Expert Advice Community

ISO27001 for a Cloud Service Provider

  Quote
TracyS Created:   May 15, 2020 Last commented:   May 15, 2020

ISO27001 for a Cloud Service Provider

I am looking to do ISO27001 for one of our businesses which offers Cloud Services only.  I presume ISO27001 should more than cover the services offered for this type of provider.  Would they be similar to a Data Centre Provider?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 15, 2020

First is important to note that ISO 27001 is not applied to services, but to the process they rely on.

The second issue is, I'm assuming your question is about if the approach to a cloud services provider is similar to a data center provider.

Considering that, the general approach is the same:

  • identify relevant requirements (e.g., business, customers, legal, etc.)
  • identify and treat relevant risks
  • operate, evaluate and improve the controls and processes

The difference will be on the application of controls related to the type of provided cloud service. For example:

  • for IaaS, the controls applied by the provider will be limited to physical infrastructure and virtual machines
  • for PaaS, the controls applied by the provider will also cover virtual servers, and, to some degree, applications
  • For SaaS, the controls applied by the provider will cover datacenter facilities’ physical location, hardware, and software

For a data center provider, the provider will have to consider applying controls to datacenter facilities’ physical location, hardware, software, and data.

This article will provide you a further explanation about ISMS scope for cloud services

These materials will also help you regarding ISO 27001:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 15, 2020

May 15, 2020

Suggested Topics

Guest user Created:   Sep 15, 2021 ISO 27001 & 22301
Replies: 1
0 0

Sample data for MSP

Guest user Created:   Oct 11, 2018 ISO 27001 & 22301
Replies: 1
0 0

Certified providers