Overview
ISO/IEC 22123-3:2023 specifies the Cloud Computing Reference Architecture (CCRA). This international standard defines a structured, vendor-neutral reference architecture for cloud computing, including viewpoints, layered functional models, defined roles and activities, and a catalogue of cross-cutting aspects such as security, privacy and service levels. ISO/IEC 22123-3:2023 replaces ISO/IEC 17789:2014 and is part of the ISO/IEC 22123 series (see also Parts 1 and 2 for vocabulary and concepts).
Key topics and requirements
The standard organizes the CCRA into clear viewpoints and technical building blocks:
- Viewpoints and architectural views: user view, functional view, implementation view and deployment view to support different stakeholder perspectives.
- Roles and parties: formal differentiation of cloud stakeholders (for example Cloud Service Customer, Cloud Service Provider and Cloud Service Partner) and associated roles/sub-roles and activities.
- Layered functional architecture: defined functional layers including User, Access, Service, and Resource layers plus multi-layer functions and a layering framework.
- Functional components and capabilities: catalogues of components (e.g., service capabilities) and how they map to user roles and activities.
- Cross-cutting aspects: requirements and considerations for security, privacy / PII protection, auditability, governance, interoperability, portability, reversibility, performance / KPIs, maintenance & versioning, and service levels / SLAs.
- Relationships and mappings: how the user view maps to the functional view (including multi-tenancy and isolation).
- Normative references: aligns with ISO/IEC 22123-1 (vocabulary) and ISO/IEC 22123-2 (concepts) and references architecture and privacy standards such as ISO/IEC/IEEE 42010 and ISO/IEC 29100.
Practical applications - who uses this standard
ISO/IEC 22123-3 is intended for:
- Cloud architects and solution designers - to create consistent, standards-based architectures.
- Cloud service providers and operators - to structure offerings, define capabilities, and demonstrate compliance with standard architectural practices.
- Enterprise IT, cloud service customers and procurement teams - to evaluate vendors, define SLAs, and ensure interoperability and portability.
- System integrators and implementers - to map functional components into concrete deployments.
- Auditors, regulators and risk managers - to assess governance, security, privacy and auditability aligned with accepted architecture principles.
Related standards
Keywords: ISO/IEC 22123-3:2023, Cloud Computing Reference Architecture, CCRA, cloud architecture, cloud roles, interoperability, portability, cloud security, SLAs.