scieee AI-readable full text Open interactive document viewer

Developing a General Concept for C5 Compliance: Adapting and Applying the Concept to a Company's Application

Suresh Akshintala, Anusha

Abstract

Software Industry is increasing its reliance on Cloud Architecture and this has led to a majorshift in the industry. Along with the benefits it brings there is also an immediate necessity toincrease security measures of these Cloud environments to protect sensitive data andensure regulatory and Compliance requirements are satisfied. This thesis explores the C5Certification Criteria developed by the Bundesamt für Sicherheit in der Informationstechnik(BSI) for Cloud Environments and Applications and aims to create a General Concept andpathway to achieving C5 Compliance for an Application aiming to bridge the Gap betweentheoretical and practical implementation by implementing the General concept to anApplication at the company OEV Online Dienste GmbH. A detailed evaluation of the C5criteria and its core principles will be examined and a pathway to achieving C5 will beexplored. The C5 certification not only allows organizations to ensure security andcompliance but also gives them a competitive edge.

Full text

Developing a General Concept for C5 Compliance: Adapting and Applying the Concept to a Company’s Application Master Thesis Master of Science (M.Sc.) Professional IT Business and Digitalization Faculty 4 Submitted by Anusha Suresh Akshintala (s0590683) Berlin, 03.02.2025 1st Supervisor: Prof. Dr.-Ing. Thomas Schwotzer 2nd Supervisor: Mr. Nico Schönnagel Restriction note The present thesis with the title Developing a General Concept for C5 Compliance: Adapting and Applying the Concept to a Company’s Application contains in-house data of the company OEV Online Dienste GmbH Therefore it is only assigned for the HTW Berlin - University of Applied Sciences as well as the supervisors of the thesis. The thesis must not be made publicly available, neither made available to unauthorized third persons. Berlin ,03/02/2025 _____________ __________________ (Location, date) (signature) Abstract Software Industry is increasing its reliance on Cloud Architecture and this has led to a major shift in the industry. Along with the benefits it brings there is also an immediate necessity to increase security measures of these Cloud environments to protect sensitive data and ensure regulatory and Compliance requirements are satisfied. This thesis explores the C5 Certification Criteria developed by the Bundesamt für Sicherheit in der Informationstechnik (BSI) for Cloud Environments and Applications and aims to create a General Concept and pathway to achieving C5 Compliance for an Application aiming to bridge the Gap between theoretical and practical implementation by implementing the General concept to an Application at the company OEV Online Dienste GmbH. A detailed evaluation of the C5 criteria and its core principles will be examined and a pathway to achieving C5 will be explored. The C5 certification not only allows organizations to ensure security and compliance but also gives them a competitive edge. Acknowledgements Firstly I would like to start by thanking god for giving me the strength , wisdom and perseverance to successfully complete my thesis I would like to thank my university Hochschule für Technik und Wirtschaft Berlin for providing me the opportunity to pursue my masters degree and the necessary resources and infrastructure to complete my research and studies. My gratitude goes to Prof. Dr.-Ing. Thomas Schwotzer for his encouragement , support and constructive feedback throughout the thesis. The knowledge and skills I have gained here have been invaluable in shaping my academics and career. My sincere thanks to Mr. Nico Schönnagel for his valuable suggestions and practical perspective. His technical expertise helped me navigate and resolve challenges throughout my study. A special thanks to OEV Online Dienste GmbH for putting their trust in me and giving me an opportunity to work on this thesis in a professional setting. The collaboration with the company not only provided access to invaluable resources and technical support but also allowed me to gain hands on experience in addressing real world challenges. The practical exposure and insights I gained during this time have significantly broadened my understanding and enhanced the overall quality of my research. I am deeply thankful for their trust and encouragement throughout this journey. Lastly, I want to thank my parents ,friends and colleagues for their unwavering support and encouragement, which motivated me to persevere and complete this thesis successfully. Table of Contents Contents Abstract................................................................................................................................. 3 Acknowledgements ............................................................................................................... 3 Table of Contents .................................................................................................................. 4 1.Introduction ........................................................................................................................ 6 1.1 Background ................................................................................................................. 6 1.2 Research Problem ....................................................................................................... 6 1.3 Research Aim and Objectives ...................................................................................... 7 1.4 Research Questions .................................................................................................... 7 1.5 Thesis Structure .......................................................................................................... 8 2. Cloud Security ................................................................................................................... 9 2.1 Introduction to Cloud Computing ................................................................................. 9 2.2 Security Concerns in Cloud ....................................................................................... 10 2.3 Need for Compliance ................................................................................................. 