The cloud has changed everything about how we store, share, and secure information. But while it brings scalability and speed, it also introduces new risks, especially when sensitive or regulated data moves beyond your direct control.
That’s where Control 5.23 of ISO 27001 comes in. This control ensures that organisations manage information security risks associated with the use of cloud services, from selection and onboarding through to monitoring and exit.
It’s not about avoiding the cloud. It’s about using it intelligently and securely.
Control 5.23 is designed to make sure your organisation doesn’t hand over responsibility for security the moment it signs a cloud contract.
Just because a vendor says they’re “ISO certified” doesn’t mean your risk disappears. This control requires you to identify what data is being stored or processed in the cloud, understand who’s responsible for protecting it, and ensure that appropriate controls are in place.
In short: shared service, shared responsibility.
You’re expected to:
It’s about managing your part of the shared model, not outsourcing it.
The shift to cloud computing has blurred the boundaries of traditional IT security. Your data could be sitting in multiple regions, replicated across dozens of servers, and accessed from anywhere in the world.
Without structured oversight, that flexibility quickly turns into exposure.
Control 5.23 helps you retain control and visibility, so you’re not relying solely on trust or vendor marketing. It ensures due diligence when choosing a provider and continuous assurance throughout the relationship.
Neglecting this control can lead to:
In other words, it keeps your head in the cloud, but your feet firmly on the ground.
To meet the intent of Control 5.23, your organisation should:
Ultimately, good cloud governance is about knowing what you’ve got, where it is, and how it’s being protected.
Managing cloud-related risk shouldn’t rely on spreadsheets or memory. de.iterate makes the process seamless by helping you:
And when it comes time to update your Statement of Applicability or risk register, de.iterate keeps everything aligned. So you can show, not just tell, how you’re managing your cloud environment securely.
Cloud adoption isn’t the risk. Unmanaged cloud use is.
ISO 27001 Control 5.23 helps you balance innovation with assurance, ensuring the move to cloud doesn’t come at the cost of control.
With the right systems, governance, and technology support, you can have both agility and assurance, because smart compliance doesn’t slow you down, it keeps you running strong.