Security & Compliance
Standards and frameworks — what they mean for BaseCloud
Below is a brief overview of each area: what it is, which market and industry it applies to, and how BaseCloud supports design, operations, and evidence for audits. The product focus is EU organizations; US frameworks (SOC 2, HIPAA) are covered when an EU company works with US customers or data.
Formal certification status and audit reports are shared only when covered by contract and supported by documents (certificate, SOC report, registry entry). Here we describe how we help clients build operational alignment with these frameworks.
ISO/IEC 27001
Market: global / EU · Industry: enterprise, public procurement, B2B
Information security management system (ISMS)
International standard defining requirements for an information security management system: policies, risk, controls, continuous improvement, and internal audit. Often required by enterprise clients and tenders in the EU.
How BaseCloud supports this
- design of technical and organizational controls in the infrastructure layer,
- environment segregation, access management, logging, and hardening,
- evidence support (configurations, change procedures, monitoring) for client audits.
ISO/IEC 27017
Market: global / EU · Industry: cloud providers and consumers
Cloud services security
Extension of ISO 27001 with controls specific to cloud: provider–customer responsibility split, tenant isolation, hypervisor and API protection, image management, and key handling in a shared responsibility model.
How BaseCloud supports this
- clear responsibility model (RACI) in the managed cloud agreement,
- network and resource isolation, administrative panel controls,
- provisioning / deprovisioning procedures and secret protection.
ISO/IEC 27018
Market: global / EU · Industry: PII processing in cloud
Protection of personal data in public cloud
Guidelines for PII processors in public cloud: processing purposes, breach notification, data return/deletion, and limits on provider use of data for its own purposes.
How BaseCloud supports this
- EU data residency and control of processing location,
- processor agreements and data deletion / return procedures,
- operator access to client data limited to need-to-know.
ISO/IEC 27701
Market: EU (mapped to GDPR) · Industry: privacy / DPO
Privacy information management system (PIMS)
Extension of ISMS for privacy management: controller and processor roles, DPIA, data subject rights, processing records. Often mapped to GDPR requirements.
How BaseCloud supports this
- role mapping (controller / processor) in managed services,
- support for request handling and operational log retention,
- documentation of data flows in client infrastructure.
ISO 22301
Market: global / EU · Industry: continuity, critical services
Business continuity management (BCMS)
Business continuity standard: BIA analysis, BCP/DR plans, recovery testing, crisis communication. Key for organizations with high SLA requirements.
How BaseCloud supports this
- backup, replication, and DR scenarios agreed in contract,
- RTO/RPO and recovery testing on a contractual cycle,
- incident runbooks and 24/7 escalation.
SOC 2 Type II
Market: USA (AICPA origin) · often required by US clients and EU companies selling to the US · Industry: SaaS, B2B IT
Service organization controls report (Trust Services Criteria)
Independent auditor report (AICPA) assessing control effectiveness over time (Type II) across Security, Availability, Confidentiality, Processing Integrity, and Privacy. Not an EU legal requirement — it appears in due diligence when US or global enterprise partners expect a familiar report. EU companies typically combine it with GDPR / ISO 27001 rather than replacing EU obligations.
How BaseCloud supports this
- operational controls aligned with TSC (access, changes, monitoring),
- evidence collection for client audits,
- environment preparation for a potential independent Type II report.
CSA STAR
Market: global · Industry: cloud security due diligence
Cloud Security Alliance — Security, Trust, Assurance and Risk
CSA program assessing cloud provider security (CCM — Cloud Controls Matrix): from self-assessment (Level 1) to external audits. Useful in cloud provider due diligence.
How BaseCloud supports this
- mapping CCM controls to private / hybrid cloud architecture,
- responses to client security questionnaires,
- transparent description of responsibility boundaries and residual risk.
BSI C5
Market: Germany / EU · Industry: public procurement, regulated cloud
Cloud Computing Compliance Controls Catalogue (Germany)
BSI control catalogue for cloud services: security, data location, continuity, subcontractors. Often cited in DE/EU public procurement and when selecting providers for regulated sectors.
How BaseCloud supports this
- control design aligned with C5 expectations (including logging, IAM),
- clarity on data location and subcontractor chain,
- materials for client / auditor assessment.
EUCS
Market: European Union · Industry: cloud service providers
European Cybersecurity Certification Scheme for Cloud Services
European cloud certification scheme (ENISA / EU): assurance levels (Basic / Substantial / High) with technical and organizational requirements. Regulatory direction for cloud service providers in the EU.
How BaseCloud supports this
- architecture for EUCS assurance levels (isolation, auditability),
- tracking scheme requirements for EU enterprise projects,
- gap mapping and roadmap before potential provider certification.
NIS2
Market: European Union · Industry: essential and important entities (including ICT, healthcare, manufacturing, energy — per national implementation)
EU Network and Information Security Directive
Imposes cyber risk management, incident reporting, and board oversight obligations on essential and important entities in the EU (including digital infrastructure, manufacturing, healthcare, finance — depending on national implementation).
How BaseCloud supports this
- monitoring, detection, and incident escalation paths,
- hardening, patch management, and IT service continuity,
- documentation and evidence support for supervisor requirements.
DORA
Market: European Union · Industry: finance, fintech, critical ICT providers
Digital Operational Resilience Act
EU regulation for the financial sector: ICT resilience, testing, third-party risk management, incident reporting. Applies to banks, investment firms, fintechs, and critical ICT providers.
How BaseCloud supports this
- SLA, monitoring, and DR aligned with operational resilience requirements,
- contracts and evidence for the ICT supply chain,
- support for recovery testing and crisis communication.
GDPR
Market: EU / EEA · Industry: nearly all organizations processing personal data
General Data Protection Regulation
EU personal data protection framework: legal bases, data subject rights, processing agreements, breaches, transfers outside the EEA. Applies to nearly every organization processing personal data in the EU. For healthcare in the EU the primary basis is GDPR (plus national law) — not HIPAA; HIPAA applies when US patient data is involved.
How BaseCloud supports this
- processor agreements and limits on operator processing purposes,
- EU data location, access control, and log retention,
- support for procedures on requests and security incidents.
HIPAA
Market: United States · Industry: healthcare (PHI) · niche for EU↔US companies
Health Insurance Portability and Accountability Act (USA)
US framework for Protected Health Information (PHI): Privacy Rule, Security Rule, Breach Notification. Not EU law and does not replace GDPR for healthcare providers in Europe.
Typical cases where an EU company still needs to consider it:
- software or hosting provider for clinics or insurers in the US,
- processing US citizens' PHI on behalf of a HIPAA-covered entity (Business Associate),
- entering the US healthcare market or a contract requiring a BAA (Business Associate Agreement).
For EU-only healthcare and e-health, priority remains GDPR, possibly NIS2, and ISO controls — not US HIPAA frameworks.
How BaseCloud supports this
- isolation, encryption, logging, and access design aligned with Security Rule requirements,
- evidence and procedure support when a client signs a BAA with a US partner,
- role clarity: client as covered entity / business associate — BaseCloud as infrastructure layer.
Need these frameworks mapped to your environment? Book a consultation or email contact email.
Back to Compliance section · Knowledge base · About BaseCloud