Specify, implement and manage information security controls for cloud service acquisition, use, management and exit.
Also written as A5.23, Annex A 5.23, ISO 27001:2022 A.5.23, ISO27001 A.5.23.
Information security for use of cloud services is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Specify, implement and manage information security controls for cloud service acquisition, use, management and exit. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.
When preparing your Statement of Applicability (SoA) for A.5.23, gather artefacts such as:
What actually gets raised against A.5.23, in rough order of how often it comes up:
A.5.23 is new in ISO 27001:2022. Excluding it requires demonstrating you use no cloud services whatsoever, which is now rare enough that auditors treat the exclusion with scepticism. If you are cloud-hosted, expect this control to be sampled in depth, and expect it to be read alongside A.5.19 to A.5.22 on supplier relationships.
If you run more than one framework, the same evidence usually satisfies all of them. A.5.23 aligns with:
SOC 2: CC6.7 Protection of data in transmission and movement, CC9.2 Vendor and business partner risk
NIST CSF 2.0: GV.SC-05 Supply chain requirements in contracts, GV.SC-06 Due diligence before supplier relationships, ID.AM-04 Supplier-provided asset inventory
A.5.23 is a new control introduced in the 2022 revision with no direct 2013 equivalent. Treat it as a fresh requirement when transitioning from ISO 27001:2013.
See all 37 Organisational Controls →
Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.23 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.
In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.
ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.
A.5.23 aligns with SOC 2 CC6.7, CC9.2 and NIST CSF GV.SC-05, GV.SC-06, ID.AM-04. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.
Yes. A.5.23 is one of the 11 controls introduced in the 2022 revision and has no direct ISO 27001:2013 equivalent, so a transitioning ISMS has no prior evidence to re-point and should treat it as a fresh implementation.
A cloud register that lists the three big platforms and none of the dozens of SaaS tools individual teams have bought. A shared-responsibility matrix copied from a provider marketing page without mapping it to how the organisation actually uses the service.