Guidance
Cloud security guidance
How to choose, configure and use cloud services securely.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 17 of 29
A governance framework is vital to co-ordinate and direct the management of the service.
An effective governance framework will ensure that procedural, personnel, physical and technical controls continue to work through the lifetime of a service. It should also respond to changes in the service, technological developments, and the appearance of new threats.
You should be confident that the service has a governance framework and processes which are appropriate for your intended use.
There are some common security standards that include controls covering how well a governance framework risk-manages a particular service. These include CSA CCM v3.0.1, SOC2, and ISO/IEC 27001. Note that standards differ in the level of detail that they cover. You should seek evidence of independent certification against such standards and ensure that the scope covers the goals that are set out above.
Services subject to GDPR may be able to use evidence provided to demonstrate compliance with the accountability data protection principle for some of the points above. The service provider’s GDPR Data Protection Officer will sometimes be the board representative who is responsible for the security of the cloud service.
A service provider may instead assert that the 4 goals above are met, providing evidence of an independent audit of the claims made. As with all service provider assertions, you will need to decide whether you are content with the level of confidence this gives you.


