2.5 Artificial Intelligence and Cloud Computing Characteristics
Key Takeaways
- PECB's ISO/IEC 27001:2022 Foundation Domain 1 explicitly requires knowledge of the main characteristics of artificial intelligence and cloud computing.
- Cloud computing is typically characterized by on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service — with shared-responsibility implications for the ISMS.
- Artificial intelligence systems introduce distinctive risks around training data confidentiality, model integrity, automated decision availability, bias, opacity, and third-party model/API supply chains.
- ISO/IEC 27001:2022 Annex A maps these topics into controls such as A.5.23 (cloud services) and organizational/technological controls that also apply to AI-enabled processing.
- Foundation questions test recognition of characteristics and ISMS implications — not deep ML engineering or cloud architecture design.
PECB's ISO/IEC 27001:2022 Foundation Candidate Handbook lists an explicit Domain 1 knowledge statement: candidates must know the main characteristics of artificial intelligence and cloud computing. This is not an optional side topic. The 2022 revision of ISO/IEC 27001 also elevated related controls — notably A.5.23 Information security for use of cloud services — so Foundation questions commonly test whether you can recognize cloud and AI characteristics and map them to ISMS responsibilities.
Why AI and Cloud Appear on a Foundation Exam
Modern organizations process information on shared infrastructure they do not fully control, and they increasingly automate decisions with models they did not fully train. Both patterns change the context (Clause 4), the risk picture (Clause 6), and the controls an organization must justify in the Statement of Applicability. The Foundation exam expects vocabulary-level fluency, not cloud-architect or data-scientist depth.
Cloud Computing — Characteristics You Must Recognize
Cloud computing delivers computing resources (compute, storage, networks, applications) over a network with service-provider management of the underlying infrastructure. Foundation-level characteristics to recognize:
| Characteristic | What it means for the ISMS |
|---|---|
| On-demand self-service | Users provision resources without human interaction with the provider — shadow IT and uncontrolled SaaS adoption become real risks |
| Broad network access | Services are reachable over networks/devices — perimeter assumptions weaken; access control and cryptography matter more |
| Resource pooling | Multi-tenant shared infrastructure — isolation, data residency, and co-tenant residual risk must be considered |
| Rapid elasticity / scalability | Capacity expands and contracts quickly — capacity management (A.8.6) and change control still apply |
| Measured service | Usage is metered — useful for accountability, but metering logs themselves become sensitive assets |
Shared responsibility
Cloud does not transfer accountability for the organization's information security outcomes. The cloud customer remains responsible for classifying information, defining scope, assessing risk, selecting controls, and verifying that the provider's controls are adequate for the residual risk the organization accepts. Contracts, SLAs, audit rights, and supplier due diligence sit under organizational controls (including A.5.19–A.5.23 style supplier/cloud themes).
Common deployment and service models (exam recognition level)
- IaaS / PaaS / SaaS — who manages OS, middleware, and application controls shifts; the customer's residual obligations shrink as the provider manages more layers, but they never reach zero.
- Public / private / hybrid / community — tenancy and control boundaries change; public cloud typically increases multi-tenant and geographic considerations.
Annex A anchors for cloud
- A.5.23 Information security for use of cloud services — new in 2022; organizational control covering acquisition and use of cloud services according to the organization's information security requirements.
- Related supplier, cryptography, logging, backup, and redundancy controls still apply depending on the risk treatment.
- Guidance companions (not certifiable alone): ISO/IEC 27017 (cloud security code of practice) and ISO/IEC 27018 (PII protection in public clouds acting as PII processors).
Artificial Intelligence — Characteristics You Must Recognize
Artificial intelligence (AI) systems perform tasks that typically require human intelligence — classification, prediction, generation, recommendation — often by learning patterns from data. Foundation-level characteristics:
| Characteristic | Information-security implication |
|---|---|
| Data dependence | Models are trained or tuned on datasets; training data can leak confidential information or embed privacy risks |
| Probabilistic outputs | Answers can be wrong even when confident — integrity and reliability of automated decisions become ISMS concerns |
| Opacity / limited explainability | Harder to evidence why a decision was made — accountability and auditability need compensating controls |
| Continuous change | Retraining or prompt/configuration changes alter behavior — change management and testing matter |
| Third-party model/API supply chain | Many organizations consume external models; supplier risk and contractual controls apply |
| Automation at scale | Errors or abuse propagate quickly — availability and misuse scenarios (prompt injection, model theft, data poisoning) enter the risk register |
CIA framing for AI (exam-friendly)
- Confidentiality — training sets, prompts, embeddings, and model parameters may contain or reveal sensitive information.
- Integrity — poisoned training data, unauthorized model changes, or corrupted inference pipelines produce wrong outputs.
- Availability — model-serving outages, rate limits, or resource exhaustion can stop AI-dependent processes.
AI does not replace the ISMS. It expands the set of assets, threats, and controls the organization must consider under the same Clauses 4–10 process.
How Foundation Questions Usually Look
Expect recognition items such as:
- Which characteristic of cloud computing describes multi-tenant shared infrastructure? → resource pooling
- Who remains accountable for information security when workloads move to a public cloud? → the organization (customer), even though the provider operates infrastructure
- Which 2022 Annex A control specifically addresses use of cloud services? → A.5.23
- Why does AI heighten integrity risk? → probabilistic outputs and susceptibility to poisoned or manipulated inputs
Exam Traps
- "Moving to the cloud transfers ISMS accountability to the provider." Wrong. Accountability stays with the organization; the provider becomes a supplier/interested party in the risk picture.
- "ISO/IEC 27017 certification replaces 27001." Wrong. 27017/27018 are guidance; organizational certificates are still issued against 27001 (and optionally privacy extensions such as 27701).
- "AI is outside ISO/IEC 27001 because the standard never says 'AI'." Wrong. Domain 1 explicitly tests AI characteristics, and Annex A/organizational risk treatment still apply to AI-enabled processing.
- "A.5.23 is a technological control because cloud is technical." Wrong. A.5.23 is Organizational (A.5.x), even though the subject is cloud.
- "Elasticity means capacity management no longer applies." Wrong. Rapid scaling changes how capacity is obtained; the ISMS still needs capacity and change control appropriate to the risk.
Linking Back to the Rest of the Guide
When you reach Annex A organizational controls, treat cloud services security (A.5.23) as the control that formalizes what this section introduces conceptually. When you reach Clause 8 operation, remember outsourced cloud processes must still be controlled. When you write a Statement of Applicability, cloud and AI-related controls are included or excluded with justification — never silently omitted.
According to PECB's ISO/IEC 27001:2022 Foundation Domain 1 knowledge statements, which emerging-technology topic must candidates be able to describe at a characteristic level?
An organization migrates a customer database to a public cloud provider. Which statement is correct for an ISO/IEC 27001 ISMS?
Which ISO/IEC 27001:2022 Annex A control specifically addresses information security for use of cloud services, and in which theme does it sit?