Skip to content
  • ISO 27001
  • Annex A

ISO 27001 Annex A 5.23: Information security for use of cloud services

Updated 5 min read

Annex A 5.23 is the supplier control that was added in the 2022 edition, and for a modern small business it is often the one that matters most: most of your suppliers that hold data are cloud services. It asks for a process covering the whole life of a cloud service — choosing it, using it, managing it and leaving it.

This page covers what the control requires, the shared-responsibility and exit records auditors increasingly ask for, and an evidence checklist. The parent guide, ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence, covers all five supplier controls.

What Annex A 5.23 requires

The control, paraphrased: processes for the acquisition, use, management and exit from cloud services should be established in accordance with the organisation’s information security requirements. Its full title is Information security for use of cloud services. There is no 2013 equivalent; organisations previously covered cloud providers under the general supplier controls.

The ISO/IEC 27002:2022 guidance, summarised, expects the process to define:

  • the security requirements that apply to cloud services you use;
  • how cloud services are selected, and what each may be used for;
  • roles and responsibilities, including which controls the provider operates and which you must operate yourself;
  • how you use the provider’s security features and obtain assurance about the controls it operates;
  • how controls, interfaces and changes are managed across several cloud services;
  • how incidents involving a cloud service are handled;
  • how ongoing use is monitored, reviewed and evaluated;
  • the exit strategy.

The guidance also lists matters for the agreement with a cloud provider, among them: where data is processed and stored, support during incidents including help gathering evidence, backups, security when the provider itself subcontracts, advance notice of substantive changes, and the return of your information when the service ends.

A proportionate implementation

Add a cloud services section to your supplier procedure, then keep three short records for each critical or high-tier cloud service:

RecordWhat it says
Shared-responsibility noteWhat the provider secures, what you configure: identity and MFA, access reviews, logging, backups, data retention settings
Assurance reviewWhich independent report or certification you relied on (SOC 2 Type II, ISO 27001, and where relevant ISO 27017/27018), its scope and period, and your conclusion
Exit noteHow data is exported and in what format, the retrieval window after termination, how deletion is confirmed, and the alternative service

The exit note is the record most often missing, and auditors have started asking for it. Writing it at onboarding takes an hour; the Vendor onboarding checklist: the checks to finish before the contract is signed includes it as its last check. If a cloud service processes personal data, its DPA and data location also belong here; see GDPR Article 28 processor due diligence: vetting vendors that handle personal data.

What certification auditors look for

  • The documented cloud services process, approved.
  • For a sampled cloud service: why it was chosen, what it may be used for, and who owns it.
  • The responsibility split, and evidence you operate your side — for example MFA enforced and access reviewed.
  • The assurance you relied on and when you last reviewed it.
  • The exit plan.

Evidence checklist for Annex A 5.23

  • Cloud services process (a section of the supplier procedure is enough)
  • Inventory of cloud services in use, each with an owner and tier
  • Shared-responsibility note for each critical and high-tier cloud service
  • Dated review of each provider's SOC 2 report or ISO certificate
  • Evidence you operate your side: MFA, access reviews, logging, backups
  • Agreement terms: data location, incident support, change notice, data return
  • Exit note per critical cloud service

Also relevant: 5.30 (ICT readiness for business continuity), for critical cloud services, and 8.13 (Information backup), where backup is your responsibility rather than the provider’s.

Frequently asked questions

What is ISO 27001 Annex A 5.23?
Annex A 5.23, Information security for use of cloud services, requires processes for the acquisition, use, management and exit from cloud services, established in accordance with the organisation's information security requirements. It is one of the controls new in ISO/IEC 27001:2022 and has no direct 2013 equivalent.
Does Annex A 5.23 apply to SaaS tools?
Yes. The control covers cloud services generally — infrastructure, platform and software as a service. For most small and mid-sized organisations the SaaS tools that hold business data are the bulk of their cloud services, and an auditor will expect the process to cover them.
What is a cloud exit strategy for ISO 27001?
A short record, per critical cloud service, of how you would leave: how your data is exported and in what format, how long you have to retrieve it, how the provider confirms deletion, what would replace the service, and who owns the plan. ISO/IEC 27002 lists exit strategy among the things the cloud services process should define.
Are ISO 27017 and ISO 27018 required for Annex A 5.23?
No. ISO/IEC 27017 (security controls for cloud services) and ISO/IEC 27018 (protection of personal data in public clouds acting as processors) are codes of practice. A provider's certification against them is useful assurance when you assess the provider, but neither is a requirement of ISO 27001 for the customer.