How should cloud providers handle Government Access requests under ISO/IEC 27018?
Treat each Government Access request as a legal and incident-response event: verify that the request is valid, confirm the legal basis and scope with counsel, and decide whether the request can be fulfilled as written or must be narrowed before anything is disclosed.
Keep the response limited to the minimum information authorized by the request and by law. NIST SP 800-53 says organizations should use procedures and controls to validate information before release and only release information outside the system if the receiving system or process provides the required controls, while NIST SP 800-61r3 says legal experts can review plans and requests that may have legal ramifications.
- Validate the request and escalate to legal review before disclosure.
- Limit disclosure to the minimum data and minimum systems needed to satisfy the request.
- Notify the customer when law and the request allow it, and document any restriction on notice.
- Record the request, the decision, the data disclosed, the approvals, and the reason for any exception.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
Used for release control and audit guidance.
Used for legal review, incident response coordination, and notifications.