C.6 Cloud Service Provider Management Policy

Version: April 2025
Applies to: All employees, contractors, and third-party partners
Aligned with: ISO/IEC 27001:2022 & ISO/IEC 27017

Purpose
To ensure that all cloud services used by the organization meet strict cybersecurity, data protection, and operational standards through structured selection, onboarding, and ongoing oversight.

1. Scope
Covers:
- All cloud service models (SaaS, PaaS, IaaS)
- All cloud-related accounts and services
- Internal staff and external partners using or managing cloud-based infrastructure or tools

Mandatory for all cloud engagements — exceptions require formal approval.

2. Core Requirements for Cloud Services

ID Requirement
CSP-01 Maintain a current list of approved cloud providers (CSPs)
CSP-02 Track each approved service within each CSP
CSP-03 Maintain a list of approved SaaS vendors
CSP-04 Track all user accounts provisioned across CSPs and SaaS
CSP-05 Maintain baseline security configuration standards for all CSPs
CSP-06 Maintain security benchmarks per service within each CSP
CSP-07 Apply security baselines to SaaS platforms as well
CSP-08 Operate a cloud vulnerability management system to scan CSP/SaaS
CSP-09 Use a Data Loss Prevention (DLP) solution to log and alert on CSP/SaaS data events
CSP-10 Ensure logging is enabled within each authorized CSP/SaaS
CSP-11 Ensure cloud logs are centralized in a log management system

3. Non-Compliance & Sanctions
Breaches may result in:
- Refresher training
- Temporary suspension of access
- Termination of employment or third-party contracts
- Legal actions where applicable

All enforcement actions are subject to internal HR and legal review processes.

Direct URL: