+OIS-08.01B

1. Übersicht

OIS-08.01B

The cloud service provider performs the risk management process specified by OIS-07 as needed and at least annually.

This criterion applies only to risks that reside within the area of responsibility of the cloud service provider. Risks that arise for the cloud service customer when using the cloud service are not covered by this criterion. When outsourcing activities for the provision of cloud services to service organisations, the responsibility for these risks remains with the cloud service provider. Requirements for measures to manage these risks can be found in the criteria area 'Control and Monitoring of Service Providers and Suppliers (SSO)'.

Cloud service providers may leverage established risk management standards, such as ISO 27005 or the ISO 31000 family of standards to address risks related to the cloud service. Risk management procedures already implemented at the cloud service provider may be leveraged for OIS-08 where possible to reduce redundancies. Documentation of risks, treatment plans and risk acceptance in the sense of this criterion does not require specific formal frameworks; lean forms of documentation can be leveraged wherever appropriate to address the OIS-08 subcriteria.

Examples of scenarios in which the risk management process may be executed 'as needed' include, but are not limited to, the following:

1. Changes to the threat landscape (cf. OIS-05);
2. Security incidents or business disruptions;
3. Changes to the cloud service provider's legal, regulatory, self-imposed and contractual requirements relevant to the information security of the cloud service (cf. COM-01);
4. Changes to the cloud service provider's organisational structure with impact on roles, responsibilties or procedures for provisioning the cloud service;
5. Changes to the achitecture of the cloud service (cf. OPS-31);
6. Events related to the cloud service provider's service organisations (cf. SSO-05);
7. Exceptions to policies or procedures (cf. SP-03); and
8. Identification of critical vulnerabilities (cf. OPS-22) or compliance deviations (cf. COM-03).
Bezeichnung Standard

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.2 Related Regulation

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Regulations

Regulations
Source Regulierung
Impressum