OnwynStandards › BSI C5 — Cloud Computing Compliance Criteria Catalogue

Scheme / framework · C5:2020

BSI C5 — Cloud Computing Compliance Criteria Catalogue

C5 is a criteria catalogue published by Germany's Federal Office for Information Security (BSI) that defines a minimum baseline of information security for professional cloud services. It is deliberately not a certification in the ISO sense: no certificate is issued and no accreditation body is involved. Conformity is demonstrated by an independent auditor performing an assurance engagement under ISAE 3000 (Revised) and issuing an attestation report that contains the provider's own description of its service and controls, the criteria, the auditor's tests, and the auditor's opinion. A Type 1 report addresses whether controls are suitably designed and implemented at a point in time; a Type 2 report additionally tests whether they operated effectively over a period, and it is the Type 2 report that sophisticated buyers ask for. The catalogue distinguishes basic criteria, the baseline expected of any professional cloud service, from additional criteria for elevated confidentiality and availability needs, and it is completed by a section of supplementary information about the service — jurisdiction, processing and storage locations, availability commitments, and how government investigation requests are handled. For a German cloud or SaaS provider selling into public sector, financial or healthcare procurement, a current C5 Type 2 attestation is frequently the document that decides the deal. This pack follows the C5:2020 catalogue, whose criteria are organised in seventeen areas identified by codes such as OIS, OPS and IDM; references here point to the area, while your auditor works from the individual criterion numbers in the catalogue text.

42
Requirements
11
Areas
26
Recommended documents
3
Mapped frameworks
Start BSI C5 free Have us do it instead

What this standard asks for

Every requirement in BSI C5 — Cloud Computing Compliance Criteria Catalogue, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

The attestation engagement

6 requirements

  • ENG-1Understand what a C5 attestation is — and what it is not
  • ENG-2Choose between Type 1 and Type 2 and plan the observation period
  • ENG-3Define the scope: service, locations and subservice organisations
  • ENG-4Write the system description and state the complementary customer controls
  • ENG-5Decide which additional criteria you commit to
  • ENG-6Supply the additional information about the cloud service

Security organisation, policies & compliance (OIS, SP, COM, INQ)

5 requirements

  • OIS-AInformation security management system with defined scope and management commitment
  • OIS-BRisk management process with documented assessment and treatment
  • SP-ASecurity policies and derived instructions, approved and communicated
  • COM-ALegal and contractual requirements, internal audit and control monitoring
  • INQ-AHandling investigation requests from government agencies

Personnel & asset management (HR, AM)

5 requirements

  • HR-AScreening, security obligations and disciplinary process
  • HR-BJoiner, mover and leaver process with asset return
  • HR-CSecurity awareness and role-specific training
  • AM-AAsset inventory, ownership and classification
  • AM-BEndpoint use, removable media and secure disposal

Physical security (PS)

2 requirements

  • PS-APhysical access control to premises and data centres
  • PS-BEnvironmental protection and facility monitoring

Operations (OPS)

6 requirements

  • OPS-ACapacity management and service monitoring
  • OPS-BProtection against malicious software
  • OPS-CLogging, monitoring and protection of log data
  • OPS-DHardening, vulnerability management and patching
  • OPS-ESeparation of customer datasets in the shared infrastructure
  • OPS-FBackup, restoration and backup protection

Identity, access & cryptography (IDM, CRY)

4 requirements

  • IDM-AIdentity lifecycle and unique accounts
  • IDM-BPrivileged access, strong authentication and access reviews
  • CRY-ACryptography policy and state-of-the-art protection of data
  • CRY-BKey management across the lifecycle

Communication security (COS)

2 requirements

  • COS-ANetwork segmentation and perimeter protection
  • COS-BProtection of data in transfer and control of information flows

Development, change & product security (DEV, PSS)

4 requirements

  • DEV-ASecurity in the development lifecycle
  • DEV-BChange management with approval, testing and rollback
  • PSS-ASecurity functions and secure defaults exposed to customers
  • PSS-BCustomer-facing security information and known vulnerabilities

