ISO 27001 A.5.23 — Information security for use of cloud services

A.5.23 covers the whole life of a cloud service — how you choose it, how you configure it, how you monitor it, and how you leave it. For cloud-first SMEs it is one of the highest-value controls in Annex A.

Michael McCarroll 6 min read Updated August 2026

What the control says

Processes for the acquisition, use, management and exit from cloud services shall be established in accordance with the organisation's information security requirements. It links tightly to the supplier controls A.5.19 to A.5.22.

Theme: Organisational · New in ISO 27001:2022

Why it matters

Most SME breaches involving cloud are configuration failures, not provider failures. A.5.23 forces the shared-responsibility conversation: the provider secures the platform, you secure your identities, data, sharing settings and integrations.

If you run Microsoft 365 or Google Workspace plus a handful of SaaS tools, this control is mainly about a maintained inventory, documented security requirements before purchase, tenant configuration baselines and a plausible exit plan.

How to implement it

  1. Inventory every cloud service that holds or processes your information, including the ones bought on a card by a single team.
  2. Write down the security requirements a new cloud service must meet before purchase: SSO/MFA support, data location, encryption, audit logging, breach notification terms and available certifications.
  3. Document the shared responsibility split for each significant service — one row per service, one line each for who handles identity, data, configuration, backup and logging.
  4. Baseline the tenant configuration (external sharing, guest access, admin roles, conditional access) and review it on a set cadence.
  5. Capture the exit strategy: how you extract data, in what format, and how you confirm deletion.
  6. Re-review each service annually and when the provider makes a material change.

Evidence auditors ask for

  • Cloud service inventory with owner, data classification and criticality
  • Documented cloud selection criteria and evidence they were applied to a recent purchase
  • Shared responsibility matrix for the main services
  • Configuration baseline reports and dated reviews (for Microsoft 365 tenants, exportable directly)
  • Contract or terms extract covering data location, breach notification and deletion on exit

Common findings

  • Shadow SaaS: services in use that never made it onto the inventory.
  • No exit plan, so the organisation could not demonstrate it can recover its data if the provider fails.
  • Provider certifications collected once at onboarding and never refreshed.
  • Configuration drift — external sharing or legacy authentication quietly re-enabled since certification.

Related controls

  • A.5.19 Information security in supplier relationships
  • A.5.20 Addressing information security within supplier agreements
  • A.5.21 Managing information security in the ICT supply chain
  • A.5.22 Monitoring, review and change management of supplier services
  • A.8.9 Configuration management

See the full list of all 93 Annex A controls or start from the Statement of Applicability template.

FAQ

Does A.5.23 apply if we only use Microsoft 365?
Yes. Microsoft 365 is a cloud service holding your information, so selection, configuration, monitoring and exit all fall in scope — even if it is your only cloud platform.
Is the provider's ISO 27001 certificate enough evidence?
No. It evidences the provider's side of the shared responsibility split. Auditors will still ask how you configure, monitor and govern your own tenant.
How does A.5.23 relate to the supplier controls?
A.5.19 to A.5.22 cover supplier relationships generally; A.5.23 adds the cloud-specific requirements on top. Run one supplier process and add cloud-specific questions to it rather than maintaining two.

Evidence A.5.23 without the spreadsheet

ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →