BSI C5
The Cloud Computing Compliance Criteria Catalogue, C5, is the German Federal Office for Information Security's standard for cloud service providers. It defines the security a provider must demonstrate and how an auditor attests to it, so cloud customers can judge a service on evidence rather than promises. turingsecure holds the controls and evidence behind each C5 criterion.
What the Catalogue Requires
Cloud Security an Auditor Attests To
C5 sets out criteria across areas such as organisation of information security, physical security, identity and access management, cryptography and operations. Each criterion has a basic requirement that every provider must meet, and many carry additional criteria for services with higher assurance needs. The catalogue also asks providers to describe their environment so customers understand the context the criteria are met in.
Unlike a certificate you display, C5 results in an auditor attestation modelled on ISAE 3402. An independent auditor examines the controls and reports on whether they are suitably designed and, in a type 2 attestation, operating effectively over a period. Customers read that report to decide whether the service fits their own compliance obligations.
How C5 Works
From Criteria to Customer Transparency
- Basic and Additional Criteria
Meet the basic criteria every provider must satisfy, then add the additional ones your assurance level calls for. turingsecure maps both to controls you maintain once.
- System Description
Describe the environment the criteria are met in, so the attestation has the context a reader needs. Control status is kept ready for it.
- Auditor Attestation
An independent auditor examines the controls in the style of ISAE 3402 and reports on their design and, for type 2, their operation over time.
- Customer Transparency
Cloud customers read the C5 report to judge the service on documented evidence, and reuse it in their own audits rather than running their own.
Related
The Modules That Carry BSI C5
C5 draws on the same connected model as the rest of your compliance work.
- Frameworks
Adopt C5 as a framework and map its basic and additional criteria alongside ISO 27001 in one place.
- Controls
A control library with applicability, ownership and implementation status covers each C5 criterion from one source.
- Evidence
Attach the artifacts the auditor tests to each control and keep them current with expiry reminders across the attestation period.
- Audits
Plan the C5 examination and track findings to corrective action and closure before the attestation is issued.
Give Cloud Customers the Evidence They Ask For
Book a personal demo and see how turingsecure holds the controls and evidence behind your BSI C5 attestation.