SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

A proof for fulfillment of requirement A.9.5.1 from ISO 27017

  Quote
Guest
Guest user Created:   Sep 29, 2022 Last commented:   Sep 29, 2022

A proof for fulfillment of requirement A.9.5.1 from ISO 27017

Our certification body has asked us to show the proof of implementation of A.9.5.1 from ISO 27017: "Risk assessment performed and mitigating controls to address risks imposed by customer-developed/supplied software in the cloud environment. (s1)"

Could you please give us some examples on what kind of proof we would need to present to the certification body?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 29, 2022

I’m assuming you are referring to control CDL 9.5.1 - Segregation in virtual computing environments.

Regarding the “Risk assessment performed” you can show as evidence the last risk assessment and treatment report, showing to which risks related to “customer-developed/supplied software in the cloud environment” the control CDL 9.5.1 is used as treatment.

Regarding the “mitigating controls to address risks imposed by customer-developed/supplied software in the cloud environment”, examples of evidence of implementation of this control are:

  • Network diagrams showing how computing environments are segregated
  • Firewall rules tables showing the configurations implemented in network devices to segregate the environments
  • Results of independent penetration tests covering the evaluation of this control

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Sep 29, 2022

Sep 29, 2022