Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.5.23 Information Security for Use of Cloud Services

Control Objective

Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organisation’s information security requirements.

Policy Statement

anDREa governs the entire lifecycle of cloud services—including acquisition, daily operations, and eventual exit—in strict alignment with our information security and data protection standards.

Compliance with ISO/IEC 27001, NIS 2, and GDPR is maintained by enforcing rigorous pre-onboarding risk assessments, defining shared responsibility models, and ensuring secure, validated data sanitization upon contract termination.


Cloud Lifecycle Management Process

1. Acquisition and Risk Assessment

Before onboarding any Cloud Service Provider (CSP), a formal risk assessment and supplier review are conducted to evaluate:

  • Compliance Posture: Verification of mandatory security certifications (e.g., ISO/IEC 27001, SOC 2 type II) and regulatory alignment (e.g., GDPR, NIS 2).
  • Technical Controls: Evaluation of data encryption architectures (at rest and in transit), robust access management, disaster recovery capabilities, and incident response readiness.
  • Data Residency: Assurance that data storage and processing locations adhere to strict jurisdictional and organizational residency requirements.

2. Contractual Agreements & Shared Security Models

Cloud contracts must explicitly outline security and operational boundaries, ensuring:

  • Shared Responsibility Matrix: Clear demarcation of security duties between the CSP and anDREa.
  • Service Level Agreements (SLAs): Defined expectations for service availability, uptime guarantees, and incident notification timelines (see: Service Level Agreement).
  • Data Sovereignty: Unambiguous ownership of all data by anDREa throughout the service lifecycle (see: myDRE Highlevel Architecture).

3. Secure Cloud Usage and Operations

Authorized users and administrators must manage cloud environments in accordance with internal security baselines:

  • Identity and Access Management: Implementation of stringent access controls, universally enforced via Multi-Factor Authentication (MFA).
  • Data Protection: Classification-based storage rules combined with mandatory encryption for all sensitive assets.
  • Logging and Auditing: Centralized logging and continuous monitoring to promptly identify anomalies, unauthorized access attempts, or infrastructure changes.
  • Resilience: Regular execution of independent backup procedures to ensure rapid data restoration in the event of a provider-level incident or disaster.

4. Cloud Exit Strategy

To prevent vendor lock-in and ensure compliance during decommissioning, anDREa maintains an exit plan for all critical cloud services:

  • Data Migration: Defined protocols for the secure, verified retrieval of all assets in a standard, readable format.
  • Data Sanitization: Contractual mandates requiring the CSP to securely delete and purge all copies of anDREa data from their infrastructure.
  • Formal Confirmation: Requirements for a formal, timed confirmation from the provider certifying successful data deletion.

Training and Awareness

All employees managing or operating within cloud environments receive continuous training on secure cloud configurations, data handling guidelines, and emerging cloud-specific security risks (see: Training).