11 3. Cloud Computing Compliance Criteria Catalogue (C5).................................................... 12 3.1 The 17 Objectives of C5 and its importance .............................................................. 13 3.2 Structure of C5 Criteria .............................................................................................. 17 4. Evaluating C5 ComplianceLeveraging RAG Models for CSP Assessment .................... 18 4.1 RAG - Theoretical Background .................................................................................. 19 4.2 RAG - Implementation ............................................................................................... 19 5 . Company Application ..................................................................................................... 23 6. C5 compliance pathway .................................................................................................. 25 6.1 OIS-03: Interfaces and Dependencies ....................................................................... 25 6.2 AM-06: Asset Classification and Labelling ................................................................. 26 6.3 PS-02: Redundancy model ........................................................................................ 28 6.4 OPS-02: Capacity Management – Monitoring ............................................................ 28 6.5 OPS-03: Capacity Management – Controlling of Resources ...................................... 29 6.6 OPS-05: Protection Against Malware ......................................................................... 30 6.7 OPS-06: Data Backup and Recovery – Concept and OPS-06: Data Backup and Recovery - Monitoring ..................................................................................................... 32 6.8 OPS-10: Logging and Monitoring – Concept and OPS-15 Logging and Monitoring – Accountability .................................................................................................................. 33 6.9 OPS-18: Managing Vulnerabilities, Malfunctions and Errors – Concept and OPS-22: Testing and Documentation of Known Vulnerabilities ...................................................... 34 6.10 OPS-21: Involvement of Cloud Customers in the Event of Incidents ........................ 34 6.11 OPS-23: Managing Vulnerabilities, Malfunctions and Errors – System Hardening ... 35 6.12 OPS-24: Separation of Datasets in the Cloud Infrastructure .................................... 36 6.13 CRY-02: Encryption of Data for Transmission (Transport Encryption) , CRY-03: Encryption of Sensitive Data for Storage and COS-08: Policies for Data Transmission ... 37 6.14 COS-01: Technical Safeguards ............................................................................... 38 6.15 COS-03: Monitoring of Connections in the Cloud Service Provider’s Network ......... 39 6.16 COS-04: Cross-Network Access .............................................................................. 40 6.17 COS-06: Segregation of Data Traffic in Jointly Used Network Environments ........... 41 6.18 PI-01: Documentation and Safety of Input and Output Interfaces............................. 43 6.19 PI-02: Contractual Agreements for the Provision of Data ......................................... 43 6.20 PI-03: Secure Deletion of Data ................................................................................ 44 6.21 DEV-06: Testing Changes and DEV-09: Approvals for Provision in the Production Environment .................................................................................................................... 44 6.22 SSO-04: Monitoring Compliance with Requirements ............................................... 45 6.23 SIM-01: Policy for Security Incident Management ,SIM-03: Documentation and Reporting of Security Incidents and SIM-04: Duty of Users to Report Security Incidents . 45 6.24 SIM-05: Evaluation and Learning Process ............................................................... 46 6.25 BCM-02: Business Impact Analysis Policies and Instructions ,BCM-03: Planning Business Continuity and BCM-04: Verification, Updating, and Testing of Business Continuity ........................................................................................................................ 46 6.26 COM-02: Policy for Planning and Conducting Audits ............................................... 47 6.27 INQ-01: Legal Assessment of Investigative Inquiries and INQ-02: Informing Cloud Customers about Investigation Requests ........................................................................ 47 6.28 PSS-01: Guidelines and Recommendations for Cloud Customers ........................... 48 6.29 PSS-03: Online Register of Known Vulnerabilities ................................................... 48 6.30 PSS-04: Error Handling and Logging Mechanisms .................................................. 49 6.31 PSS-05: Authentication Mechanisms ....................................................................... 49 6.32 PSS-06: Session Management ................................................................................ 50 6.33 PSS-07: Confidentiality of Authentication Information .............................................. 50 6.34 PSS-08: Roles and Rights Concept ......................................................................... 51 6.35 PSS-11: Images for Virtual Machines and Containers ............................................. 51 6.36 PSS-12: Locations of Data Processing and Storage ................................................ 52 7. Conclusion ...................................................................................................................... 52 7.1 Challenges and Limitations ........................................................................................ 53 7.2 Future Research Directions ....................................................................................... 54 8. References...................................................................................................................... 54 Appendix ............................................................................................................................. 58 Table of Figures .................................................................................................................. 