Overview
ISO/IEC 27018 provides guidance for cloud service providers on protecting personally identifiable information (PII) based on ISO/IEC 27002 and in alignment with privacy principles. It establishes cloud-specific controls and best practices for PII.
Certification demonstrates that SITE Cloud implements controls for PII protection as required by ISO/IEC 27018.
SITE Cloud and ISO/IEC 27018
- SITE Cloud has achieved ISO/IEC 27018 certification for its implementation of privacy controls for PII.
- The SITE Cloud ISO/IEC 27018 certificate validates compliance with PII protections.
- Clients can leverage SITE Cloud's ISO/IEC 27018 certification to support compliance for workloads involving PII stored on the SITE Cloud.
Scope of Certification
The SITE Cloud ISO/IEC 27018 certification applies to the following in-scope cloud services:
- Cloud Virtual Datacenter(VDC)
- Cloud Disaster Recovery
- Cloud Managed IT
- Cloud Managed IT SME
Audit Certificates
- The SITE Cloud ISO/IEC 27018 certificate is available upon request via SITE Cloud Support Portal.
Frequently Asked Questions:
- Who does ISO/IEC 27018 apply to?
ISO/IEC 27018 provides guidance specifically for cloud service providers processing PII on behalf of clients.
- How can I access SITE Cloud's ISO/IEC 27018 audit documentation?
Certificates can be requested through the SITE Cloud Support Portal.
- Can I use SITE Cloud's certification to support my ISO/IEC 27018 compliance?
Yes, SITE Cloud's ISO/IEC 27018 certification can help demonstrate compliance for PII processed and stored on the cloud. Clients remain responsible for compliance of their cloud implementation and internal controls.