Skip to main content
Category: Technical Security Controls

Cloud Services Security

Also known as: Cloud Security, Cloud Computing Security
Simply put

Cloud services security is the set of policies, practices, and technologies used to protect the applications, data, and infrastructure that organizations run in cloud environments. It aims to defend cloud-based systems against security risks and unauthorized access. The specific measures involved vary depending on the cloud provider, the services used, and the organization's own responsibilities.

Formal definition

Cloud services security refers to the frameworks of policies, controls, procedures, and technologies applied to protect cloud-hosted applications, data, and infrastructure from security threats. In practice it spans identity and access management, data protection, network and workload controls, and configuration and monitoring, typically implemented under a shared-responsibility model in which the cloud provider secures the underlying infrastructure and the customer secures what they deploy and configure within it. In an audit or certification context, cloud services security controls may be evaluated against relevant Trust Services Criteria in a SOC 2 examination or against selected ISO/IEC 27001 ISMS requirements and Annex A reference controls; the applicable controls and scope depend on the engagement, and cloud-specific guidance such as ISO/IEC 27017 may inform control selection. The evidence available describes the general concept but does not specify particular control frameworks, so specific control mappings should be confirmed against the applicable standard and scope.

Why it matters

As organizations move applications, data, and infrastructure into cloud environments, the attack surface and the controls needed to protect it shift accordingly. Cloud services security matters because the responsibility for protecting cloud-hosted systems is typically divided between the cloud provider and the customer under a shared-responsibility model: the provider secures the underlying infrastructure, while the customer remains responsible for securing what they deploy and configure. Misunderstanding this division is a common source of exposure, since controls a customer assumes are handled by the provider may in fact fall to the customer.

For compliance and audit purposes, cloud services security is significant because the controls protecting cloud environments are often the subject of examination. In a SOC 2 examination, cloud-related controls may be evaluated against the relevant Trust Services Criteria, while under ISO/IEC 27001 they may be assessed against selected ISMS requirements and Annex A reference controls, with cloud-specific guidance such as ISO/IEC 27017 potentially informing control selection. The applicable controls and scope depend entirely on the engagement.

It is important to recognize the limits of any assurance in this area. A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Because specific control frameworks are not universally prescribed, organizations should confirm the exact control mappings against the applicable standard and the agreed scope rather than assuming a fixed set of measures applies.

Who it's relevant to

Compliance and GRC Managers
Compliance and GRC professionals need to determine which cloud services security controls fall within the scope of a SOC 2 examination or an ISO 27001 ISMS. Because responsibilities are typically split under a shared-responsibility model, they must document clearly which controls are managed by the cloud provider and which remain the organization's own, and confirm control mappings against the applicable standard rather than assuming a fixed set applies.
Security Engineers and Cloud Architects
Those who deploy and configure cloud environments are usually responsible for the customer side of the shared-responsibility model, including identity and access management, data protection, network and workload controls, and configuration and monitoring. The specific measures they implement vary with the provider and the services in use.
Auditors and Assessors
In a SOC 2 examination, auditors may evaluate cloud services security controls against the relevant Trust Services Criteria, while ISO 27001 assessors evaluate them against selected ISMS requirements and Annex A reference controls. In both cases the applicable controls and scope depend on the engagement, and cloud-specific guidance such as ISO/IEC 27017 may inform control selection.
Executive and Risk Stakeholders
Leaders relying on cloud assurance should understand its limits: a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Neither outcome extends beyond its stated boundaries.

Inside Cloud Services Security

Shared Responsibility Model
The division of security obligations between the cloud service provider and the customer. The provider typically secures the underlying infrastructure, while the customer is generally responsible for configuration, access management, and data within the service. The precise allocation depends on the service model (IaaS, PaaS, SaaS) and the terms of the engagement.
SOC 2 Reporting for Cloud Providers
A SOC 2 examination is an attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certificate. Cloud providers often obtain a SOC 2 Type II report to demonstrate that controls were both suitably designed and operating effectively over a defined review period, the length of which is determined by scoping decisions.
ISO/IEC 27001 Certification for Cloud Services
An ISO/IEC 27001 certificate is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10. Cloud providers may pursue this certification to demonstrate a managed information security management system, with applicable controls selected through a Statement of Applicability informed by risk assessment.
Cloud-Specific Extension Standards
ISO/IEC 27017 provides guidance on information security controls for cloud services, and ISO/IEC 27018 addresses the protection of personally identifiable information in public clouds. These are distinct from ISO/IEC 27001 itself and are typically used to supplement an ISMS where cloud services are in scope.
Trust Services Criteria Relevant to Cloud
For SOC 2 engagements, Security (the Common Criteria) is the only required category, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. Cloud providers frequently include Availability given the service delivery model, though selection depends on the engagement scope.
Scope Definition
Both frameworks apply only to the boundaries defined for the engagement or ISMS. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS. Cloud environments require careful scoping of which systems, services, and locations are included.

Common questions

Answers to the questions practitioners most commonly ask about Cloud Services Security.

Does using a cloud provider that has a SOC 2 report or ISO 27001 certificate mean my own organization is compliant?
No. A cloud provider's SOC 2 report or ISO 27001 certificate covers only that provider's controls and the scope defined in their engagement or ISMS. It does not extend to your organization's use of the service. In most cloud arrangements, responsibilities are shared: the provider addresses certain infrastructure-layer controls, while you remain responsible for configuration, access management, and data handling within your scope. You would need your own SOC 2 examination or ISO 27001 certification, scoped to your environment, to demonstrate your own compliance.
Is a SOC 2 report from a cloud provider the same thing as an ISO 27001 certificate for procurement purposes?
No. A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 standard, resulting in a report about controls relevant to the Trust Services Criteria. An ISO/IEC 27001 certificate is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, with reference controls selected through a Statement of Applicability. They are different deliverables produced through different processes, and one does not automatically satisfy the other. Mapping between them is possible but only partial, so procurement teams should evaluate each on its own terms and against the scope covered.
How do I determine which cloud security responsibilities fall to my organization versus the provider?
Review the provider's shared responsibility documentation alongside the scope statements in their SOC 2 report or ISO 27001 Statement of Applicability. These typically indicate which controls the provider operates and which remain with the customer. The division depends on the service model and the specific configuration, so responsibilities vary by engagement. Where a provider's report identifies complementary user entity controls, those are areas your own organization is expected to address, and they should be reflected in your own control set and risk assessment.
What should I look for when reviewing a cloud provider's SOC 2 report as part of vendor due diligence?
Confirm whether the report is a Type I, which addresses suitability of design at a point in time, or a Type II, which addresses design and operating effectiveness over a defined review period whose length is set by scoping decisions. Check which Trust Services Criteria categories are included, noting that Security (the Common Criteria) is the only required category while Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. Also review the described scope, any noted exceptions, and any complementary user entity controls. Remember that the report attests only to the controls and period covered and does not guarantee freedom from breaches.
How can cloud security controls be reflected in an ISO 27001 ISMS?
Cloud-related risks are addressed through the ISMS requirements in clauses 4 through 10, with applicable reference controls selected through the Statement of Applicability and informed by your risk assessment. When citing specific control counts, specify the version, since Annex A was restructured in the 2022 revision. Organizations that operate significant cloud environments may also consider related standards such as ISO 27017 and ISO 27018, which provide additional guidance for cloud services and for handling personal data in the cloud, respectively; these are typically used to supplement rather than replace the certifiable ISO 27001 requirements.
If my cloud environment is certified or attested, does that cover all of my services automatically?
Not necessarily. Both frameworks apply only to a defined scope: a SOC 2 report attests only to the controls and the period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS. Cloud services, accounts, or regions outside that scope are not automatically included. When scoping, confirm which environments and data flows are covered so that stakeholders do not assume broader coverage than the engagement or certification actually provides.

Common misconceptions

A cloud provider's SOC 2 report or ISO 27001 certificate means the customer's use of the service is automatically compliant and secure.
Under the shared responsibility model, the provider's attestation or certification covers only the controls within its scope. The customer typically remains responsible for its own configuration, access management, and data protection, and a provider's report or certificate does not guarantee freedom from breaches.
A SOC 2 report and an ISO 27001 certificate are interchangeable, so obtaining one satisfies the other for cloud services.
SOC 2 is an attestation examination producing a report, while ISO 27001 is a certification against a management system standard. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
Achieving SOC 2 or ISO 27001 for cloud services requires selecting every available criterion or control.
For SOC 2, only the Security Common Criteria is required and additional categories are selected based on scope. For ISO 27001, Annex A controls are reference controls selected via a Statement of Applicability informed by risk assessment rather than applied universally.

Best practices

Clarify and document the shared responsibility boundary for each cloud service model in use, so it is clear which controls fall to the provider and which remain the customer's responsibility.
Define the scope of any SOC 2 examination or ISO 27001 ISMS precisely, identifying which cloud systems, services, and locations are included and which are out of scope.
Review a cloud provider's SOC 2 report to understand the review period, the Trust Services Criteria covered, and any noted exceptions, rather than treating the report as a blanket assurance.
When ISO 27001 certification is pursued for cloud services, consider supplementing the ISMS with cloud-specific guidance from ISO/IEC 27017 and, where personal data is involved, ISO/IEC 27018.
Select SOC 2 optional categories (such as Availability or Confidentiality) and ISO 27001 Annex A controls based on documented risk assessment and scope rather than defaulting to all of them.
Avoid relying on a provider's attestation or certification as evidence of your own compliance; validate that customer-side controls address the portions of the shared responsibility model owned by your organization.