Page Text: Contact a Specialist
C5 Attestation
In response to the ever-growing need to consider information security in the cloud computing world, the C5 Attestation or Cloud Computing Compliance Criteria Catalogue, was published. The program is a baseline of security controls that was developed by the Federal Office for Information Security in Germany, BSI.
Contact a Specialist Build Your Compliance Roadmap
Why C5 Attestation?
With the C5 security controls baseline cloud service providers (CSPs) are able to better develop transparent and trusted relationships between themselves and their cloud customers. The catalogue of controls pulls from internationally recognized standards such as International Organization for Standardization (ISO) 27001, ISO 27002, and ISO 27017, as well as the Cloud Control Matrix (CCM) of the Cloud Security Alliance (CSA).
Type 1 Schellman performs a “Type 1” C5 examination when management requires a report on the fairness of presentation of the CSP’s system and the suitability of the design of controls as of a specified date.
Type 2 A “Type 2” C5 examination is performed when management requires a report on the fairness of presentation of the CSP’s system and the suitability of the design and operating effectiveness of controls over a period of time.
Your organization specifies whether a Type 1 or Type 2 examination will be performed for the C5 report
Type 1 Schellman performs a “Type 1” C5 examination when management requires a report on the fairness of presentation of the CSP’s system and the suitability of the design of controls as of a specified date.
Type 2 A “Type 2” C5 examination is performed when management requires a report on the fairness of presentation of the CSP’s system and the suitability of the design and operating effectiveness of controls over a period of time.
Our Process
We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.
1. Planning