High level structure
ISO 27001:2013 is the International Requirements Standard for Information Security Management Systems. It is a risk based management system that requires an organization to meet the requirements of 7 main mandatory clauses as detailed. As a result of risk assessments carried out by the organization, it must decide which of those threats and vulnerabilities, identified in Activity 2, will require protection against risk and guidance on how to close the vulnerability gap.
Based upon the amount of risk an organization may wish to take on, a list of 114 possible controls that can be implemented to support the effective implementation of the management system are provided in Annex A of the standard.
None of these controls are mandatory, however should an organization need to implement a control to satisfy its own risk acceptance criteria and they do not wish to use the listed controls, other compensating controls must be implemented.
In order for a Cloud Service Provider to achieve STAR Certification, certification to this standard is a pre-requisite to being considered for the scheme.