ISO27002
Security controls framework
27017/18
Cloud management framework
ISO 27701
Personal Data and privacy
ISO 31000
Best for overall risk management assessment not just security
ISO 21000
Cyber security framework
SOC 2
CIAP
Service organisational controls - Evaluates internal controls for storing customer data
Confidentiality,
Integrity,
Availability,
Privacy
SSAE
Statement of standards for attestation - is a certified audit to ensure consumers that cloud providers are meeting professional standards
SOC2 Type 1
Assess the design and implementation
SOC2 Type 2
Assess the effectiveness of the design between 6 - 12 months
SOC 3
Is a high level certification to clarify compliance with SOC2