Organizations have the option to submit either security or privacy self-assessments, or both. Level 1 is suitable for organizations that:
- Operate within a low-risk environment.
- Seek to enhance transparency regarding their security controls.
- Aim for a cost-effective means to bolster trust and transparency.
Level 2 enables organizations to tailor industry certifications and standards specifically for cloud services. Organizations should consider Level 2 if they:
- Operate in a medium-to-high risk environment.
- Already hold or adhere to certifications such as ISO 27001 orSOC 2.
- Are looking for a cost-effective approach to enhance assurance in cloud security and privacy.