ISO/IEC 27001:2022 sets specific requirements for how SaaS providers prevent data loss, delete customer information and dispose of media. Three Annex A controls govern this area: Control 5.23 (Information security for use of cloud services), Control 8.10 (Information deletion) and Control 8.11 (Data masking). The 2022 revision restructured these controls and introduced new documentation obligations that certification auditors now verify systematically.
Many SaaS organizations pursuing or maintaining ISO 27001 certification face a common pattern: leadership is accountable for implementing these controls, but no single executive owns the strategy, governance decisions or cross-functional coordination required. Engineering understands the technical mechanisms. Legal understands retention obligations. Security understands threats. The gap is executive ownership that translates the standard's requirements into decisions, assigns accountability and reports progress to the board.
What These Controls Require in Plain Terms
Control 5.23 addresses SaaS providers that themselves consume cloud infrastructure services. It requires documented processes for how the organization acquires, uses, manages and exits cloud service arrangements, including data deletion when those arrangements end. This control governs your provider relationships, not your customer relationships.
Control 8.10 governs how the SaaS provider deletes information stored in its systems, whether customer data, employee data or operational data. The standard requires documented deletion procedures that specify when deletion occurs, how it is performed, who authorises it and how deletion is verified. The control applies to all storage types, including backups, archives and replicated data.
Control 8.11 addresses data masking, the practice of obscuring sensitive information in non-production environments or when providing data for testing, development or analytics. The control requires documented rules for what data must be masked, the masking methods used and the access controls that govern masked datasets.
How the 2022 Revision Changed These Requirements
The 2013 edition of ISO 27001 addressed these topics under different control numbers and with less specificity. Control 5.23 on cloud services is entirely new to the 2022 revision, reflecting the maturity of cloud infrastructure and the specific risks that arise when a SaaS provider depends on underlying cloud platforms.
Information deletion appeared in the 2013 edition under Control A.11.2.7 (Secure disposal or reuse of equipment) and Control A.8.3.2 (Disposal of media). The 2022 revision consolidated and expanded this into Control 8.10, adding explicit requirements for deletion of information independent of hardware disposal. The new control requires documented procedures for logical deletion, not just physical media destruction.
Data masking existed in the 2013 edition as Control A.12.3.1 (Information backup) and was implied in controls addressing development and test environments. The 2022 revision made masking an explicit standalone control, requiring SaaS providers to document masking policies and verify their effectiveness.
What Must Be Documented for Certification
Certification auditors will verify that documented policies and procedures exist for each control and that those procedures are followed in practice. For Control 5.23, this means documented criteria for selecting cloud providers, contracts that specify data location and deletion obligations, and procedures for terminating cloud services including data recovery or destruction.
For Control 8.10, documentation must specify deletion timelines tied to retention schedules, the technical methods used for deletion (overwriting, cryptographic erasure, physical destruction), who can authorise deletion, and how the organisation verifies that deletion has occurred across all storage locations including backups and disaster recovery sites.
For Control 8.11, documentation must define what constitutes sensitive information requiring masking, the masking techniques applied (tokenisation, hashing, synthetic data generation), the environments where masking is mandatory, and testing procedures to confirm that masked data cannot be reversed to reveal the original values.
Auditors will also verify that these documented procedures integrate with the organisation's broader information security management system, including risk assessments, internal audits and management review processes required by the core ISO 27001 clauses.
Why This Matters to the Business
Certification auditors can issue nonconformities for missing or inadequate documentation of these controls, delaying certification or requiring remediation within tight timelines. If the organisation holds certification and fails to maintain these controls, surveillance audits can result in suspension or withdrawal of the certificate, which affects customer contracts that require valid ISO 27001 status.
Beyond audit outcomes, inadequate deletion procedures create legal and regulatory risk. Many privacy regimes, including GDPR and state privacy laws, require that organisations delete personal data when it is no longer needed for its original purpose or when an individual exercises a deletion right. A SaaS provider that cannot demonstrate systematic deletion across all storage locations faces enforcement risk and reputational harm.
Data loss prevention failures have different consequences. If the organisation's cloud provider relationship lacks documented exit procedures, a contract dispute or provider failure can leave customer data inaccessible or unrecoverable. If masking procedures are absent or poorly documented, sensitive production data migrates into development environments where access controls are weaker and breach risk is higher.
Who Owns These Requirements and What Ownership Looks Like
ISO 27001 requires that top management assign responsibility for the information security management system and report on its performance. For Controls 5.23, 8.10 and 8.11, effective ownership means a single executive who can make risk decisions, allocate resources, coordinate across engineering, legal and compliance functions, and report status to the board in business terms.
