Annual Cloud Provider Security Review Checklist
Retrospective: this article looks back at events from April 2024, written in 2026 with the benefit of hindsight.
Use this checklist to review each major cloud provider's security each year.
Evidence
- Current SOC 2 Type II report reviewed (including exceptions and complementary user entity controls).
- ISO 27001 and cloud-specific certifications current.
- Sector-specific attestations (HIPAA BAA, PCI DSS, FedRAMP) in place where required.
- Penetration test summaries or bug bounty program information reviewed.
Incidents
- Provider incidents in the past year identified (public disclosures, notifications to you).
- Root cause reports obtained for incidents affecting your services.
- Your own response to provider incidents reviewed.
Contract
- Incident notification terms meet your needs.
- Logging and audit data availability confirmed.
- Data residency commitments match requirements.
- Subprocessor list reviewed.
Your configuration
- Shared responsibility mapping current.
- Customer-side controls (complementary user entity controls) implemented.
- Provider security recommendations reviewed (for example, secure score or Trusted Advisor).
Resilience
- Dependency on the provider for critical services documented.
- Exit or contingency plan exists for critical services.
- Backups stored independently where required.
Outcome
- Risk rating updated.
- Actions assigned with owners.
- Summary reported to leadership or risk committee.