Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Compliance in Italy: Navigating the New Cloud Italy Strategy

ISO Certifications | CSA STAR Program

As the world becomes increasingly digital, governments around the world are taking measures to ensure the safety and security of their citizens' data.

 

One such example is the recent Cloud Italy Strategy, initiated by the Italian Agency for National Cybersecurity (ACN) which outlines specific compliance requirements for cloud service providers serving the Italian public sector.

 

Whether your organization is based in Italy or elsewhere, this new development may impact your cloud services and compliance efforts. 

That’s why, in this article, we’re going to leverage our extensive experience with the relevant ISO standards and Cloud Security Alliance (CSA) STAR Programs to disseminate Cloud Italy Strategy requirements so that cloud providers understand this new standard for cybersecurity more clearly.

 

Cloud Italy Strategy Data and Service Classifications

If you’re a cloud service provider that services (or potentially would seek to service) the Italian public sector, you will need to have to meet the requirements of this ACN Cloud Italy Strategy.

 

From what we know, there are three classifications of data and services within the Cloud Italy Strategy:

  • Ordinary (QC1)
  • Critical (QC2)
  • Strategic (QC3)

 Though Strategic is the highest classification—meaning it requires the most certifications—the ACN anticipates that the majority of CSPs will be considered Ordinary or Critical. Still, however you do classify, you’ll have to demonstrate the related minimum compliance requirements that, depending on the classification, could include the following:

 

Cloud Italy Strategy Compliance Requirements

How these certifications and requirements break down by classification is as follows:

 

Classification

Requirements

Ordinary (QC1)

  • ISO 9001 certification: Requires implementation of a Quality Management System (QMS) for your cloud service that is subject to qualification
  • ISO/IEC 27001:2013 certification: Requires implementation of an Information Security Management System (ISMS) for your cloud service with the following extensions that are subject to qualification:

o   ISO/IEC 27017:2015 certification; and

o   ISO/IEC 27018:2019.

(As an alternative to the above ISO 27001 requirement, you can instead acquire Cloud Security Alliance - Star Level 2 certification.)

Critical (QC2)

  • Meet all QC1 requirements, AND
  • Self-attestation for ISO 22301: Requires your attesting to compliance with the Business Continuity Management System standard for your cloud service that is subject to qualification.
  • Self-attestation for ISO 20000-1: Requires your attesting to compliance with the Service Management System standard for your cloud service that is subject to qualification.

Strategic (QC3)

 

Such certification requirements demonstrate a clear commitment to cybersecurity, but in fact, there’s more to do—in addition to these mandates noted above, cloud service providers will also have to ensure that they have controls and processes in place based on the Italian National Cybersecurity Framework as relevant to the cloud service provider’s classification. 

What is the Timeline for Cloud Italy Strategy?

As much of a load this may seem to be, you unfortunately don’t have much time to begin your preparation—the Italian government has set a deadline of July 2023 for compliance with these new requirements.

 While we believe this to be an aggressive timeline, our team at Schellman is ready to assist any organization that will need to make the effort so that you can further understand and meet these requirements as quickly as possible.

 For those who have already met the requirements of the previous Italian cloud scheme, you have a bit more of a reprieve in that the country has set January 2024 as your deadline to demonstrate compliance, but should you have any questions, we are here to guide you through this process as well. 

How Schellman Can Help with the New Cloud Italy Strategy

At Schellman, we have been working with CSA STAR for years and now field a team of highly trained experts in ISO 9001, ISO 27001, ISO 22301, and ISO 20000-1. As such, we can help you navigate these new requirements and ensure that you are fully compliant with the standards required for servicing the Italian public sector.

 With our support, you can be confident in your ability to provide the best service to your customers while meeting compliance obligations. To ease this transition, please reach out to us directly to schedule a consultation.

 

About Schellman

Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.