A security architect is reviewing certifications a candidate cloud provider holds. She wants the certification that specifically extends an information security management system with cloud-specific control guidance for both providers and customers. Which certification best meets that need?
- AISO/IEC 27017, which gives cloud-specific security control guidance for cloud service providers and cloud service customers. Correct
- BISO/IEC 27018, which provides a code of practice for protecting personally identifiable information processed in public clouds.
- CFIPS 140-3, which validates the security of cryptographic modules used to protect sensitive data.
- DCommon Criteria, which evaluates the security assurance of a specific IT product against a protection profile.
Why A is correct: Correct. ISO/IEC 27017 supplements the ISMS control set with implementation guidance tailored to cloud services and assigns responsibilities across provider and customer, matching the requirement stated.
Why B is wrong: ISO/IEC 27018 is genuinely cloud-relevant, which makes it tempting, but it targets protection of PII in public clouds specifically rather than general cloud security control guidance for providers and customers.
Why C is wrong: FIPS 140-3 is a valid assurance standard but it validates cryptographic modules, not a cloud-wide security management control set, so it does not extend an ISMS with cloud control guidance.
Why D is wrong: Common Criteria evaluates individual products against protection profiles at an assurance level; it is product assurance, not organisation-level cloud security management guidance.