"5.23 Information Security for Cloud Service Usage"
"Processes for procuring, using, managing, and terminating cloud services must be established in accordance with the organization's information security requirements."
We also use a lot of cloud services, but we need to develop usage selection criteria, application and approval flows, account management, and systems in the event of an incident.
Even before the standard revision, account management was a mandatory requirement, so there were not many changes, but I would like to introduce that it is being implemented for reference.
Start of Use Application and Approval Flow
Use our service "Colorkrew Workflows" to apply for the start of using cloud services.
In this case, the application requires the submission of a security check sheet that defines the criteria for using the service.
The approver is the department management manager under the ISMS system and checks the security check sheet. "Colorkrew Workflows" can export application and approval data, so it will be left as a trail.
Account Management
Not limited to cloud services, account management is also always checked in the review.
This also aggregates the approval flow in "Colorkrew Workflows" so that a trail is left.
One point that is often overlooked is the flow at the end of use.
In some cases, it may be left unattended without appropriate action at the end of use, so decide in advance what to do at the end of use.
I try to do regular inventory.
"5.30 ICT Preparation for Business Continuity"
"Organizations must plan for ways to maintain an appropriate level of information security in the event of business disruption or disruption."
Originally, there was a request for BCP, but it is necessary to make a plan limited to ICT.
For example, define the response flow in the event of a failure of a cloud service or office IT equipment.
In addition, we regularly conduct education and training on the response flow for each department and leave evidence of this.
Evacuation drills, alternative machine operation in the event of WiFi equipment failure, or restoration in the event of cloud storage failure may be considered.
"7.4 Physical Security Monitoring"
"Facilities must continuously monitor for unauthorized physical access."
I think that security such as office building equipment, surveillance cameras, and admission passes is implemented by all companies.
It is necessary to understand the specifications again and check whether you can refer to the records of the surveillance cameras.
8.9 Configuration Management
"Configurations must be established, documented, implemented, monitored, and reviewed, including hardware, software, services, and network security configurations."
We organized the infrastructure and middleware configuration of each system and reviewed it regularly.
This information is also important for understanding vulnerabilities, so we held regular MTGs to prevent them from becoming a formality, and kept the minutes of the meetings as evidence.
Evaluation During Screening
There was no problem by submitting the above application and approval data and actual operation status as evidence.
Regarding regular reviews such as configuration management, it seems important to always review and keep a trail of so-called changes in the introduction and update of the system.
We have introduced up to 5 of the 11 management measures. See you next time.