A.5.23 Organizational
Information security for use of cloud services
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-20partialaligns with — Both address the need to establish security requirements and controls when organizational information is processed or stored on external systems.
- CA-6partialaligns with — Both require formal acceptance of residual risk by management before authorizing the use of external services.
- CM-7partialaligns with — Both require organizations to restrict and control the functionality and scope of external services to only what is necessary and approved.
- IR-4partialaligns with — Both require defined procedures for handling security incidents that occur within the environment of an external service provider.
- SR-2partialaligns with — Both emphasize establishing a documented plan to manage supply-chain and third-party risks associated with external providers.
- SA-9noneimplements — Both controls require organizations to define security responsibilities, obtain assurance, and manage risks when relying on external service providers for information processing.
Aligned NIST CSF 2.0 outcomes (15)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-02partialaligns with — Defining and communicating roles and responsibilities between the organization and cloud providers satisfies the CSF outcome of establishing coordinated cybersecurity roles for suppliers.
- GV.SC-06partialaligns with — The ISO control’s emphasis on pre-acquisition review of cloud agreements and risk assessments mirrors the CSF outcome of performing due diligence before entering supplier relationships.
- GV.SC-10partialaligns with — The ISO control’s requirement for exit strategies and continued support after termination of cloud services matches the CSF outcome of including post-contract provisions in supply-chain risk plans.
- ID.RA-10partialaligns with — The ISO control requires assessment of cloud service providers prior to use, which aligns with the CSF outcome of assessing critical suppliers before acquisition.
- GV.SC-01noneimplements — The ISO control establishes a dedicated program, policies, and processes for managing cybersecurity risks arising from cloud service providers, which directly fulfills the CSF outcome of creating a supply-chain risk management program.
- GV.SC-05noneimplements — By requiring the organization to define security requirements, responsibilities, and controls in cloud service agreements, the ISO control satisfies the CSF outcome of embedding cybersecurity requirements into supplier contracts.
- GV.SC-07noneimplements — The ISO control mandates risk assessments, residual-risk acceptance, and ongoing monitoring of cloud providers, aligning with the CSF outcome of understanding, recording, and prioritizing supplier risks.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (8)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1357partialprevents — Cloud-service security partially overlaps when the untrusted component is cloud-hosted.
- CWE-200partialprevents — Requiring the provider to store and process sensitive data only in approved jurisdictions and to meet confidentiality objectives reduces the probability that data is disclosed to unauthorized parties through mis-configured storage or inadequate isolation.
- CWE-284partialprevents — Explicitly assigning which party manages each access-control mechanism and requiring the provider to enforce the customer's access requirements reduces the chance that authorization decisions are omitted or left to default permissive settings.
- CWE-285nonenone — Defining the split of authorization responsibilities and mandating that the provider implement the customer's security requirements limits the likelihood that an actor can perform actions outside its intended privilege scope.
- CWE-522nonenone — Requiring the provider to implement access-control mechanisms that satisfy the customer's security requirements lowers the likelihood that credentials or tokens protecting cloud resources remain weakly protected or transmitted in clear text.
- CWE-673nonemitigates — Cloud-service governance limits external providers from redefining organizational control spheres.
- CWE-732nonenone — Mandating that the provider manage access controls and meet the customer's permission requirements decreases the chance that cloud resources are created or left with overly permissive default or inherited permissions.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1078.004mostlymitigates — Defining and enforcing which party manages authentication and access controls for cloud accounts limits an adversary’s ability to abuse legitimate cloud credentials for stealthy access.
- T1530mostlyprevents — Mandating contractual controls on data location, encryption, and access restrictions directly constrains an attacker’s capacity to collect data stored in cloud object storage without detection.
- T1199partialmitigates — Requiring explicit assignment of security responsibilities and access-control obligations between the organization and cloud providers reduces the likelihood that an adversary can leverage a trusted third-party relationship to gain initial access.
- T1087.004nonemitigates — Requiring the organization to specify and monitor account-discovery permissions in cloud service agreements reduces the attacker’s ability to enumerate cloud identities and map the target environment.
- T1526nonemitigates — By forcing the organization to define allowable cloud services and continuously review their configurations, the control shrinks the attack surface an adversary can probe when performing cloud-service discovery.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02mostlyprevents — Defining which security controls are handled by the provider versus the customer and requiring explicit review of cloud agreements reduces the chance that default or mis-tuned settings will be left in place.
- A03partialmitigates — Mandating risk assessments, exit strategies, and assurance on provider controls limits exposure to compromised or malicious components introduced through the cloud supply chain.
- A07noneprevents — Requiring the cloud agreement to address access-control responsibilities and the organization to verify their implementation helps ensure authentication and authorization mechanisms are neither omitted nor misconfigured.
- A09nonemitigates — Specifying incident-handling procedures and evidence-gathering support in the cloud contract improves the organization’s ability to detect, log, and respond to security events occurring in the provider environment.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.