Data Protection & GDPR

Cloud Services Registry

The object is not the provider but the service

The BSI building block OPS.2.2 Cloud Usage requires a service definition, clarified areas of responsibility, evidence of information security and an orderly termination for every cloud service. Without a registry of services this cannot be maintained, because the reference object is missing. And the object is the service, not the provider: one provider typically supplies several, such as Exchange Online, Teams and Entra ID. The registry complements existing directories and replaces none. Anything already maintained in the supplier, contract or processor directory is a reference here.

BSI IT-GrundschutzDSGVOISO 27001
Features

Your benefits

1

OPS.2.2 lands in the implementation plan

Every cloud service is a target object. From the detail view the building block requirements can be transferred into the implementation plan in one click, where implementation status, dates and owners are maintained anyway. A second place for the same thing would drift apart.

2

The exit carries a rehearsal date

Exit arrangement, notice period and portability sit next to the field recording when the exit was last rehearsed. Between a described and a rehearsed migration lies the question of whether the export is complete and usable outside the service.

3

Organisational where CSPM is technical

Cloud security posture management finds misconfigurations in the accounts. The registry answers the other half: which service, with which data, in which country, with which subcontractors and by which route back out.

Capabilities

Capabilities in detail

  • Cloud services with a sequential number prefixed CLD
  • Service definition: service model, deployment model, availability, service hours
  • Business and IT responsibility kept apart (OPS.2.2 A4)
  • Data centre country and further processing countries
  • Subcontractors per service, as the basis for A8 and A9
  • Evidence with review date and follow-up, due items in the cockpit
  • Encryption at rest and in transit, key management, own backup
  • Exit arrangement, notice period, portability, exit rehearsed on
  • Reference to processor and record of processing
  • Links to processes, IT systems, software and information
  • Every service is a target object for implementation plan, protection needs and risks
Result

A registry that does not describe OPS.2.2 but supplies the reference object that makes its requirements plannable.

Experience Cloud Services Registry live

Schedule a no-obligation demo – we will show you the module with your own use cases.