In practice, many SaaS organisations delegate these controls to the Chief Technology Officer, Chief Information Security Officer or VP of Engineering. This creates a structural problem: these roles own implementation but lack the enterprise risk perspective and cross-functional authority needed to resolve conflicts between business objectives, customer commitments and compliance timelines.
Adequate ownership has three characteristics. First, the owner can articulate the business risk these controls address in terms the board and executive team understand, without requiring technical depth. Second, the owner has decision authority to resolve resource conflicts and approve exceptions. Third, the owner reports progress and risk exposure to executive leadership on a defined schedule, using metrics that reveal whether the organisation is maintaining compliance or accumulating technical debt.
The owner does not personally write deletion procedures or configure masking tools. The owner ensures that accountability is clear, that procedures exist and are tested, and that when gaps emerge, they are escalated and addressed before they become audit findings.
How This Relates to Cloud Security Architecture and Governance
Control 5.23 on cloud services sits within a broader architectural question: how does the SaaS provider structure its use of cloud infrastructure to meet security, compliance and operational requirements. This is not a technical question alone. It requires governance decisions about acceptable risk, vendor concentration, data residency and exit strategy.
A SaaS provider may rely on a single cloud infrastructure provider for all storage and compute, use multiple providers for different functions or maintain hybrid infrastructure with on-premises components. Each architectural choice affects how deletion is performed, how data loss prevention controls are implemented and what contractual protections are required from cloud providers. These are board-level risk decisions, not implementation details.
Control 8.10 on information deletion intersects with cloud architecture when data replication, backup and disaster recovery systems span multiple regions or providers. A documented deletion procedure that addresses only the primary production database will fail audit if backup systems in other regions retain the same data indefinitely. The governance question is whether the organisation has systematically identified all data stores and assigned deletion accountability for each.
Control 8.11 on data masking connects to cloud governance when development and test environments use infrastructure separate from production. If those environments are managed by different teams with different access controls, a documented masking policy must specify how sensitive data moves between environments and who verifies that masking has occurred. This is an organisational design question, not a technical one.
Organisations pursuing ISO 27001 certification often approach cloud security architecture as a technical project led by engineering. The certification process reveals that it is a governance problem requiring executive decision-making, documented policies and ongoing risk management. Heights provides [virtual CISO leadership](/vciso/) that translates these requirements into strategy, assigns accountability and reports progress to the board in business terms.
Practical Next Steps for Leadership
If your organisation is pursuing or maintaining ISO 27001 certification, begin by identifying who currently owns Controls 5.23, 8.10 and 8.11. If ownership is unclear or distributed across multiple functions, that is the first risk to address.
Review the documented procedures for each control. If procedures do not exist, specify who will draft them and the timeline for completion. If procedures exist but are generic or copied from templates, verify that they reflect the organisation's actual practices, including specific cloud providers, storage systems and deletion methods.
For Control 5.23, list all cloud infrastructure providers the organisation uses, verify that contracts specify data deletion obligations at termination, and document the procedure for exiting each provider relationship. If contracts do not address deletion, flag this as a commercial risk requiring legal review.
For Control 8.10, identify all locations where information is stored, including primary databases, backups, disaster recovery sites, archived data and replicated systems. Verify that documented deletion procedures address each location and specify timelines consistent with retention schedules. Test deletion procedures to confirm they function as documented.
For Control 8.11, identify environments where sensitive data is used outside production, including development, test, staging and analytics systems. Document the masking requirements for each environment, the techniques applied and the testing procedures used to verify masking effectiveness. If masking is not currently performed, this is a compliance gap requiring immediate attention.
Establish a reporting schedule where the executive owner of these controls provides status to the leadership team. The report should state whether procedures are documented, tested and followed, whether gaps exist, and what resources or decisions are required to address them. This creates visibility and accountability before an auditor requests evidence.
If your organisation lacks the executive capacity to own these controls, or if the current owner lacks the enterprise risk perspective to translate technical requirements into business decisions, that is a structural gap. Heights provides virtual CISO leadership to close this gap: strategy, governance, risk decisions, regulatory positioning and board-level reporting. If you are uncertain whether your organisation has adequate ownership, a confidential consultation will clarify the options and what adequate looks like in your specific context. Contact Heights directly to arrange a discussion.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Cloud Security Architecture and Governance
Design and governance for cloud environments: what the provider secures, what remains yours, and how you keep track of a platform that changes underneath you.