Overview
ISO/IEC TR 23187:2020 - Information technology - Cloud computing - Interacting with cloud service partners (CSNs) - is a Technical Report (first edition, June 2020) from ISO/IEC JTC 1/SC 38. It provides an explanatory framework and practical guidance on interactions between cloud service partners (CSNs) - notably cloud service brokers, cloud service developers and cloud auditors - and other cloud roles such as cloud service providers (CSPs) and cloud service customers (CSCs). The report clarifies roles, sub‑roles, responsibilities and how cloud service agreements (CSAs) and cloud SLAs can be used to manage those interactions.
Key topics and elements (guidance, not prescriptive requirements)
- Definition of terms and concepts: Aligns CSN terminology with ISO cloud vocabulary to reduce role ambiguity in multi‑party cloud environments.
- Roles, sub‑roles and responsibilities: Detailed overview of CSNs, CSPs, CSCs and cloud service users (CSUs), including role relationships and risk considerations.
- Types of CSN interactions: Describes CSN-to-CSC, CSN-to-CSP and CSN-to‑CSN interactions and common interaction patterns (e.g., reselling, managed services, service exchanges).
- Use of CSAs and cloud SLAs: Guidance on elements to include in agreements and SLAs to ensure clarity about responsibilities, performance, security, data handling and audit rights.
- Cloud adoption and migration context: Guidance on CSN roles during cloud migrations and different deployment models.
- Examples and scenarios: Practical scenarios illustrating reselling, cloud service exchange, managed services and cloud data management to show typical responsibilities and risks.
- Risk and relationship management: Advice on mapping activities to contractual clauses and on accountability across multi‑provider or brokered environments.
Note: ISO/IEC TR 23187:2020 is a technical report offering guidance and examples rather than normative requirements.
Practical applications - who uses it
- Cloud service customers (CSCs) and enterprise buyers - to understand brokered services, audit rights and SLA coverage.
- Cloud service providers (CSPs) - to define contractual interfaces and responsibilities when partnering with brokers or auditors.
- Cloud service brokers and developers (CSNs) - to document role boundaries, manage consumer expectations and structure CSAs/SLAs.
- Auditors, compliance and procurement teams - to design audit clauses, assess third‑party risk, and craft enforceable SLAs.
- Cloud architects and risk managers - to map functional responsibilities across multi‑cloud deployments.
Related standards
Using ISO/IEC TR 23187:2020 helps organizations and partners reduce ambiguity in cloud ecosystems, improve contractual clarity, and better manage operational, security and compliance risks in brokered or multi‑party cloud services.