BSI C5 Cloud Compliance – Strengthening security and trust in cloud services
The BSI C5 (Cloud Computing Compliance Criteria Catalogue) sets forth the minimum information security requirements for cloud services.
It focuses on the following service models:
- Infrastructure as a Service (IaaS)
- Platform as a Service (PaaS)
- Software as a Service (SaaS)
Cloud and SaaS providers undergo a C5 audit in order to increase the information security of their cloud services for their business partners and customers, and to secure a decisive competitive advantage based on a standardised audit.
A BSI C5 certification can be carried out as an adequacy assessment at a defined point in time or as a performance audit over a defined test period.
The objective of the adequacy assessment is to assess
- whether the description of the cloud service provided (to be prepared by the legal representatives of the company) was prepared in all material respects in accordance with the minimum content contained in the auditing standard and
- whether the measures presented in the description of the cloud service and to be implemented by the legal representatives were appropriate in all material respects and were implemented at the time of the audit.
The aim of the performance audit – over and above the adequacy test – is to assess whether these measures were suitable, implemented in the audited time period and effective in the audited time period.
BSI C5 audits are carried out in accordance with the German auditing standard IDW PS 860 "IT Audit outside the Audit of Financial Statements" of the Institute of Public Auditors in Germany (IDW) and the IDW Audit Guidance "Auditing of Cloud Services" (IDW PH 9.860.3 n.F. ). The last one is in accordance with the "International Standard on Assurance Engagements" (ISAE) 3000 (Revised).
We advise you:
We support you from the initial BSI C5 audit (adequacy assessment, type 1) through to the performance audit (type 2). We help you safeguard your processes and coach you throughout the project until successful implementation is complete.
Our compliance audits are carried out by experienced IT and business auditors who will issue a recognised BSI C5 certificate and provide you with long-term, personalised support.
We have in-depth team experience in C5 certifications as well as system and process audits (ICS, ISAE 3402) and the initial establishment of suitable controls (ICS) at data centres, SaaS providers, service providers and software manufacturers.
Benefit from our comprehensive BSI C5 expertise, proven best-practice approaches and an experienced project team that will make your cloud services secure and transparent.
Want to learn more?
The BSI C5:2020 criteria catalogue for Infrastructure as a Service (IaaS) covers 17 subject areas:
- Organisation of Information Security (OIS)
- Safety guidelines and work instructions (SP)
- Personnel (HR)
- Asset Management (AM)
- Physical security (PS)
- Regular operation (OPS)
- Identity and authorisation management (IDM)
- Cryptography and key management (CRY)
- Communication security (COS)
- Portability and interoperability (PI)
- Procurement, development and modification of information systems (DEV)
- Control and monitoring of service providers and suppliers (SSO)
- Handling security incidents (SIM)
- Business continuity and contingency management (BCM)
- Compliance (COM)
- Dealing with investigative questions from government agencies (INQ)
- Product safety (PS)
Within these areas, 121 criteria are listed with detailed requirements to be fulfilled, e.g.
- Information security guidelines
- Rules for access control and authentication
- Requirements for data encryption at rest and in transit
- Processes for incident response and disaster recovery
- Guidelines for planning and conducting audits
- Redundancy models
- Concept for handling metadata during logging and monitoring
- Documentation and verification for audits
Compliance with the BSI C5 criteria catalogue is certified by auditors and demonstrated to customers in a transparent manner. In this process, the cloud or SaaS provider commissions the auditors directly. The audit report contains detailed documentation of the audit procedures carried out and a description of the cloud service provided, which clearly outlines the security measures implemented by the provider.
If the cloud provider is not yet certified according to BSI C5 and is contractually obliged to have this certification, for example in a tender, we recommend initially carrying out a project-specific adequacy assessment according to type 1, checking the minimum criteria.
Once all measures have been implemented, the period for a possible performance test begins, which usually covers a period of at least 6 to a maximum of 12 months. Depending on the degree of maturity and the required security level, it is also advisable to expand the assessment by applying the additional criteria.
In practice, cloud providers often use their own subcontractors when providing their services – for instance for hosting or housing partners for data centre operations as well as strategic partners such as AWS, Azure, Google Cloud or the Open Telekom Cloud. For C5 certifications, a precise and comprehensible delineation of responsibilities is essential. Subcontractors can be treated according to the carved-out method, for example.
Monitoring is carried out in accordance with the BSI C5 controls for supplier security and outsourcing (SSO) via regular verification checks (e.g. verification using our own C5 or ISAE 3402 test certificates and ISO reports) and the resulting risk assessments.
This can result in synergies thanks to an optimised audit process and smart delimitation, which can significantly reduce the work required for the audit. We would be happy to advise you on this.
Example:
The BSI C5 criteria area "Physical security (PS)" is not part of the legal representative's description (and is not included in the audit) because this is exclusively the responsibility of the data centre operators used.
The security requirements for premises and buildings relating to the cloud or SaaS service provided can be verified by the data centre operator by means of its own C5 certificate (type 2) in accordance with the requirements of C5: PS-01-07.
Appropriate and effective verification of implementation can be carried out in accordance with a supplier management guideline (C5: SSO-01 and SSO-02).
Deviations from the audit criteria are assessed and dealt with individually as part of risk management. Suitable escalation and remediation processes are defined.