Cloud service provider assessments require evaluating ISM controls across multiple environments while delineating which controls are the provider's responsibility and which are the consumer's. CyberFrame handles this split natively so assessors can focus on evaluation, not spreadsheet management.
Assessment Scopes
A Cloud Service Provider (CSP) assessment evaluates the security posture of a cloud service and its provider against the Australian Government Information Security Manual (ISM). It is typically required when government agencies or organisations handling sensitive data use cloud services that need to meet specific classification requirements.
CSP assessments differ from standard IRAP assessments in that they must account for the shared responsibility model inherent in cloud computing. Some ISM controls are the responsibility of the cloud provider, some are the responsibility of the consumer (the organisation using the service), and some are shared. The assessment must clearly delineate who is responsible for what.
The assessment covers three distinct environment scopes: the administration environment (management plane), cloud production common (shared infrastructure), and cloud production service (the specific service being assessed). Each environment may have different controls and different responsibility splits.
CSP assessments are conducted by ASD-endorsed assessors and follow a similar methodology to IRAP assessments. The key difference is the multi-environment scoping and the consumer/provider responsibility mapping that must be documented in the assessment report.
CSP assessments add a layer of complexity that standard assessment tools do not handle: every control must be evaluated across multiple environments with a clear consumer/provider responsibility assignment for each. Tracking which party is responsible for which control in which environment, and producing a report that clearly documents these splits, requires a platform that understands the CSP model.
Assess controls across administration, cloud production common, and cloud production service environments. Each environment is scoped independently with its own applicable controls and evaluation status.
For every control in every environment, document whether the responsibility lies with the consumer, the provider, or is shared. The responsibility mapping is built into the evaluation workflow, not tracked separately.
The ISM control library is scoped to the controls relevant for cloud assessments. Classification-level applicability filtering ensures assessors evaluate the right controls for the target classification level.
Evaluate each control separately within each environment scope. The evaluation grid shows controls by environment by asset group, giving assessors complete visibility into coverage and status across the entire cloud service.
Report templates structured for CSP assessments with sections that clearly distinguish consumer and provider findings per environment. Classification markings and ASD formatting requirements are handled automatically.
A dedicated workflow structured around the CSP assessment methodology with phases, objectives, and activities specific to cloud service provider evaluation. Structured test methods guide assessors through cloud-specific control evaluation.
See how CyberFrame handles multi-environment scoping, consumer/provider responsibility mapping, and CSP-specific reporting in a single platform.