# Cloud services and outsourcing policy

Source: https://aestech.com.au/policy-templates/#cloud-and-outsourcing-policy
Markdown URL: https://aestech.com.au/policy-templates/cloud-and-outsourcing-policy.md

Use for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how cloud services and outsourced functions are selected, approved, operated and exited, so that the company retains control over its information and obligations when work or data is placed with an external provider.

2. Scope
This policy applies to all cloud services, including infrastructure, platform and software as a service, and to any outsourced business or technology function that processes company or customer information or supports critical operations.

3. Policy statements
- New cloud services and outsourcing arrangements must be approved by the [Security Lead or IT Manager] before company data is placed in them, and unapproved services must not be used for company work.
- Due diligence proportionate to the risk tier must be completed before approval, covering security posture, certifications or assurance reports, data protection terms, subcontractors, incident notification commitments, financial viability and support arrangements.
- Data residency must be confirmed before approval, and services storing regulated or customer data must keep it in [approved regions] unless an exception is approved.
- A shared responsibility mapping must be documented for each significant cloud service, recording which security controls the provider operates and which the company must operate, such as identity, access, configuration, backup and monitoring.
- Contracts must include confidentiality, security requirements, breach notification within [x] hours, audit or assurance rights appropriate to the service, and data return or deletion on termination.
- Each approved service must have a named business owner and must be recorded in the cloud services register.
- Company-managed controls on cloud services, such as MFA, least privilege access and logging, must be configured before production use.
- An exit strategy must be documented for critical services, covering data export formats, migration options, notice periods and how long an exit would take.
- Services must be reviewed on a cadence matched to their risk tier, and on contract renewal, major changes or provider incidents.

4. Roles and responsibilities
- The [Security Lead] sets the assessment standard, performs or reviews due diligence and approves exceptions.
- Business owners justify the need, own the relationship and initiate reviews and offboarding.
- IT configures company-managed controls and manages access.
- Legal or the contract owner ensures required terms are in place.

5. Procedures
- Request approval for a new service through [ticketing system] with the intended data types and users.
- Complete the due diligence checklist and assign a risk tier.
- Record the service, owner, data types, residency and responsibility mapping in the register.
- Review critical services at least annually, and confirm assurance reports remain current.
- On exit, export data, confirm provider deletion in writing and remove integrations and access.

6. Evidence and records
Keep the cloud services register, due diligence records, assurance reports, contracts and data processing terms, responsibility mappings, review records, exception approvals, exit plans and deletion confirmations.

7. Review cadence
This policy is reviewed at least annually and after material changes to providers, regulations or company data flows.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md