The BSI building block OPS.2.2 Cloud Usage requires a service definition, clarified areas of responsibility, evidence of information security and an orderly termination for every cloud service. Without a registry of services this cannot be maintained, because the reference object is missing. And the object is the service, not the provider: one provider typically supplies several, such as Exchange Online, Teams and Entra ID. The registry complements existing directories and replaces none. Anything already maintained in the supplier, contract or processor directory is a reference here.
Every cloud service is a target object. From the detail view the building block requirements can be transferred into the implementation plan in one click, where implementation status, dates and owners are maintained anyway. A second place for the same thing would drift apart.
2
The exit carries a rehearsal date
Exit arrangement, notice period and portability sit next to the field recording when the exit was last rehearsed. Between a described and a rehearsed migration lies the question of whether the export is complete and usable outside the service.
3
Organisational where CSPM is technical
Cloud security posture management finds misconfigurations in the accounts. The registry answers the other half: which service, with which data, in which country, with which subcontractors and by which route back out.
Capabilities
Capabilities in detail
Cloud services with a sequential number prefixed CLD
Service definition: service model, deployment model, availability, service hours
Business and IT responsibility kept apart (OPS.2.2 A4)
Data centre country and further processing countries
Subcontractors per service, as the basis for A8 and A9
Evidence with review date and follow-up, due items in the cockpit
Encryption at rest and in transit, key management, own backup
Exit arrangement, notice period, portability, exit rehearsed on
Reference to processor and record of processing
Links to processes, IT systems, software and information
Every service is a target object for implementation plan, protection needs and risks
Result
A registry that does not describe OPS.2.2 but supplies the reference object that makes its requirements plannable.
Experience Cloud Services Registry live
Schedule a no-obligation demo – we will show you the module with your own use cases.