Cloud compliance: SOC 2, ISO 27017, ISO 27018, CSA STAR and FedRAMP
Cloud compliance standards compared: SOC 2, ISO 27017/27018, CSA STAR, FedRAMP, BSI C5 and EUCS - requirements and certification paths.
Summary: IT security compliance refers to adherence to legal provisions, regulatory requirements, and contractual obligations in the field of information security. Relevant frameworks for German companies: GDPR, NIS2, ISO 27001, BSI IT-Grundschutz, KRITIS Regulation, industry-specific regulations (BAIT, VAIT, KAIT).
Questions about this topic?
Our experts advise you free of charge and without obligation.
About the Author
Dipl.-Math. (WWU Münster) and doctoral candidate at the Promotionskolleg NRW (Hochschule Rhein-Waal), researching phishing awareness, behavioral security and nudging in IT security. Responsible for building and maintaining ISMS, leads internal audits to ISO/IEC 27001:2022 and advises as an external information security officer (ISB) in KRITIS sectors. Lecturer for Communication Security at Hochschule Rhein-Waal and NIS2 training lead at isits AG.
3 Publikationen
- Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations Across Different Industries (2025)
- Self-promotion with a Chance of Warnings: Exploring Cybersecurity Communication Among Government Institutions on LinkedIn (2024)
- Exploring the Effects of Cybersecurity Awareness and Decision-Making Under Risk (2024)