ISO 27018
Evidence request list. 45 controls, 45 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Data Lifecycle
On termination the processor shall return or securely dispose of PII as instructed by the customer.
- Exit clause
- Deletion certificates
- Backup purge evidence
- Return logs
- Backups retain PII
- No deletion certificate
- Return method unclear
ISO 27018: Cloud Governance
Shared responsibility model definition. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Cloud security policy and strategy. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Cloud risk assessment. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Regulatory compliance for cloud services. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Cloud security roles and responsibilities. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
ISO 27018: Cloud Infrastructure Security
Virtual network segmentation. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Container and serverless security. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Cloud workload protection. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Image and template hardening. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Cloud configuration management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
ISO 27018: Cloud Operations & Monitoring
Cloud security monitoring and logging. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Incident response in cloud. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Cloud vulnerability management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Cloud change management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Service level agreement management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
ISO 27018: Data Protection in Cloud
Data classification for cloud. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Encryption of cloud-stored data. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Data residency and sovereignty. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Data backup and recovery in cloud. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Secure data deletion in cloud. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
ISO 27018: Identity & Access in Cloud
Cloud identity management. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Multi-factor authentication for cloud. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Privileged access in cloud environments. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Federation and single sign-on. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
API security and access tokens. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Incident
The processor shall promptly notify the customer of any incident leading to loss, disclosure or alteration of PII.
- Breach notification SLA
- Notification templates
- Incident records
- Customer communications log
- No SLA
- Notification informal
- Customer comms missing
PII Principles
Public cloud PII processor shall process PII only as instructed by the cloud service customer who is the PII controller or by the PII principal.
- Customer agreement clauses
- Processing instructions log
- Use restriction policy
- Audit trail
- Vague processing instructions
- Marketing use of PII
- No audit trail
PII shall be processed only for the purposes specified by the customer and not used for the processor's own purposes.
- Purpose register
- Use case approvals
- Internal use prohibition policy
- Marketing opt-in records
- Telemetry uses PII
- No purpose register
- Marketing reuse without consent
The processor shall not collect PII beyond what is required for the agreed purpose.
- Data minimization review
- Field-level necessity analysis
- Schema documentation
- Change control records
- No minimization review
- Over-collection by default
- Schema drift
Temporary files and copies of PII shall be erased or destroyed in a defined period.
- Retention schedule
- Temporary file purge job logs
- Cache policy
- Deletion certificates
- Cache retains PII
- No purge jobs
- Backups out of scope
PII shall not be retained beyond the timeframe required to fulfil the agreed purpose unless required by law.
- Retention policy
- Deletion logs
- Legal hold register
- Customer-driven deletion workflow
- No customer-driven deletion
- Indefinite logs
- Legal holds without review
PII processed shall be accurate and up to date to the extent necessary for the purpose.
- Data quality controls
- Correction workflow
- Customer correction requests log
- Validation rules
- No correction workflow
- Customer can't correct via portal
- Validation absent
The processor shall provide the customer with information about the processing of PII including subcontractors and locations.
- Subprocessor list
- Data location disclosure
- Trust page
- Notification process for changes
- Subprocessor list stale
- No location disclosure
- No change notification
The processor shall provide means for the customer to fulfil PII principal rights including access, correction and deletion.
- DSAR support runbook
- Customer APIs for rights
- Response time SLA
- Closure records
- No DSAR API
- Manual fulfilment slow
- No SLA tracking
The processor shall assign roles to manage PII protection and demonstrate compliance.
- Privacy officer appointment
- Privacy program charter
- Compliance reports
- Audit evidence
- No privacy officer
- Program informal
- No external audit
Privacy by Design
Customer shall be informed of countries in which PII is or may be stored or processed.
- Data location disclosure
- Region pinning configs
- Subprocessor list
- Audit reports
- Region drift
- No customer disclosure
- Subprocessor regions hidden
PII shall be transmitted only to destinations agreed with the customer.
- Data flow diagrams
- Egress controls
- Approved destination list
- Network policy
- No data flow diagrams
- Unapproved destinations
- Egress wide open
Security
PII shall be protected with appropriate technical and organizational measures consistent with risk.
- Risk assessment
- Control implementation evidence
- Pen test reports
- Encryption standards
- Risk assessment dated
- Encryption gaps
- No regular pen tests
Personnel processing PII shall be under confidentiality obligations recorded in writing.
- Signed confidentiality agreements
- Contractor agreements
- Training records
- Exit confirmation
- Contractors missing
- No exit confirmation
- Training not specific to PII
Creation of hardcopy materials containing PII shall be restricted and controlled.
- Print policy
- Pull-print logs
- Hardcopy register
- Destruction records
- No print policy
- Hardcopy not registered
- Destruction unverified
Restoration of PII from backups shall be controlled and logged.
- Restoration runbook
- Approval log
- Restore test records
- Audit trail
- No approval workflow
- Restores not logged
- Test restores skipped
PII on media leaving premises shall be subject to authorization and protective measures including encryption.
- Removable media policy
- Encryption enforcement
- Movement log
- Authorization records
- Unencrypted USB allowed
- No movement log
- Authorization informal
PII transmitted over networks shall be encrypted and integrity-protected.
- TLS configuration
- Cipher inventory
- API gateway settings
- Network test reports
- Weak ciphers enabled
- Internal traffic unencrypted
- No integrity controls
Disclosures of PII to third parties including law enforcement shall be logged and where lawful notified to the customer.
- Disclosure register
- Customer notification policy
- Legal review records
- Transparency reports
- No customer notification
- Register absent
- Legal review skipped
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27018 framework page.