|
+PS-01.05B |
1. ÜbersichtPS-01.05BIf the cloud service provider operates the cloud service in data centres operated by service organisations, the document describes:1. The complementary subservice organisation controls (CSOC) expected at the service organisations; and 2. The measures for monitoring the design and operation of controls at the service organisations with respect to these CSOC (cf. SSO-05). Incorrect planning can endanger the operational safety and availability of the premises or buildings. This can result from an incorrect assessment of elementary hazards at the site (e.g. air traffic, earthquakes, floods, hazardous substances) as well as an incorrect conception of the bandwidth or energy supply. Premises and buildings related to the cloud service provided include data centres and server rooms housing system components used to process cloud service customer data (including data centres for backup or redundancy purposes) and the technical utilities required to operate these system components (e.g. power supply, refrigeration, fire-fighting, telecommunications, security, etc.). Premises and buildings in which no data from cloud service customers is processed or stored (e.g. offices of the cloud service provider, server rooms with system components for internal development and test systems) adhere to requirements specifically covered under PS-08. Premises and buildings operated by third parties are e.g. server housing, colocation, IaaS.
1.1 Referenzen1.2 Identifizierte Anforderungen1.2 Related Regulation2. Identifizierte Anforderungen
3. Related Regulations
|