cannot change service conditions presented by the provider you should evaluate if your organization can accept the risks not properly covered by the provided service agreement,and if there are alternative providers you can consider.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 17, 2019

Apr 20, 2019

Suggested Topics

Guest user Created:   Jun 23, 2021 ISO 27001 & 22301
Replies: 1
0 1

ISMS implementation

Guest user Created:   Sep 30, 2023 ISO 27001 & 22301
Replies: 1
0 0

Environment and Scope