Service providers & suppliers (SSO)

2 requirements

  • SSO-ASelection and contracting of service providers and suppliers
  • SSO-BOngoing monitoring of providers and their attestations

Incident management & continuity (SIM, BCM)

4 requirements

  • SIM-ASecurity incident management process
  • SIM-BEvidence preservation, root cause analysis and improvement
  • BCM-ABusiness impact analysis and continuity planning
  • BCM-BRedundancy and regular testing of continuity plans

Portability & interoperability (PI)

2 requirements

  • PI-AData export and deletion at the end of the contract
  • PI-BDocumented interfaces and dependencies enabling migration

The documents you will end up with

The recommended document set for BSI C5 — Cloud Computing Compliance Criteria Catalogue — 26 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

System Description

The document the auditor works from and the one your customers read: what the service is, how it is built and operated, which controls you run, and which controls the customer has to run at their end.

Engagement Scoping Note

Records the decisions you made before the audit started: Type 1 or Type 2, the observation period, and which additional criteria you signed up for.

Information Security Policy and Derived Instructions

The top-level security commitment plus the working instructions derived from it, approved and actually communicated to staff.

Risk Management Procedure

How security risks to the cloud service are identified, assessed, treated and re-checked.

Compliance and Internal Audit Plan

The legal and contractual obligations that bind the service, and the schedule for checking your own controls against them.

Government Investigation Request Procedure

What happens when an authority demands customer data: who is notified, who signs off, and what is recorded.

HR Security Policy

Background checks, security duties in the employment contract, the disciplinary route, and the joiner-mover-leaver process including getting kit back.

Security Awareness and Training Plan

What security training everyone gets, what extra the privileged roles get, and how you evidence it happened.

Asset Management and Endpoint Policy

The inventory of assets with owners and classifications, plus the rules for endpoints, removable media and secure disposal.

Physical and Environmental Security Policy

How data centres and offices are physically protected and monitored, and what covers power, cooling and fire.

Capacity and Service Monitoring Procedure

How you watch service load and headroom, and what triggers you to add capacity before customers notice.

Malware Protection Standard

What protects your systems and endpoints against malicious software, and how it is kept current.

Logging and Monitoring Policy

What is logged across the service, how log data is protected from tampering, and who reviews it.

Hardening, Vulnerability and Patch Standard

The baseline configuration systems are built to, how vulnerabilities are found and ranked, and the deadlines for fixing them.

Tenant Separation Design Note

How one customer's data is kept apart from another's in shared infrastructure, and how that separation is tested.

Backup and Restore Policy

What is backed up, how often, how copies are protected, and how restores are proven to work.

Identity and Access Management Policy

How accounts are created and removed, how privileged access is granted and authenticated, and how access is reviewed.

Cryptography and Key Management Policy

Where encryption is applied to customer data, which algorithms are acceptable, and how keys are handled across their life.

Network and Communication Security Policy

How the network is segmented and defended, and how data in transit and information flows are controlled.

Secure Development Policy

How security is built into the way the service is designed, coded, reviewed and tested.

Change Management Procedure

How changes to the production service are approved, tested and rolled back if they go wrong.

Customer Security Documentation

What you tell customers about the security features they can switch on, the secure defaults you ship, and known weaknesses.

Supplier and Subservice Organisation Policy

How you select and contract providers you depend on, and how you keep checking their security and attestations.

Security Incident Management Procedure

How incidents are detected, triaged, escalated and communicated, and how evidence and root causes are handled afterwards.

Business Continuity Plan and Impact Analysis

What the service must survive, what recovery targets you have committed to, and how the plans are exercised.

Exit, Data Export and Portability Documentation

How a customer gets their data out and gets it deleted at the end, and which documented interfaces let them move elsewhere.

Work that counts twice

BSI C5 — Cloud Computing Compliance Criteria Catalogue overlaps with 3 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start BSI C5 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.