Provides cloud service customers and cloud service providers with guidance on gaining visibility into the information security risks associated with the use of cloud services and managing those risks effectively, and responding to risks specific to the acquisition or provision of cloud services that can have an information security impact on organizations using these services. The scope of this standard is to define guidelines supporting the implementation of information security management for the use of cloud services.