التفاصيل

Cloud service information security management system certification

ISO/IEC 27017:2015

01

مقدمة الخدمة

Cloud service information security management system certification is an authoritative evaluation mechanism for cloud service providers and cloud service customers to establish, implement and maintain cloud security full control capability, aiming at ensuring data security, privacy protection and compliance operation in the cloud environment through a standardized framework. This certification is mainly based on the international standard ISO/IEC 27017:2015 "Information Technology Security Technology Practice Guide for Information Security Control of Cloud Services Based on ISO/IEC 27002". This standard is an extension of cloud services based on ISO/IEC 27001 information security management system, with seven new cloud-specific control measures (CLD) and 37 cloud-based implementation guides. The certification is finally awarded to the organization with a certificate valid for three years, and is usually jointly reviewed with ISO/IEC 27001 and issued with a comprehensive certificate.

Certification core content

The certification of information security management system of cloud services revolves around the particularity of cloud environment, and the core inspection is as follows:

Basic information security management system: Establish a complete information security management system (ISMS) according to ISO/IEC 27001, including organizational environment analysis, leadership role and commitment, information security policy, risk assessment and disposal, resource guarantee, internal audit and management review, and continuous improvement mechanism.

Cloud-specific control measures (7 new controls): division of roles and responsibilities between cloud service providers and customers; asset removal/return management at the end of the contract; protection and isolation of customers' virtual environment; virtual machine configuration; management operations and procedures related to mirror management of cloud environment; authority and mechanism for cloud customers to monitor activities in the cloud; docking and security protection of virtual and cloud network environment -4-9

Shared responsibility model management: clearly define the responsibility boundary between cloud service providers and customers in security, including data protection, access control, vulnerability management, compliance obligations, etc.

Life cycle security of cloud services: service design and delivery security supply chain security management security clauses in contracts and service agreements, service backup and disaster recovery, service termination and data migration security.

Multi-tenancy and virtualization security: ensure data isolation, resource isolation and network isolation between different customers and prevent cross-tenant attacks.

Customer data protection: data encryption (static, in transit), privacy protection, access control, authentication, data retention and destruction mechanism.

Operational security control: security incident management (detection, response and reporting) business continuity and disaster recovery compliance audit and logging continuous monitoring of security situation.

Certification process

Cloud service information security management system certification is usually divided into the following stages:

Pre-preparation stage: the enterprise must first pass the ISO/IEC 27001 information security management system certification or establish a management system that meets the dual requirements of ISO/IEC 27001 and ISO/IEC 27017. The system has been in operation for more than 3 months and has completed at least one internal audit and management review.

Application and acceptance: submit application materials (business license, system documents, applicability statement SoA, risk assessment report, internal audit/management review records, etc.), and the certification body will conduct application review to confirm that the organization has the basic conditions for certification (it has not been subject to administrative punishment within one year).

The first stage audit (document audit): review the compliance of system documents with ISO/IEC 27001 and ISO/IEC 27017 standards, check the responsibility sharing matrix, the design of cloud-specific control measures, the coverage of risk assessment, etc., and confirm the adequacy of the second stage audit preparation.

Audit in the second stage (on-site audit): conduct on-site audit, including personnel interview, file record inspection, on-site inspection of cloud platform/data center, effectiveness verification of security control measures (such as access control, encryption mechanism, monitoring logs, isolation measures, etc.), evaluate the compliance and effectiveness of the system, and identify nonconformities.

Rectification and review: for the nonconformities found in the audit, the organization shall complete the rectification within the specified time limit and submit the evidence, which will be reviewed by the audit team.

Certification decision and certification: Certification certificate will be issued after the technical review, which confirms that the organization meets the requirements of ISO/IEC 27001 and ISO/IEC 27017 standards. The certificate is valid for three years and can be found on the website of CNCA.

Supervision and audit: conduct supervision and audit once a year after obtaining the certificate (the interval shall not exceed 12 months) to confirm that the system continues to meet the certification requirements.

Re-certification audit: Re-certification audit is conducted before the certificate expires, and the certification qualification is extended, usually for three years.

Certification value

Enhance customer trust and satisfaction: ISO 27017 certification is an internationally recognized cloud security standard. Certified enterprises can prove that they are in line with international best practices in providing cloud services, have the ability to protect customer data and privacy, and significantly enhance customer confidence.

Enhance market competitiveness: Certification can get extra points in bidding, especially in high-sensitive industries such as government cloud, financial cloud and medical cloud, which has become a key threshold for suppliers to enter; Help enterprises connect with international standards and expand overseas markets.

Reduce security risks and costs: the system identifies and manages information security risks in cloud services, and establishes a sound risk assessment and emergency response mechanism to reduce the possibility of security vulnerabilities and attacks, thus reducing related costs and losses.

Meet the requirements of laws and regulations: help organizations meet the requirements of domestic and foreign laws and regulations such as Network Security Law, Data Security Law and GDPR, and reduce legal risks and fines caused by data leakage or violation.

Clear responsibility boundary: ISO 27017 standard clarifies the roles and responsibilities of cloud service providers and customers in data security to avoid security loopholes and disputes caused by unclear responsibilities.

Enhance brand reputation: reduce the negative publicity risk caused by data leakage and establish a good brand image through sound data protection control.

Promote business expansion: certification provides general guidelines covering different countries, which facilitates enterprises to conduct business on a global scale and obtain opportunities as preferred suppliers.

additional remarks

Prerequisites: ISO 27017 is a supplementary standard based on ISO 27001. Before carrying out ISO 27017 certification, enterprises need to obtain ISO 27001 certification or accept joint audit simultaneously.

Joint certification: Most certification bodies provide ISO 27001+ISO 27017 joint audit services, which can reduce the number of repeated audit days and improve certification efficiency.

Applicability of certification: certification does not certify the specific products or functions of cloud services, but rather recognizes the information security management system of cloud services itself, indicating that the organization has established internationally recognized good cloud security management practices.

Validity period and maintenance: the certificate is valid for three years, and the certified enterprise needs to be supervised and audited every year, re-certified after three years, and use the certification certificate and logo correctly according to the regulations.

03

عملية الخدمة

04

ملف القواعد

هل تحتاج إلى هذه الشهادة؟

اتصل بنا