SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.23Information security for use of cloud services

Manage the security of cloud services across their lifecycle, from selection and onboarding to exit, with clear agreement on who is responsible for what. Cloud shifts some duties to the provider but not all.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0331Shared responsibility model · PolicysupportsThe shared-responsibility policy facet documents, provider by provider, exactly which security duties are the company's, the starting point A.5.23 requires before anything else.RCF-0332Shared responsibility model · ProcesssupportsThe process facet turns the documented split into routine work, so someone performs each customer-side duty on a schedule instead of assuming the provider covers it.RCF-0333Shared responsibility model · TechnicalenablesThe technical facet enables the customer-side of the cloud boundary to be defended in practice, with tenant hardening, backup, and logging that no provider certificate replaces.RCF-0334Cloud IAM · PolicysupportsThe cloud access policy facet supports A.5.23 by setting who gets which cloud role, how admin access is restricted, and when rights get reviewed.RCF-0337CSPM posture · PolicysupportsThe CSPM policy facet commits the company to continuous scanning of cloud configurations, one piece of the ongoing cloud security posture A.5.23 expects.RCF-0346Workload protection · PolicysupportsThe workload protection policy facet sets the security requirements every cloud workload must meet before and while it runs, one leg of A.5.23's technical scope.RCF-0349Multi-tenancy controls · PolicysupportsThe multi-tenancy policy facet addresses in writing how tenant data stays separated in shared cloud environments, a boundary A.5.23 requires the customer to manage.RCF-0352SaaS security configuration · PolicysupportsThe SaaS security configuration policy facet defines mandatory settings such as MFA and restricted sharing for every SaaS app, covering the SaaS side of A.5.23.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

In practice

SMEs often treat a cloud provider's certifications as covering their own obligations too. In practice the split is narrower: the provider secures the underlying infrastructure, but tenant hardening, backup, identity configuration, and SaaS admin settings stay with the customer. The gap shows most in shared responsibility matrices that were written once during a vendor review and never revisited when a new SaaS tool was adopted. A working setup names an owner for each provider's customer-side duties, enforces MFA and restricted sharing defaults on every SaaS app, and runs continuous configuration checks rather than trusting a point-in-time audit.

Common gaps

The shared responsibility matrix was drafted for one provider years ago and never extended to the SaaS tools added since.
Nobody runs continuous configuration checks against cloud environments, so drift goes unnoticed until an external scan or an incident finds it.
Admin access to SaaS platforms was granted years ago and has never been reviewed against who still needs it.

Questions your auditor will ask

Where is the shared responsibility split documented per cloud provider?
In a shared responsibility matrix listing each cloud and SaaS provider alongside the security duties that remain with the company.
How do you check cloud configurations stay within your security standard?
A CSPM tool continuously scans cloud environments against the agreed configuration standard and flags drift for a named owner to fix.
What stops one tenant's data from being visible to another in shared cloud services?
Tenant separation is enforced at the platform layer, and access reviews confirm no configuration lets one customer reach another's data.
Which security settings are required on every SaaS app before it goes live?
Enforced MFA, restricted external sharing defaults, and admin account limits, defined in the SaaS security baseline every new tool is checked against.

Where regulation demands it

NIS2 6.1 requires security requirements baked into how ICT services are acquired, and ENS op.ext.1 expects the same discipline in contracts with cloud and SaaS suppliers.
NIS2 6.3 requires configuration management across systems, which cloud posture management extends into every provider environment the company depends on.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.23?”
Also via MCP, free with account