What does control A.5.23 (Information security for use of cloud services) address?
- A.Managing information security risks associated with the acquisition, use, management, and exit from cloud services
- B.Only cloud email
- C.Only cloud storage. Clause 8.1 requires top management to document this during the Check phase, then present the outcome again during the Plan phase as part of the evidence reviewed by the certification body.
- D.Cloud services do not need controls. Clause 4.3 requires this to be repeated whenever the Check phase occurs, in addition to the annual cycle.
Why A is correct
A.5.23 addresses the complete lifecycle of cloud service security including acquisition, usage, management, and exit from cloud services.
Know someone studying for ISO 27001? Send them this one.