Skip to main content
Category: Supplier and Third-Party

Cloud Services Security Control (5.23)

Also known as: Annex A 5.23, Information Security for Use of Cloud Services, ISO 27001 Control 5.23, Control A.5.23
Simply put

This is a control in the 2022 version of ISO/IEC 27001's Annex A that deals with how an organisation manages the security of the cloud services it uses. It covers the full lifecycle of a cloud service, including acquiring, using, managing, and eventually exiting from those services. It was introduced as a new control in the 2022 revision of the standard.

Formal definition

Annex A 5.23 ("Information security for use of cloud services") is a reference control introduced in the ISO/IEC 27001:2022 revision that addresses the processes required for the acquisition, use, management of, and exit from cloud services in line with an organisation's information security requirements. As with all Annex A controls, its inclusion is not automatically mandatory; it is selected via the Statement of Applicability and informed by the organisation's risk assessment, with implementation typically scaled to the cloud services in scope. In practice, it addresses matters such as ensuring cloud service providers (processors) maintain adequate security, managing access to and provisioning of cloud accounts, and handling data transfer obligations, though specific measures depend on scope and applicable requirements. This control forms part of the reference controls in Annex A and should be distinguished from the certifiable ISMS requirements in clauses 4 through 10; it is not equivalent to the SOC 2 Trust Services Criteria.

Why it matters

As organisations migrate more of their operations to cloud services, the security boundary extends beyond the organisation's own infrastructure to encompass third-party providers acting as processors. Annex A 5.23 was introduced in the ISO/IEC 27001:2022 revision to address this shift directly, recognising that the acquisition, use, management, and exit from cloud services each carry distinct information security considerations that were not called out as a dedicated control in the prior edition. Without structured processes across this lifecycle, organisations risk gaps in accountability, unclear division of security responsibilities, and difficulty recovering or securely disposing of data when a service relationship ends.

The control matters because cloud arrangements introduce dependencies that an organisation does not fully control. A cloud service provider's security posture, its handling of data transfers, and the terms under which access and provisioning occur all bear on the confidentiality, integrity, and availability of information the organisation is responsible for. Treating cloud usage as a defined process, rather than an ad hoc procurement decision, helps ensure that provider security expectations are set, monitored, and enforced consistently.

It is worth noting that, as with all Annex A controls, inclusion of 5.23 is not automatically mandatory. It is selected via the Statement of Applicability and informed by the organisation's risk assessment, with implementation typically scaled to the cloud services in scope. An ISO 27001 certificate covers only the defined scope of the ISMS, so the presence of this control speaks to how cloud services within that scope are governed rather than offering any guarantee of provider infallibility.

Who it's relevant to

Compliance and GRC managers
Those maintaining an ISO 27001:2022 ISMS need to determine whether 5.23 is applicable within their scope, justify that decision in the Statement of Applicability, and ensure the organisation's cloud lifecycle processes are documented and evidenced for certification audits. They should distinguish this Annex A reference control from the certifiable ISMS requirements in clauses 4 through 10.
Security engineers and cloud architects
Practitioners responsible for provisioning and managing cloud services implement the operational aspects of this control, managing access, creating and revoking accounts, assigning group memberships, and verifying that providers maintain adequate security. They often rely on identity and access management tooling to enforce these processes consistently across cloud services in scope.
Vendor risk and procurement teams
Teams involved in acquiring and exiting cloud services apply this control during provider selection, contracting, and offboarding. They address matters such as provider security expectations and data transfer obligations (for example, SCCs or an IDTA), and ensure exit processes allow data to be recovered or securely handled when a service relationship ends.
Auditors and certification bodies
Auditors assessing an ISO 27001:2022 ISMS evaluate whether the organisation's treatment of cloud services aligns with its risk assessment and Statement of Applicability. The assessment covers only the defined scope of the ISMS, and the appropriate depth of implementation is expected to be scaled to the cloud services in use rather than judged against a single fixed standard.

Inside Cloud Services Security Control (5.23)

Annex A Reference Control (ISO/IEC 27001:2022)
Control 5.23 is one of the reference controls introduced in the four-theme structure of the 2022 revision of Annex A. It addresses the use of cloud services and is selected for inclusion via the Statement of Applicability, informed by the organization's risk assessment, rather than being automatically mandatory.
Scope of Cloud Service Use
The control focuses on establishing processes for the acquisition, use, management, and exit from cloud services in line with the organization's information security requirements. The specific processes applied depend on the organization's scope and risk decisions.
Shared Responsibility Considerations
Addressing cloud services typically involves clarifying the division of security responsibilities between the organization and the cloud service provider, though the precise allocation varies by provider, service model, and contractual terms.
Relationship to Supporting Standards
While control 5.23 sits within ISO/IEC 27001 Annex A, additional guidance on cloud security may be found in related standards such as ISO/IEC 27002, ISO/IEC 27017, and ISO/IEC 27018. These are distinct from the certifiable ISMS requirements in clauses 4 through 10.

