Expert Advice Community

Guest

Cloud Service Provider assessment considerations

  Quote
Guest
Guest user Created:   Oct 13, 2016 Last commented:   Oct 13, 2016

Cloud Service Provider assessment considerations

When writing a Cloud Service Provider Assessment Guideline based on CSA 3.0, what aspects should be considered?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Oct 13, 2016

Answer:

One of the most useful CSA's resources is the Cloud Controls Matrix, currently on version 3.0.1. It is a mapping of CSA recommended practices to the most known standards and regulations regarding information protection. Considering ISO standards, this matrix maps CSA practices to:

ISO/IEC 27001:2013 (information security management)
ISO/IEC 27002:2013 (information security practices)
ISO/IEC 27017:2015 (information security in cloud environments)
ISO/IEC 270018:2015 (protection of PII)

So, if someone whishes to create a vendor assessment guideline alignend with CSA practices, he can use the Cloud Controls Matrix to identify which CSA recommendations are mapped to supplier management practices from ISO 27001 (items marked with A.15.x.x) and ISO 27002 (items marked with 15.x.x), and choose those that are best fit for his organization. He also can use the same method to align his guideline to ISO 27017 (s ecurity in cloud services) and ISO 27018 (protection of PII).

The Cloud Controls Matrix can be found in this link: https://cloudsecurityalliance.org/download/cloud-controls-matrix-v3-0-1/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 13, 2016

Oct 13, 2016