BSI C5 – Cloud Computing Compliance Criteria Catalogue

With BSI C5 in conjunction with ISAE 3000 audits, cloud service operators can demonstrate in a structured and transparent manner that the BSI C5 criteria for ensuring information security are met. We support you in the audit of the BSI C5 criteria according to the ISAE 3000 standard and pave the way for trustworthy, resilient cloud services.
Frank Reutter
Partner
Auditor, Certified Tax Advisor, CISA, Graduate in Business Informatics
Nicolas Fehrenbach
Manager
Write to us without obligation:
Get in touch now

BSI C5 & ISAE 3000: Reliable Audit Standards for Cloud Service Providers

The BSI C5 defines essential requirements for a secure and trustworthy cloud computing environment with a focus on information security. The aim of the BSI C5 is to subject the security measures of cloud service providers to a standardized audit and to make them transparent. The BSI C5 criteria catalog can be used in conjunction with the ISAE 3000 as an audit basis for cloud providers. During the audit of the BSI C5 criteria according to ISAE 3000, we determine whether the cloud provider has implemented the security measures and processes defined in the BSI C5 and whether they are effective.

Quality and Credibility

ISAE 3000 is an internationally recognized standard that ensures that audits are carried out using uniform methods. This increases the quality and credibility of the audit results. Clients who rely on cloud providers being BSI C5-compliant can rely on the audit carried out in accordance with ISAE 3000 – and thus create trust in the provider’s services. In addition, companies can use the results of the BSI C5 audit carried out in accordance with ISAE 3000 for their risk management and governance processes to ensure that cooperation with the cloud provider meets the necessary information security requirements

Reporting Trends & Solutions

Your update from the world of auditing: Relevant insights on Audit, Reporting, ESG, GRC, Deals, Digital Transformation, Cybersecurity & more – compact, solution-oriented, and from a single source.

To the newsletter