How to vet a cloud provider under ISO 27001
Fourteen questions to ask a cloud provider during selection. Which answers are acceptable, which should stop the deal.
2 min read
TL;DR
14 key questions to vet a cloud provider during ISO 27001 selection. Acceptable answers and the ones that should stop the deal.
The 14 questions
Certifications and governance
- Do you hold ISO 27001:2022, 27017, 27018, 9001? Can you show me the certificates?
- Acceptable: all 4 with consistent scope.
- Stop: less than 27001 + 27017.
- Which certification body? When was the last audit?
- Acceptable: accredited body (TÜV, DNV, Bureau Veritas) and audit within 12 months.
- Stop: non-accredited body, audit > 18 months.
- Do you have a published security policy?
- Acceptable: PDF available or public summary.
- Stop: generic refusal.
Datacentre and operations
- Where are the datacentres physically?
- Acceptable: Italy or EU with explicit declaration.
- Stop: extra-EU without SCCs or EU-US DPF.
- Who controls the operating company?
- Acceptable: EU corporate registration.
- Stop: undisclosed non-EU control.
- Support staff and SOC?
- Acceptable: Italian or EU, trained.
- Stop: extra-EU outsourcing without disclosure.
Business continuity
- RTO and RPO documented in your SLAs?
- Acceptable: yes, contract.
- Stop: only "best effort".
- Off-site backup frequency? Integrity verification?
- Acceptable: every N hours + automatic verification.
- Stop: unverified backup.
- How often do you drill your DR?
- Acceptable: quarterly or more often.
- Stop: generic annual, undocumented.
Technical security
- At-rest encryption? In-transit?
- Acceptable: AES-256 + TLS 1.3.
- Stop: none or only at-rest.
- Key management? HSM?
- Acceptable: HSM or dedicated KMS.
- Stop: manually managed keys.
- MFA? For all accounts or admins only?
- Acceptable: all, at least recommended.
- Stop: admin only.
Incident handling
- Customer notification procedure?
- Acceptable: written SLA (e.g. 4-24h).
- Stop: no written commitment.
- Sub-suppliers? Who and what?
- Acceptable: transparent list.
- Stop: refusal to disclose.
Selection workflow
- send the questionnaire to the provider (max 1 week to respond);
- evaluate responses: 12 of 14 green = OK; 2 red = stop;
- request proof (certificates, drill logs);
- sign only after all 14 are covered.
FAQ
The provider refuses to answer 14 questions, what to do?
Switch providers. A serious cloud provider responds in 2-3 days.
Can I accept a provider with limited certification scope?
Only if the scope covers the specific service you will buy. Verify.
For the continuity cluster guide, ISO 27001:2022 and continuity. For ISO comparison, ISO 27001 vs 27017 vs 27018.
Want to see Sefthy in action?
Same IP, same subnet, RTO in minutes. Try it free for 7 days or talk to one of our specialists.