61 References of Figures ......................................................................................................... 61 List of Abbreviations and definitions .................................................................................... 62 Statutory Declaration........................................................................................................... 64 1.Introduction 1.1 Background Cloud Computing is a revolutionary step towards digitalization as it gives businesses and organizations an opportunity to be scalable, flexible and extremely cost effective for hosting applications and providing solutions for managing storing and processing data. Companies are slowly adapting and migrating their workloads onto cloud infrastructures resulting in an estimated 824.6 billion USD market.[Statista, n.d.] Any new technology brings with it transformation and change but it also brings with it certain concerns. Security concerns with cloud needs to be addressed due to the growing number of cyber attacks.[Statista, n.d.2] In recent times Cyber attacks have been unique and not generalized, they are created in ways to target and attack certain applications and workloads which has brought about concern among cloud adopters. Adding to this concern is storage and processing of sensitive data in the cloud which makes it even more risk prone. Data breaches , vulnerabilities , unauthorised access and misconfigurations cause major concerns to the cloud providers , organizations and their clients [SentinelOne. (2025)]. This brings a need for a Compliance framework which can help ensure security standards are maintained and there is a reference framework that can be used by organizations to refer back to. One such framework is the Cloud Computing Compliance Criteria Catalogue(C5) which was developed by the Bundesamt für Sicherheit in der Informationstechnik (BSI) in Germany. C5 provides a set of security controls and requirements which are aimed at ensuring cloud services meet high standards of security and compliance making it an essential framework for companies operating in cloud environments.[Bundesamt für Sicherheit in der Informationstechnik. (2025)] 1.2 Research Problem Cloud Compliance frameworks such as Cloud Computing Compliance Criteria Catalogue(C5) , ISO27001 etc. have been established to help organizations safeguard sensitive data and ensure a secure cloud environment and are available for organizations to utilize but there are very little resources available to guide an organization towards achieving compliance. This dearth of accessible resources leaves many organizations vulnerable to gaps in their security posture as they may miss critical implementation details or fail to adapt the frameworks properly to their infrastructure. Many companies struggle to translate theoretical guidelines and controls into practical solutions especially when dealing with varied platforms such as Amazon Web Services(AWS) , Google Cloud Platform(GCP) , Microsoft Azure cloud etc. Every Cloud service provider has unique architecture , tools, resources and configurations and it is quite difficult to adapt the requirements across all different platforms [Sasovets, 2024].The complexity in this increases when multicloud or hybrid cloud environments are considered. This thesis will bridge the gap between theoretical and practical implementation by creating a step by step guide on how organizations can implement C5 and enhance their cloud security posture. 1.3 Research Aim and Objectives The aim of this thesis is to develop a structured and easily adaptable approach to achieving C5 compliance and apply it to a cloud hosted application. The key research objectives of this thesis are1. Develop a general C5 compliance conceptCreate a flexible and adaptable compliance strategy that can be applied to different cloud platforms, providing a systematic pathway for achieving C5 certification. 2. Implement C5 guidelines on a real world applicationApply C5 compliance measures to a real world application and make necessary technical changes to meet the security requirements. 1.4 Research Questions The thesis is guided by the following research questions that it aims to answer1. What are the core principles and security requirements outlined in the C5 framework? 2. How do we check if requirements of C5 are satisfied by the Cloud Service Provider? 3. How should the customer translate and satisfy the C5 requirements? 4. What specific challenges do organizations face when seeking C5 certification? 1.5 Thesis Structure The thesis follows the below structureIntroduction - Discusses the introduction to the thesis including the reasoning behind its importance and requirement. It gives a short introduction to Cloud and C5 o BackgroundExplores the background of C5 o Research Problem - Outlines why C5 is essential o Research Aim and Objectives - Defines goals that the research needs to achieve o Research QuestionsOutlines the main inquiries of the study Cloud Security - This section introduces Cloud computing and explores the security aspects of Cloud o Introduction to Cloud Computing - Introduces Cloud and its requirement o Security Concerns in Cloud - Describes different types of attacks and threats o Need for Compliance - Explores the requirement of Compliance in Cloud Cloud Computing Compliance Criteria Catalogue - Introduces C5 o The 17 Objectives of C5 and its importance - Defines the 17 C5 Objectives which the requirements are based on. o Structure of C5 Criteria - Explores the plan to achieve C5 Evaluating C5 ComplianceLeveraging RAG Models for CSP Assessment - Necessity of RAG for the thesis is explored. o RAG - Theoretical Background - Introduces and explains RAG and its benefits o RAG - Implementation - Explores the preprocessing , vector embedding , querying and dependencies of RAG along with Implementation for C5 Company Application - Describes the application on which C5 compliance will be implemented C5 Compliance Pathway - Details every requirement and pathway along with a solution examined to satisfying said requirement. Conclusion - o Challenges and Limitations - Addresses limitations of the research o Future Research Directions - Proposes areas for further investigation based on the study’s findings and limitations. 