1 of 6

OCP European Workstream Call

Data Center & Cloud Certifications presented by

iAP- Independent Consulting + Audit Professionals

OCP EU Con. Call – 10th of October 2023

Community-driven hyperscale innovation for all.

2 of 6

Certifications / Testations – Data Centers & Cloud Services

2

  • XXXXXXXXXX

​

​

​

Standard

Focus

For who?

Advantages / Key benefits / Remarks

BSI C5

(Cloud Computing Compliance Criteria Catalogue)

German cloud security

  • All cloud service providers
  • All cloud models and service types
  • Date center operators with cloud offerings
  • Comprehesive and ambitioned security requirements
  • Required by cloud-tenders in German public sector / for KRITIS must
  • Proves effectiveness of implemented controls for reporting period
  • Testate issued by CPA (Certified public accountant)
  • Full liability of CPA for testation
  • Testate to be renewed each year (or shorter cycles)

ISO 27001

International standard for basic information security

  • All companies and institutions
  • All industry sectors
  • Proves implementation and operation of ISMS (Information security management system)
  • Issued by accredeted certification body
  • Surveillance audit each year, certification renewal 3 years cycle
  • Only limited liability of certification body

ISO 27017

ISO 27018

Cloud security

Data privacy cloud services

  • All companies and institutions
  • All industry sectors
  • Certification based on ISO 27001
  • Additional requirements for cloud and data privacy
  • „Add on“ certification for cloud service providers
  • Only limited liability of certification body

EN 50600

Secure design & operation of data center facilities and infrastructures

Data center operators

  • Currently„The“ EU standard for design and operation of data centers
  • Conformity testatation possible by any institution (CPA, TÜV/DEKRRA, other professionals/expert)
  • Liability dependent on audit entity

Community-driven hyperscale innovation for all.

3 of 6

Certifications / Testations – Data Centers & Cloud Services Cont.

3

Standard

Focus

For who?

Advantages / Key benefits / Remarks

SOC 2

System and Organization Controls (AICPA)

​

ISAE 3402

Int. Standard on Assurance Engagements (IFAC)

Internal control system (ICS) of

IT- service providers:

    • Type 1: suitability of control design
    • Type 2: control effectiveness

​

  • All types of IT service providers, e.g. data centers, cloud providers
  • Companies with international focus / customers
  • Internationally recognized standards for IT security of oursourced IT-services
  • Prove suitable design and effectiveness of implemented controls for reporting period
  • Testate issued by CPA (Certified public accountant)
  • Full liability of CPA for testation
  • Testate to be renewed each year (or shorter cycles)

SOC 1

System and Organization Controls (AICPA)

Internal control system (ICS) for providers of

IT- services that are relevant for the financial reporting of customers

  • IT service providers, e.g. cloud based solutions
  • Software vendors relevant for financial reporting
  • Similar to SOC 2 and ISAE 3402, but focus on service that impact financial reporting
  • Can also be used for software products in customer environment
  • Controls are not standardised, to be defined and implemented by service provider

Community-driven hyperscale innovation for all.

4 of 6

Benefits And Key Considerations

4

Certifications (with certification body) and testations:

  • show adherence of business activities to accepted IT standards,
  • prove ongoing security and reliability of services and data,
  • build trust in provided IT- services,
  • serve as differentiator to competitors,
  • are often prerequisite for new business / contracts in public sector and even in private industry.

What are the benefits of certification/ testation?

What standard should be followed?

What are the key considerations

The certification/testation standard should be selected based on

  • Compliance requirements
  • Requests from customers and market requirements (e.g. tenders)
  • Type of the services that are provided
  • The value of certificates / testates in the market depends significantly on public awareness and

the liability of the issuing entity.

  • For some certifications a direct return on invest can be realised, as payment of customers for copy

of report is commonly accepted in market (e.g ISAE 3402, SOC1/ SOC2).

  • Before certification and testation it is necessary to implement the required ICS (Internal Control System) or management system. For this, commitment, resources and time are required.
  • Any implemented ICS based on selected standard can always be expanded to other standards with reduced effort, as processes for ICS operation have already been set up (CMS / compliance management system).
  • Certification / testation is not a one-shot topic but an ongoing process as effectiveness of ICS or operation of management system over time are audited.

Community-driven hyperscale innovation for all.

5 of 6

iAP Support & Certification & Testation Services

5

Setup

of Internal Control or Management System (ICS)

Audit & Certification

​

Type 1 - Design

Type 2 - Effectiveness

Re-Audit /

further development to Compliance Mgmt. Systems

  • Standard selection scope definition, project setup, tool setup
  • Risks assessment, definition of control areas and control objectives
  • Definition & selection of controls / creation of Risk-Control-Matrix (RKM)
  • Definition of control procedures / implementation of processes and responsibilities
  • Setup of ICS-documentation and required evidences for later certification
  • Depending on standard
    • Conformity / compliance assessment
    • Audit procedures - test of control design (Typ 1) or control effectiveness (Typ 2)
    • Stage 1 audit (certification readiness) or Stage 2 audit (certification process)
    • Audit report and issuing of certificate / testate
  • Optimisation of Internal control system
  • Ongoing Re-audits / surveillence audit and Re-certification
  • Development support for ICS regarding integration of additional compliance topics or standards (Compliance Management System)

Community-driven hyperscale innovation for all.

6 of 6

Any questions? We have answers!

6

Thomas Pfützenreuter

​

Managing Director

Dipl. Ing., Certified ISO 27001 Auditor, CISA, Business Mediator (Steinbeis University)

​

​

Burghard Denz

​

Head of IT-Audit & Certification

Dipl. Kfm., CISA, CISM, CCSK, IT-Security Auditor (TÜV)

iAP - Independent Consulting + Audit Professionals GmbH�Tel. +49 30 4397 16860�www.kontakt@audit-professionals.de

Community-driven hyperscale innovation for all.