Speakers
Description
The GÉANT cloud framework - OCRE 2024 - is very successul in terms of adoption among SURF's institutions. As part of our SURFcumulus service, we perform compliance checks on the OCRE 2024 vendors available in The Netherlands. A requirement on the vendors is that they are ISO 27001 compliant.
Compliance reports on information security, particularly reports from American hyperscalers, are hundreds of pages in size. Many of the institutions we serve lack the resources and expertise to analyze these reports. We centralized the effort, leveraging the expertise from SURF's Vendor Compliance team.
In our presentation we discuss what we learnt from our analysis of ISO 27001, SOC 2, C5, and CSA STAR reporting from the 4 vendors that have the most usage in The Netherlands. We discuss our approach, our engagement with the vendors, the high-level results and our reporting to our user community. Along the way we learn that diving into the details of information security compliance leads to valuable insights into the different approaches that vendors take to information security and compliance.