What are the common ISO standards related to cloud computing?
ISO is a non-governmental international organization that publishes documents and raises awareness for standards in various topics and, in the context of this book, standards related to information security and cloud services.
ISO/IEC 27001 standard
The ISO/International Electrotechnical Commission (IEC) 27000 standard is the most widely used standard for ISM. Though it is not cloud-specific, it is considered the most fundamental standard for cloud service providers (CSPs), and it sets a solid foundation for any cloud provider, from a hyper-scale cloud provider to a small SaaS provider.
The ISO 2700x is split into the following sections:
- ISO/IEC 27000:2018 provides an overview of ISM systems (ISMS).
- ISO/IEC 27001:2013 is a standard for ISM.
- ISO/IEC 27002:2013 specifies best practices for ISM.
The ISO 27001 is made of the following domains:
- Information Security Policies
- Organization...