Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Learn more about the connected frameworks

No items found.

Other tasks from the same security theme

Process for removal or return of customer assets after cloud service agreement cancellation

Critical
High
Normal
Low

Cloud service provider should be prepared for customers requesting a documented description for the process of return and removal of the customers assets in the event of service termination. This description should include:

  • Detailed procedure for asset return to customer
  • Deletion of all copies of customers data and assets
  • List of all customer assets
  • Schedule for termination of service process

Cloud service providers must also actively provide the information about the arrangements for removal and return of assets of the cloud service customer (e.g. in terms of service or other service agreement).

8: Asset management
ISO 27017
CLD 8.1: Responsibility for assets
ISO 27017
CLD 8.1.5: Removal of cloud service customer assets
ISO 27017

Describing customer's data rights in terms of the agreement

Critical
High
Normal
Low

The contract terms for offered digital services must include provisions for service provider on ways in which customer will receive their data at the end of the contract. Provisions must include at least:

  • Possible forms of data export or delivery
  • Data retention period
  • The extent of the data available to the customer
  • Data destruction policies and times
No items found.

Using encryption when downloading data

Critical
High
Normal
Low

The organization has to use encrypted and standardized network protocols when managing, downloading and uploading data.

No items found.

Application interfaces for downloading information in offered digital services

Critical
High
Normal
Low

The customer must be provided with interfaces that allow them to download the data they manage to transfer it to another cloud service, for example.

No items found.

Ensuring compatibility and data portability in offered digital services

Critical
High
Normal
Low

The organization must maintain measures for ensuring compatibility and portability of data in offered digital services. The measures should include definition of requirements for the following:

  • Supported interfaces
  • Interoperability of data processing
  • Portability of source code
  • Portability of data
No items found.