Common questions

Answers to the questions practitioners most commonly ask about Cloud Services Security Control (5.23).

Is control 5.23 a SOC 2 requirement?
No. Control 5.23 is a reference control listed in Annex A of ISO/IEC 27001 (2022 revision), not a component of SOC 2. SOC 2 is an attestation examination performed by a licensed CPA firm against the Trust Services Criteria, and it does not use ISO 27001 Annex A control numbers. While cloud-related security may be relevant under both frameworks, the specific control 5.23 belongs to ISO 27001's Annex A and is selected via the Statement of Applicability informed by risk assessment.
Does implementing control 5.23 mean my organization is certified for cloud security?
No. Selecting and implementing Annex A control 5.23 is one input to an ISO 27001 information security management system, but certification is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, not against any single control. Any resulting certificate covers only the defined scope of the ISMS. Implementing this control alone does not confer certification, and it does not by itself guarantee the security of cloud services.
How do we decide whether control 5.23 applies to our ISMS?
Applicability is typically determined through the risk assessment process and documented in the Statement of Applicability. In most engagements, organizations that acquire, use, manage, or exit cloud services would consider this control relevant, while an organization using no cloud services might justify its exclusion. The decision depends on scope and the risks identified, rather than being universally mandatory.
What kinds of activities might support this control during implementation?
Depending on scope, organizations often address processes for acquiring, using, managing, and exiting cloud services in a manner consistent with their information security requirements. This can include defining responsibilities between the organization and cloud service providers, setting selection and exit criteria, and establishing how cloud-related risks are managed. The specific measures vary by organization, provider, and the risks identified in the risk assessment.
What evidence might a certification body look for regarding control 5.23?
Auditors typically look for evidence that the control, if included in the Statement of Applicability, is implemented and operating consistently with the organization's stated approach. This can include documented processes, records of provider selection and management, and defined responsibilities. The exact evidence expected depends on the certification body, the scope of the ISMS, and how the organization has defined its controls.
How should responsibilities between our organization and a cloud provider be handled under this control?
In most implementations, organizations clarify the division of responsibilities between themselves and their cloud service providers, since some security responsibilities rest with the provider and others remain with the customer. How this is documented and managed depends on the services used, contractual arrangements, and the organization's own risk decisions, rather than a single prescribed approach.

Common misconceptions

Control 5.23 is a mandatory control that every ISO 27001 organization must implement.
Annex A controls, including 5.23, are reference controls selected through the Statement of Applicability and justified by risk assessment. An organization may exclude it with appropriate justification if it is not applicable to its defined ISMS scope. The certifiable requirements themselves reside in clauses 4 through 10.
Implementing control 5.23 is equivalent to satisfying the cloud-related expectations of a SOC 2 examination.
ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria are separate frameworks. Mapping between them is possible but partial, and addressing cloud security under ISO 27001 does not automatically satisfy the relevant Trust Services Criteria in a SOC 2 report, which is a CPA attestation under SSAE 18 rather than a certification.
Control 5.23 exists identically across all ISO 27001 versions.
Control 5.23 was introduced with the restructured Annex A of the 2022 revision, which moved from 114 controls in the 2013 version to 93 controls organized in four themes. Control numbering and counts depend on the edition, so the version should be specified when citing it.

Best practices

Document the decision to include or exclude control 5.23 in the Statement of Applicability, tying that decision to the outputs of the risk assessment.
Define and record the shared responsibility boundaries with each cloud service provider, recognizing that the allocation varies by provider and service model.
Establish processes covering the full lifecycle of cloud service use, including acquisition, ongoing management, and exit or transition arrangements, scaled to the organization's risk profile.
Consult related guidance such as ISO/IEC 27002, ISO/IEC 27017, and ISO/IEC 27018 for supplementary cloud security direction, while keeping them distinct from the certifiable ISMS requirements in clauses 4 through 10.
Specify the ISO/IEC 27001 version (for example, the 2022 revision) whenever referencing control 5.23 to avoid confusion with the differently structured 2013 edition.
Where the organization also pursues a SOC 2 examination, map cloud controls to the applicable Trust Services Criteria deliberately, treating any cross-framework alignment as partial rather than automatic.