|
Work item:
|
X.1631
|
|
Subject/title:
|
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
|
|
Status:
|
Approved on 2025-12-11 [Issued from previous study period]
|
|
Approval process:
|
TAP
|
|
Type of work item:
|
Recommendation
|
|
Version:
|
Rev.
|
|
Equivalent number:
|
ISO/IEC 27017 (Common)
|
|
Timing:
|
-
|
|
Liaison:
|
ISO/IEC JTC 1/SC 27/WG 1
|
|
Supporting members:
|
-
|
|
Summary:
|
This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
— additional guidance for relevant controls specified in ISO/IEC 27002:2022;
— additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for CSCs and CSPs.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments
|
|
Comment:
|
-
|
|
Reference(s):
|
|
|
Historic references:
|
|
Contact(s):
|
|
| ITU-T A.5 justification(s): |
|
|
|
|
First registration in the WP:
2024-03-12 14:25:33
|
|
Last update:
2026-01-14 14:16:54
|