C5 cloud criteria catalogue: the clauses behind the split
The C5 cloud computing compliance criteria catalogue, written for cloud providers and the customers who rely on them.
Shown when ticked. The framework on the compliance library.
Control areas it anchors
13Every clause cited, quoted
13 of the 121 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
C5-COS-06 Segregation of data traffic in jointly used network environmentsSegregate the traffic of different cloud customers in shared network environments at network level following a documented segregation concept, so transmitted data retains its confidentiality and integrity between tenants.
- Documented tenant segregation concept for shared network environments
- Network configuration listing the per-tenant identifiers currently in use
- Test results demonstrating traffic cannot pass between two tenant segments
- Controls preventing a retired tenant identifier from being handed to another customer
- Separation depends on application logic rather than measures taken at network level
- Identifiers recycled after decommissioning, allowing traffic to surface in the wrong tenant
- A shared services segment lets tenants observe one another's traffic
C5-CRY-04 Secure key managementOperate key management spanning generation, certificate issuance, activation, storage isolated from application and middleware layers, authorised retrieval, rekeying, compromise handling, withdrawal and deletion, with separate rules stated where pre-shared keys are used.
- Key lifecycle procedure running from generation through to destruction
- Key register recording owner, purpose, cryptoperiod and next rotation date
- Proof that the key store operates separately from application and middleware tiers
- Key compromise response instruction and any compromise event that invoked it
- Keys generated on general purpose systems with no assured source of entropy
- Rotation intervals defined on paper while expired keys stay in productive use
- Pre-shared secrets circulated by mail or chat with no dedicated handling provisions
C5-DEV-01 Policies for the development/procurement of information systemsIssue secure development policies covering the whole service lifecycle and grounded in recognised standards, addressing security in requirements, design, implementation, testing and verification, in software deployment including continuous delivery, and in reacting to faults and vulnerabilities during operation.
- Secure development policy naming the standard or method it is built on
- Lifecycle description running from requirements through to operational vulnerability handling
- Deployment security instruction covering the continuous delivery route
- Proof that the policy was issued to internal developers and contracted development staff
- Policy stops at coding conventions and is silent on deployment and operation
- Delivery pipelines run under no documented security requirement at all
- No recognised standard underpins the policy, so its completeness cannot be judged
C5-OIS-01 Information Security Management System (ISMS)Operate an information security management system aligned to ISO/IEC 27001 covering the organisational units, sites and processes that deliver the cloud service, and retain documented scope, statement of applicability and the latest management review results.
- ISMS scope statement listing the in scope legal entities, sites and cloud delivery processes
- Statement of Applicability with inclusion and exclusion justifications for every control
- Minutes, inputs and decisions of the most recent management review
- Valid certificate and certification body audit report for the management system
- Scope leaves out subsidiaries or data centre sites that in fact operate production components
- Statement of Applicability not reconciled with the control set actually in force
- Management review last held more than twelve months ago or held without recorded decisions
C5-OPS-06 Data Backup and Recovery - ConceptDocument and communicate backup and recovery policies fixing backup scope, frequency and retention against contractual and internal RTO and RPO targets, requiring state of the art encryption of backups, restricting restores to authorised persons and mandating recovery testing.
- Backup policy stating retention per data class alongside the agreed RTO and RPO
- Encryption standard and key handling rules applied to backup sets
- Authorisation matrix naming who may trigger a restore
- Mapping of customer contract terms onto the internal backup schedule
- Retention in the policy shorter than the periods promised to customers in contract
- Policy silent on where backup encryption keys are held and who controls them
- Restore authority expressed as a role that no longer exists in the organisation
- Policy scoped to databases while configuration, secrets and infrastructure state are omitted
C5-OPS-10 Logging and Monitoring - ConceptEstablish written logging and monitoring policies for systems in the provider's area of responsibility that define which events could breach protection goals, how logs are activated, paused and stopped, their purpose and retention, role responsibilities, time synchronisation and legal obligations.
- Logging policy listing the event types classified as security relevant
- Documented retention period per log source with the legal basis cited
- Responsibility matrix naming owners of log configuration and of log review
- Time synchronisation standard specifying the authoritative time sources
- Policy enumerates log sources yet never defines which events matter
- No rule stating who may pause or switch off logging on a system
- Retention periods in the policy inconsistent with the platform configuration
- No authoritative time source defined, so records across components cannot be correlated
C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - ConceptPublish technical and organisational rules for vulnerability handling requiring regular identification of vulnerabilities, assessment of their severity, prioritised remediation or mitigation within defined timelines, and a defined treatment for components where no timely fix will be applied.
