Cloud Services Security Control (5.23)
This is a control in the 2022 version of ISO/IEC 27001's Annex A that deals with how an organisation manages the security of the cloud services it uses. It covers the full lifecycle of a cloud service, including acquiring, using, managing, and eventually exiting from those services. It was introduced as a new control in the 2022 revision of the standard.
Annex A 5.23 ("Information security for use of cloud services") is a reference control introduced in the ISO/IEC 27001:2022 revision that addresses the processes required for the acquisition, use, management of, and exit from cloud services in line with an organisation's information security requirements. As with all Annex A controls, its inclusion is not automatically mandatory; it is selected via the Statement of Applicability and informed by the organisation's risk assessment, with implementation typically scaled to the cloud services in scope. In practice, it addresses matters such as ensuring cloud service providers (processors) maintain adequate security, managing access to and provisioning of cloud accounts, and handling data transfer obligations, though specific measures depend on scope and applicable requirements. This control forms part of the reference controls in Annex A and should be distinguished from the certifiable ISMS requirements in clauses 4 through 10; it is not equivalent to the SOC 2 Trust Services Criteria.
Why it matters
As organisations migrate more of their operations to cloud services, the security boundary extends beyond the organisation's own infrastructure to encompass third-party providers acting as processors. Annex A 5.23 was introduced in the ISO/IEC 27001:2022 revision to address this shift directly, recognising that the acquisition, use, management, and exit from cloud services each carry distinct information security considerations that were not called out as a dedicated control in the prior edition. Without structured processes across this lifecycle, organisations risk gaps in accountability, unclear division of security responsibilities, and difficulty recovering or securely disposing of data when a service relationship ends.
The control matters because cloud arrangements introduce dependencies that an organisation does not fully control. A cloud service provider's security posture, its handling of data transfers, and the terms under which access and provisioning occur all bear on the confidentiality, integrity, and availability of information the organisation is responsible for. Treating cloud usage as a defined process, rather than an ad hoc procurement decision, helps ensure that provider security expectations are set, monitored, and enforced consistently.
It is worth noting that, as with all Annex A controls, inclusion of 5.23 is not automatically mandatory. It is selected via the Statement of Applicability and informed by the organisation's risk assessment, with implementation typically scaled to the cloud services in scope. An ISO 27001 certificate covers only the defined scope of the ISMS, so the presence of this control speaks to how cloud services within that scope are governed rather than offering any guarantee of provider infallibility.
Who it's relevant to
Inside Cloud Services Security Control (5.23)
Common questions
Answers to the questions practitioners most commonly ask about Cloud Services Security Control (5.23).