7–9 Apr 2026
Jaarbeurs Supernova
Europe/Amsterdam timezone

Security Days Organisational Committee

My cloud vendor is compliant, how does that help me?

9 Apr 2026, 09:30
25m
Mission 1 Room (Jaarbeurs Supernova)

Mission 1 Room

Jaarbeurs Supernova

Utrecht, Netherlands
Single Presentation (25 min) Presentations 2 Governance, Risk & Compliance

Speakers

John Segers (SURF) Shiyona Keenakkottil (SURF)

Description

The GÉANT cloud framework - OCRE 2024 - is very successul in terms of adoption among SURF's institutions. As part of our SURFcumulus service, we perform compliance checks on the OCRE 2024 vendors available in The Netherlands. A requirement on the vendors is that they are ISO 27001 compliant.

Compliance reports on information security, particularly reports from American hyperscalers, are hundreds of pages in size. Many of the institutions we serve lack the resources and expertise to analyze these reports. We centralized the effort, leveraging the expertise from SURF's Vendor Compliance team.

In our presentation we discuss what we learnt from our analysis of ISO 27001, SOC 2, C5, and CSA STAR reporting from the 4 vendors that have the most usage in The Netherlands. We discuss our approach, our engagement with the vendors, the high-level results and our reporting to our user community. Along the way we learn that diving into the details of information security compliance leads to valuable insights into the different approaches that vendors take to information security and compliance.

Authors

John Segers (SURF) Shiyona Keenakkottil (SURF)

Presentation materials