- Vulnerability policy stating the severity scale and the deadline attached to each level
- Documented handling route for components that cannot be remediated, including compensating controls
- List of approved vulnerability information sources feeding the identification process
- Risk acceptance register recording deviations from the remediation deadlines
- Severity scale defined without any corresponding remediation deadline
- No documented path for end of life components that will never receive a fix
- Rules limited to operating systems and silent on libraries, images and firmware
- Risk acceptances granted verbally, never recorded and never time limited
C5-OPS-21 Involvement of Cloud Customers in the Event of IncidentsKeep affected cloud customers informed at regular intervals on the status of incidents concerning them, involve them in resolution where appropriate and necessary, and tell them what action was taken once the incident is resolved, all as the contract provides.
- Notification timeline for a sampled incident showing each update issued to the customer
- Contractual communication commitments listing notification intervals and channels
- Status page history or portal notices published for the same incident
- Closure notice describing the actions taken and any customer follow up required
- Customers told at the start and at closure with nothing in between during a long incident
- Only the technical contact notified while the contractual escalation contact is missed
- Closure message omits what was actually done, leaving the customer nothing to act on
- Notification intervals promised in the contract absent from the incident procedure
C5-PI-03 Secure deletion of dataErase customer data at the end of the contractual relationship in line with the agreed terms, covering the customer environment, metadata and backup copies, using methods that defeat recovery by forensic means.
- Erasure procedure spanning the live environment, metadata stores and backup media
- Completion confirmation issued for a terminated customer within the agreed period
- Technical description of the wiping or key destruction method relied upon
- Backup retention schedule showing when residual copies finally expire
- Live data removed while backup copies persist to the end of an unchanged retention cycle
- Metadata, audit trails and derived indexes retained after the content itself is gone
- Removal limited to deleting pointers, leaving content readable from the underlying media
C5-PS-04 Physical site access controlControl entry at every access point using an access control system whose documented rules grant least privilege authorisations, revoke unused rights after two and six months, enforce two factor authentication for areas holding customer data, escort visitors and log all entries.
- Badge system export showing authorisation holders per security area
- Report of automatically revoked credentials with the recorded inactivity dates
- Visitor register with escort names and pass return times
- Door reader event log for a sampled high security room
- Dormant contractor badges still active well past the stated inactivity limit
- Two factor reader on the machine room door bypassed through an adjacent office door
- Visitors recorded at reception yet not tracked by the badge system inside the building
- No periodic reconciliation of badge holders against current job roles
C5-PSS-11 Images for Virtual Machines and ContainersWhere customers run virtual machines or containers, let the customer restrict which images its users may launch, inform the customer of what changed between versions of any images the provider supplies, and harden those provider supplied images to generally accepted industry standards.
- Customer facing setting restricting which images users are permitted to launch
- Release notes describing what changed between successive provider supplied images
- Hardening baseline and build evidence for one provider supplied image
- Catalogue showing the approved image set made available to a tenant
- Image restriction applies in the console while other launch paths ignore it
- New image versions published with no statement of what changed
- Provider images shipped with default accounts and unnecessary services enabled
- Hardening applied at first build and not maintained across later rebuilds
C5-PSS-12 Locations of Data Processing and StorageLet the cloud customer choose, from the options available under its contract, the location or country in which its data is processed, stored and backed up, and ensure the cloud architecture itself enforces that choice.
- Contract or ordering options listing the selectable processing and storage regions
- Architecture documentation showing regional placement is technically enforced
- Configuration evidence that backup copies remain within the chosen region
- Record confirming a tenant's actual data placement matches its selection
- Primary storage pinned regionally while backups or replicas leave the region
- Placement honoured by process alone with nothing preventing a cross region deployment
- Support tooling and telemetry data processed outside the selected location
- Customers given a choice with no means of verifying where data actually resides
C5-SSO-01 Policies and instructions for controlling and monitoring third partiesDocument, communicate and make available policies governing third parties whose services support the cloud service, covering procurement risk assessment, subcontractor classification, security and training obligations, legal duties, vulnerability handling, contractual wording, monitoring, and flow down to their own providers.
- Approved third party control policy with version history and publication record
- Distribution list showing which procurement and legal staff received the policy
- Template contract clause library covering security, training and vulnerability obligations
- Classification rubric distinguishing subcontractors from other suppliers
- Policy silent on flow down of obligations to a supplier's own subcontractors
- No documented rule for deciding when a third party counts as a subcontractor
- Policy exists but was never issued to the teams that sign supplier contracts