Onwyn › Standards › BSI C5 — Cloud Computing Compliance Criteria Catalogue
Scheme / framework · C5:2020BSI C5 — Cloud Computing Compliance Criteria Catalogue
C5 is a criteria catalogue published by Germany's Federal Office for Information Security (BSI) that defines a minimum baseline of information security for professional cloud services. It is deliberately not a certification in the ISO sense: no certificate is issued and no accreditation body is involved. Conformity is demonstrated by an independent auditor performing an assurance engagement under ISAE 3000 (Revised) and issuing an attestation report that contains the provider's own description of its service and controls, the criteria, the auditor's tests, and the auditor's opinion. A Type 1 report addresses whether controls are suitably designed and implemented at a point in time; a Type 2 report additionally tests whether they operated effectively over a period, and it is the Type 2 report that sophisticated buyers ask for. The catalogue distinguishes basic criteria, the baseline expected of any professional cloud service, from additional criteria for elevated confidentiality and availability needs, and it is completed by a section of supplementary information about the service — jurisdiction, processing and storage locations, availability commitments, and how government investigation requests are handled. For a German cloud or SaaS provider selling into public sector, financial or healthcare procurement, a current C5 Type 2 attestation is frequently the document that decides the deal. This pack follows the C5:2020 catalogue, whose criteria are organised in seventeen areas identified by codes such as OIS, OPS and IDM; references here point to the area, while your auditor works from the individual criterion numbers in the catalogue text.
What this standard asks for
Every requirement in BSI C5 — Cloud Computing Compliance Criteria Catalogue, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
The attestation engagement
6 requirements
- ENG-1Understand what a C5 attestation is — and what it is not
- ENG-2Choose between Type 1 and Type 2 and plan the observation period
- ENG-3Define the scope: service, locations and subservice organisations
- ENG-4Write the system description and state the complementary customer controls
- ENG-5Decide which additional criteria you commit to
- ENG-6Supply the additional information about the cloud service
Security organisation, policies & compliance (OIS, SP, COM, INQ)
5 requirements
- OIS-AInformation security management system with defined scope and management commitment
- OIS-BRisk management process with documented assessment and treatment
- SP-ASecurity policies and derived instructions, approved and communicated
- COM-ALegal and contractual requirements, internal audit and control monitoring
- INQ-AHandling investigation requests from government agencies
Personnel & asset management (HR, AM)
5 requirements
- HR-AScreening, security obligations and disciplinary process
- HR-BJoiner, mover and leaver process with asset return
- HR-CSecurity awareness and role-specific training
- AM-AAsset inventory, ownership and classification
- AM-BEndpoint use, removable media and secure disposal
Physical security (PS)
2 requirements
- PS-APhysical access control to premises and data centres
- PS-BEnvironmental protection and facility monitoring
Operations (OPS)
6 requirements
- OPS-ACapacity management and service monitoring
- OPS-BProtection against malicious software
- OPS-CLogging, monitoring and protection of log data
- OPS-DHardening, vulnerability management and patching
- OPS-ESeparation of customer datasets in the shared infrastructure
- OPS-FBackup, restoration and backup protection
Identity, access & cryptography (IDM, CRY)
4 requirements
- IDM-AIdentity lifecycle and unique accounts
- IDM-BPrivileged access, strong authentication and access reviews
- CRY-ACryptography policy and state-of-the-art protection of data
- CRY-BKey management across the lifecycle
Communication security (COS)
2 requirements
- COS-ANetwork segmentation and perimeter protection
- COS-BProtection of data in transfer and control of information flows
Development, change & product security (DEV, PSS)
4 requirements
- DEV-ASecurity in the development lifecycle
- DEV-BChange management with approval, testing and rollback
- PSS-ASecurity functions and secure defaults exposed to customers
- PSS-BCustomer-facing security information and known vulnerabilities
Service providers & suppliers (SSO)
2 requirements
- SSO-ASelection and contracting of service providers and suppliers
- SSO-BOngoing monitoring of providers and their attestations
Incident management & continuity (SIM, BCM)
4 requirements
- SIM-ASecurity incident management process
- SIM-BEvidence preservation, root cause analysis and improvement
- BCM-ABusiness impact analysis and continuity planning
- BCM-BRedundancy and regular testing of continuity plans
Portability & interoperability (PI)
2 requirements
- PI-AData export and deletion at the end of the contract
- PI-BDocumented interfaces and dependencies enabling migration
The documents you will end up with
The recommended document set for BSI C5 — Cloud Computing Compliance Criteria Catalogue — 26 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The document the auditor works from and the one your customers read: what the service is, how it is built and operated, which controls you run, and which controls the customer has to run at their end.
Records the decisions you made before the audit started: Type 1 or Type 2, the observation period, and which additional criteria you signed up for.
The top-level security commitment plus the working instructions derived from it, approved and actually communicated to staff.
How security risks to the cloud service are identified, assessed, treated and re-checked.
The legal and contractual obligations that bind the service, and the schedule for checking your own controls against them.
What happens when an authority demands customer data: who is notified, who signs off, and what is recorded.
Background checks, security duties in the employment contract, the disciplinary route, and the joiner-mover-leaver process including getting kit back.
What security training everyone gets, what extra the privileged roles get, and how you evidence it happened.
The inventory of assets with owners and classifications, plus the rules for endpoints, removable media and secure disposal.
How data centres and offices are physically protected and monitored, and what covers power, cooling and fire.
How you watch service load and headroom, and what triggers you to add capacity before customers notice.
What protects your systems and endpoints against malicious software, and how it is kept current.
What is logged across the service, how log data is protected from tampering, and who reviews it.
The baseline configuration systems are built to, how vulnerabilities are found and ranked, and the deadlines for fixing them.
How one customer's data is kept apart from another's in shared infrastructure, and how that separation is tested.
What is backed up, how often, how copies are protected, and how restores are proven to work.
How accounts are created and removed, how privileged access is granted and authenticated, and how access is reviewed.
Where encryption is applied to customer data, which algorithms are acceptable, and how keys are handled across their life.
How the network is segmented and defended, and how data in transit and information flows are controlled.
How security is built into the way the service is designed, coded, reviewed and tested.
How changes to the production service are approved, tested and rolled back if they go wrong.
What you tell customers about the security features they can switch on, the secure defaults you ship, and known weaknesses.
How you select and contract providers you depend on, and how you keep checking their security and attestations.
How incidents are detected, triaged, escalated and communicated, and how evidence and root causes are handled afterwards.
What the service must survive, what recovery targets you have committed to, and how the plans are exercised.
How a customer gets their data out and gets it deleted at the end, and which documented interfaces let them move elsewhere.
Work that counts twice
BSI C5 — Cloud Computing Compliance Criteria Catalogue overlaps with 3 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.
Start BSI C5 today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.