The global Security & Trust Hub is the single source of truth for infrastructure assurance, shared responsibility and evidence. This page remains a market-oriented standards overview.

Security & Compliance

Standards and frameworks — what they mean for BaseCloud

Below is a brief overview of each area: what it is, which market and industry it applies to, and how BaseCloud supports design, operations, and evidence for audits. The product focus is EU organizations; US frameworks (SOC 2, HIPAA) are covered when an EU company works with US customers or data.

Formal certification status and audit reports are shared only when covered by contract and supported by documents (certificate, SOC report, registry entry). Here we describe how we help clients build operational alignment with these frameworks.

ISO/IEC 27001

Market: global / EU · Industry: enterprise, public procurement, B2B

Information security management system (ISMS)

International standard defining requirements for an information security management system: policies, risk, controls, continuous improvement, and internal audit. Often required by enterprise clients and tenders in the EU.

How BaseCloud supports this

  • design of technical and organizational controls in the infrastructure layer,
  • environment segregation, access management, logging, and hardening,
  • evidence support (configurations, change procedures, monitoring) for client audits.

ISO/IEC 27017

Market: global / EU · Industry: cloud providers and consumers

Cloud services security

Extension of ISO 27001 with controls specific to cloud: provider–customer responsibility split, tenant isolation, hypervisor and API protection, image management, and key handling in a shared responsibility model.

How BaseCloud supports this

  • clear responsibility model (RACI) in the managed cloud agreement,
  • network and resource isolation, administrative panel controls,
  • provisioning / deprovisioning procedures and secret protection.

ISO/IEC 27018

Market: global / EU · Industry: PII processing in cloud

Protection of personal data in public cloud

Guidelines for PII processors in public cloud: processing purposes, breach notification, data return/deletion, and limits on provider use of data for its own purposes.

How BaseCloud supports this

  • EU data residency and control of processing location,
  • processor agreements and data deletion / return procedures,
  • operator access to client data limited to need-to-know.

ISO/IEC 27701

Market: EU (mapped to GDPR) · Industry: privacy / DPO

Privacy information management system (PIMS)

Extension of ISMS for privacy management: controller and processor roles, DPIA, data subject rights, processing records. Often mapped to GDPR requirements.

How BaseCloud supports this

  • role mapping (controller / processor) in managed services,
  • support for request handling and operational log retention,
  • documentation of data flows in client infrastructure.

ISO 22301

Market: global / EU · Industry: continuity, critical services

Business continuity management (BCMS)

Business continuity standard: BIA analysis, BCP/DR plans, recovery testing, crisis communication. Key for organizations with high SLA requirements.

How BaseCloud supports this

  • backup, replication, and DR scenarios agreed in contract,
  • RTO/RPO and recovery testing on a contractual cycle,
  • incident runbooks and 24/7 escalation.

SOC 2 Type II

Market: USA (AICPA origin) · often required by US clients and EU companies selling to the US · Industry: SaaS, B2B IT

Service organization controls report (Trust Services Criteria)

Independent auditor report (AICPA) assessing control effectiveness over time (Type II) across Security, Availability, Confidentiality, Processing Integrity, and Privacy. Not an EU legal requirement — it appears in due diligence when US or global enterprise partners expect a familiar report. EU companies typically combine it with GDPR / ISO 27001 rather than replacing EU obligations.

How BaseCloud supports this

  • operational controls aligned with TSC (access, changes, monitoring),
  • evidence collection for client audits,
  • environment preparation for a potential independent Type II report.

CSA STAR

Market: global · Industry: cloud security due diligence

Cloud Security Alliance — Security, Trust, Assurance and Risk

CSA program assessing cloud provider security (CCM — Cloud Controls Matrix): from self-assessment (Level 1) to external audits. Useful in cloud provider due diligence.

How BaseCloud supports this

  • mapping CCM controls to private / hybrid cloud architecture,
  • responses to client security questionnaires,
  • transparent description of responsibility boundaries and residual risk.

BSI C5

Market: Germany / EU · Industry: public procurement, regulated cloud

Cloud Computing Compliance Controls Catalogue (Germany)

BSI control catalogue for cloud services: security, data location, continuity, subcontractors. Often cited in DE/EU public procurement and when selecting providers for regulated sectors.

How BaseCloud supports this

  • control design aligned with C5 expectations (including logging, IAM),
  • clarity on data location and subcontractor chain,
  • materials for client / auditor assessment.

EUCS

Market: European Union · Industry: cloud service providers

European Cybersecurity Certification Scheme for Cloud Services

European cloud certification scheme (ENISA / EU): assurance levels (Basic / Substantial / High) with technical and organizational requirements. Regulatory direction for cloud service providers in the EU.

How BaseCloud supports this

  • architecture for EUCS assurance levels (isolation, auditability),
  • tracking scheme requirements for EU enterprise projects,
  • gap mapping and roadmap before potential provider certification.

NIS2

Market: European Union · Industry: essential and important entities (including ICT, healthcare, manufacturing, energy — per national implementation)

EU Network and Information Security Directive

Imposes cyber risk management, incident reporting, and board oversight obligations on essential and important entities in the EU (including digital infrastructure, manufacturing, healthcare, finance — depending on national implementation).

How BaseCloud supports this

  • monitoring, detection, and incident escalation paths,
  • hardening, patch management, and IT service continuity,
  • documentation and evidence support for supervisor requirements.

More: NIS2 compliance as a service

DORA

Market: European Union · Industry: finance, fintech, critical ICT providers

Digital Operational Resilience Act

EU regulation for the financial sector: ICT resilience, testing, third-party risk management, incident reporting. Applies to banks, investment firms, fintechs, and critical ICT providers.

How BaseCloud supports this

  • SLA, monitoring, and DR aligned with operational resilience requirements,
  • contracts and evidence for the ICT supply chain,
  • support for recovery testing and crisis communication.

More: DORA for fintech

GDPR

Market: EU / EEA · Industry: nearly all organizations processing personal data

General Data Protection Regulation

EU personal data protection framework: legal bases, data subject rights, processing agreements, breaches, transfers outside the EEA. Applies to nearly every organization processing personal data in the EU. For healthcare in the EU the primary basis is GDPR (plus national law) — not HIPAA; HIPAA applies when US patient data is involved.

How BaseCloud supports this

  • processor agreements and limits on operator processing purposes,
  • EU data location, access control, and log retention,
  • support for procedures on requests and security incidents.

BaseCloud privacy policy

HIPAA

Market: United States · Industry: healthcare (PHI) · niche for EU↔US companies

Health Insurance Portability and Accountability Act (USA)

US framework for Protected Health Information (PHI): Privacy Rule, Security Rule, Breach Notification. Not EU law and does not replace GDPR for healthcare providers in Europe.

Typical cases where an EU company still needs to consider it:

  • software or hosting provider for clinics or insurers in the US,
  • processing US citizens' PHI on behalf of a HIPAA-covered entity (Business Associate),
  • entering the US healthcare market or a contract requiring a BAA (Business Associate Agreement).

For EU-only healthcare and e-health, priority remains GDPR, possibly NIS2, and ISO controls — not US HIPAA frameworks.

How BaseCloud supports this

  • isolation, encryption, logging, and access design aligned with Security Rule requirements,
  • evidence and procedure support when a client signs a BAA with a US partner,
  • role clarity: client as covered entity / business associate — BaseCloud as infrastructure layer.

Need these frameworks mapped to your environment? Book a consultation or email contact email.

Back to Compliance section · Knowledge base · About BaseCloud