Cloud & SaaS
Cloud vendor assessment, on evidence
SaaS, IaaS and PaaS vendors publish a lot of documentation — SOC 2, ISO 27001, CSA CAIQ/STAR, DPAs, security white papers and architecture docs. Governly maps your requirements to that evidence and turns it into a traceable assessment that supports NIS2 and DORA expectations.
Typical evidence we review
- SOC 2 Type II reports
- ISO 27001 certificate and SoA
- CSA CAIQ / STAR self-assessment
- Data Processing Agreement (DPA)
- Security white paper & architecture
- Sub-processor list and transfer mechanisms
- Penetration test summary
- Business continuity & DR plans