E005—Assess cloud vs on-prem processing
>Control Description
Establish criteria for selecting cloud provider, and circumstances for on-premises processing considering data sensitivity, regulatory requirements, security controls, and operational needs
Application
Mandatory
Frequency
Every 12 monthsCapabilities
Universal
>Controls & Evidence (1)
Operational Practices
E005.1
Documentation: Deployment decisionsCore - This should include:
- Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs, and security controls for cloud vs. on-premises AI processing. - Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices with business justification. - Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat landscape evolves.
Typical evidence: Risk assessment and decision record evaluating cloud vs. on-premises factors (e.g. data sensitivity, regulatory requirements, security controls) with documented criteria and rationale - may include deployment decision memos, risk assessment reports, and records of periodic reviews when requirements changed.
Location: Internal processes
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.