1 Scope
This document surveys aspects of the audit of cloud services including:
-
role and responsibilities of parties conducting audit and description of the interactions between the CSC, CSP, and CSN;
-
approaches for conducting audits of cloud services to facilitate confidence in delivering and using cloud services;
-
examples of available frameworks and standards which can be used for audit schemes, for certification , and for authorization .
This document builds upon the cloud auditor role as defined in ISO/IEC 17789 and ISO/IEC 22123.
This document is applicable to all types and sizes of organizations that need to plan
and conduct internal or external audits , and that use, provide and support cloud services.
This document is not intended to describe certification or to identify controls that are published elsewhere.