- ISO 27001
- Annex A
ISO 27001 Annex A 5.23: Information security for use of cloud services
Updated 5 min read
Annex A 5.23 is the supplier control that was added in the 2022 edition, and for a modern small business it is often the one that matters most: most of your suppliers that hold data are cloud services. It asks for a process covering the whole life of a cloud service — choosing it, using it, managing it and leaving it.
This page covers what the control requires, the shared-responsibility and exit records auditors increasingly ask for, and an evidence checklist. The parent guide, ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence, covers all five supplier controls.
What Annex A 5.23 requires
The control, paraphrased: processes for the acquisition, use, management and exit from cloud services should be established in accordance with the organisation’s information security requirements. Its full title is Information security for use of cloud services. There is no 2013 equivalent; organisations previously covered cloud providers under the general supplier controls.
The ISO/IEC 27002:2022 guidance, summarised, expects the process to define:
- the security requirements that apply to cloud services you use;
- how cloud services are selected, and what each may be used for;
- roles and responsibilities, including which controls the provider operates and which you must operate yourself;
- how you use the provider’s security features and obtain assurance about the controls it operates;
- how controls, interfaces and changes are managed across several cloud services;
- how incidents involving a cloud service are handled;
- how ongoing use is monitored, reviewed and evaluated;
- the exit strategy.
The guidance also lists matters for the agreement with a cloud provider, among them: where data is processed and stored, support during incidents including help gathering evidence, backups, security when the provider itself subcontracts, advance notice of substantive changes, and the return of your information when the service ends.
A proportionate implementation
Add a cloud services section to your supplier procedure, then keep three short records for each critical or high-tier cloud service:
| Record | What it says |
|---|---|
| Shared-responsibility note | What the provider secures, what you configure: identity and MFA, access reviews, logging, backups, data retention settings |
| Assurance review | Which independent report or certification you relied on (SOC 2 Type II, ISO 27001, and where relevant ISO 27017/27018), its scope and period, and your conclusion |
| Exit note | How data is exported and in what format, the retrieval window after termination, how deletion is confirmed, and the alternative service |
The exit note is the record most often missing, and auditors have started asking for it. Writing it at onboarding takes an hour; the Vendor onboarding checklist: the checks to finish before the contract is signed includes it as its last check. If a cloud service processes personal data, its DPA and data location also belong here; see GDPR Article 28 processor due diligence: vetting vendors that handle personal data.
What certification auditors look for
- The documented cloud services process, approved.
- For a sampled cloud service: why it was chosen, what it may be used for, and who owns it.
- The responsibility split, and evidence you operate your side — for example MFA enforced and access reviewed.
- The assurance you relied on and when you last reviewed it.
- The exit plan.
Evidence checklist for Annex A 5.23
- Cloud services process (a section of the supplier procedure is enough)
- Inventory of cloud services in use, each with an owner and tier
- Shared-responsibility note for each critical and high-tier cloud service
- Dated review of each provider's SOC 2 report or ISO certificate
- Evidence you operate your side: MFA, access reviews, logging, backups
- Agreement terms: data location, incident support, change notice, data return
- Exit note per critical cloud service
Related controls
- ISO 27001 Annex A 5.19: Information security in supplier relationships — the general supplier process 5.23 sits inside.
- ISO 27001 Annex A 5.20: Addressing information security within supplier agreements — the agreement terms.
- ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain — the provider’s own supply chain.
- ISO 27001 Annex A 5.22: Monitoring, review and change management of supplier services — reviewing the service over time.
Also relevant: 5.30 (ICT readiness for business continuity), for critical cloud services, and 8.13 (Information backup), where backup is your responsibility rather than the provider’s.
Frequently asked questions
- What is ISO 27001 Annex A 5.23?
- Annex A 5.23, Information security for use of cloud services, requires processes for the acquisition, use, management and exit from cloud services, established in accordance with the organisation's information security requirements. It is one of the controls new in ISO/IEC 27001:2022 and has no direct 2013 equivalent.
- Does Annex A 5.23 apply to SaaS tools?
- Yes. The control covers cloud services generally — infrastructure, platform and software as a service. For most small and mid-sized organisations the SaaS tools that hold business data are the bulk of their cloud services, and an auditor will expect the process to cover them.
- What is a cloud exit strategy for ISO 27001?
- A short record, per critical cloud service, of how you would leave: how your data is exported and in what format, how long you have to retrieve it, how the provider confirms deletion, what would replace the service, and who owns the plan. ISO/IEC 27002 lists exit strategy among the things the cloud services process should define.
- Are ISO 27017 and ISO 27018 required for Annex A 5.23?
- No. ISO/IEC 27017 (security controls for cloud services) and ISO/IEC 27018 (protection of personal data in public clouds acting as processors) are codes of practice. A provider's certification against them is useful assurance when you assess the provider, but neither is a requirement of ISO 27001 for the customer.
Related guides
- ISO 27001
- Audit
ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence
The five supplier controls in the 2022 edition, what each demands, and the records that satisfy them.
11 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.19: Information security in supplier relationships
The control that asks for a supplier security process: types of supplier, tiers, requirements, and the records that prove it ran.
5 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.20: Addressing information security within supplier agreements
Which security requirements belong in the supplier contract, how to handle vendors on their own paper, and the gap log auditors ask for.
5 min read