A.5.23Information security for use of cloud services
Manage the security of cloud services across their lifecycle, from selection and onboarding to exit, with clear agreement on who is responsible for what. Cloud shifts some duties to the provider but not all.
Mapping at a glance
A.5.23Information security for use of cloud servicesISO/IEC 27001:2022
SMEs often treat a cloud provider's certifications as covering their own obligations too. In practice the split is narrower: the provider secures the underlying infrastructure, but tenant hardening, backup, identity configuration, and SaaS admin settings stay with the customer. The gap shows most in shared responsibility matrices that were written once during a vendor review and never revisited when a new SaaS tool was adopted. A working setup names an owner for each provider's customer-side duties, enforces MFA and restricted sharing defaults on every SaaS app, and runs continuous configuration checks rather than trusting a point-in-time audit.
Common gaps
The shared responsibility matrix was drafted for one provider years ago and never extended to the SaaS tools added since.
Nobody runs continuous configuration checks against cloud environments, so drift goes unnoticed until an external scan or an incident finds it.
Admin access to SaaS platforms was granted years ago and has never been reviewed against who still needs it.
Questions your auditor will ask
Where is the shared responsibility split documented per cloud provider?
In a shared responsibility matrix listing each cloud and SaaS provider alongside the security duties that remain with the company.
How do you check cloud configurations stay within your security standard?
A CSPM tool continuously scans cloud environments against the agreed configuration standard and flags drift for a named owner to fix.
What stops one tenant's data from being visible to another in shared cloud services?
Tenant separation is enforced at the platform layer, and access reviews confirm no configuration lets one customer reach another's data.
Which security settings are required on every SaaS app before it goes live?
Enforced MFA, restricted external sharing defaults, and admin account limits, defined in the SaaS security baseline every new tool is checked against.
Where regulation demands it
NIS2 6.1 requires security requirements baked into how ICT services are acquired, and ENS op.ext.1 expects the same discipline in contracts with cloud and SaaS suppliers.
NIS2 6.3 requires configuration management across systems, which cloud posture management extends into every provider environment the company depends on.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.