2. Cloud Security 2.1 Introduction to Cloud Computing Cloud Computing as a relatively new technology has often been met with skepticism when compared to traditional computing and storage solutions but is important for organizations to understand the intricacies of it if they aim to get C5 compliance.[Batelle, H. (2020).] The Cloud Computing Compliance Criteria Catalogue (C5) established by the Bundesamt für Sicherheit in der Informationstechnik (BSI) serves as a framework for secure cloud operations. The BSI defines Cloud Computing as “an approach for the dynamic provision, use and billing of IT services via a network, adapted to demand. These services are offered and used exclusively via defined technical interfaces and protocols.” The focus on fulfilling criteria for secure cloud usage helps both cloud service providers and users achieve high security standards which builds trust in cloud services. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] There are four types of cloud deployment - Public, Private, Hybrid, and Community. Public clouds are managed by third party providers and offer shared resources over the internet which make them cost effective and scalable. Private clouds are dedicated environments for organizations which allows better control and customization but at a higher cost. Hybrid clouds combine both Public and Private cloud environments allowing exchange of data while maintaining security for sensitive information. Community clouds provide shared infrastructure for groups which allows collaboration between them. Each type is selected based on unique organizational requirements. [Mell, P. and Grance, T. (2011)]. NIST standards state five key characteristics of cloud computingbroad network access, on demand self service, rapid elasticity, resource pooling and measurement of service [Mell, P. and Grance, T. (2011)]. Broad network access makes cloud services available on any internet connected device. [Mell, P. and Grance, T. (2011)] On demand self service allows users to independently access resources like server time and storage. [Mell, P. and Grance, T. (2011)] Rapid elasticity allows automatic scaling of resources which enhances efficiency. [Mell, P. and Grance, T. (2011)] Resource pooling allows shared computing resources among multiple users which can lower costs. [Mell, P. and Grance, T. (2011)] modifications done to the systems also are taken in consideration and requirements are given on the whole lifecycle. Control and Monitoring of Service Providers and Suppliers The Control and Monitoring of Service Providers and Suppliers focuses on requirements for CSP’s using any third party vendor for any services. It is to ensure that even the third party provider meets the requirements and standards. Security Incident Management The Security Incident Management area of the C5 focuses on creating processes for identifying, evaluating and responding to security incidents. It ensures that incidents are logged and communicated so that there is minimum damage done. Business Continuity Management The Business Continuity Management area focuses on Backups and Restoration so that work can continue or be quickly restored after a disruption. This area covers planning, implementing and testing ways to manage emergencies and maintain critical operations. Compliance The Compliance area focuses on audits and compliance requirements. This covers how and when audits will be performed and more details regarding the same. Dealing with Investigation request from Government Agencies This area focuses on how the Cloud service provider responds to any questions or enquiries from Government agencies ,proper procedures for legal reviews, protecting customer privacy and limiting data access when possible. Product Safety and Security The area of Product safety and Security focuses on secure configurations and addressing known vulnerabilities.It also looks into troubleshooting and logging related concerns. Table 1. C5 Objectives 3.2 Structure of C5 Criteria In the 17 sections of C5 mentioned there are in total 127 different criteria that need to be fulfilled. To understand the requirements it is important to understand the structure of responsibility of the criteria. Each criterion has 5 sub sections present - the Basic criteria, Additional criteria, about the criteria , complementary customer criteria and notes on continuous auditing. The “basic criterion” describes the requirement and the measures for the criterion this can include the scope of the criterion , applicability conditions of the criterion and review details. “Additional criterion” section describes any extra requirements which will be described in detail apart from the ones mentioned in the basic criterion.The subsection “about the criterion” describes the reasoning for the criterion and its limitations. The “Complementary customer criteria” are the requirements which are the responsibility of the customer who is utilizing the Cloud services . Finally , “Notes on continuous auditing” is with respect to how audits should take place , what needs to be measured and how often. Fig 2. C5 criterion division by responsibility ,Source - Created by author based on C5 criterion In all these sections it is important to note that one of these sub sections which is additional customer criteria falls as a responsibility on the Cloud customer whereas all other subsections fall under the responsibility of the Cloud service provider.It is also interesting to note that not all requirements have an additional customer criteria , there exists such additional customer criterion only for 47 of the total 127 requirements as illustrated in figure 2. The focus of this thesis is from the cloud customers perspective of creating a pathway therefore the 47 customer criteria will be discussed in detail in the C5 pathway section and a pathway with solution to each of the criteria will be addressed.From the customers perspective the rest of the criteria whose responsibility lies with the CSP needs to be verified to prove compliance hence this will be addressed in the next section of Evaluating C5 Compliance. 4. Evaluating C5 ComplianceLeveraging RAG Models for CSP Assessment As discussed in the previous section C5 criteria has 127 criterion. All these criteria have requirements that the Cloud service provider needs to satisfy. The cloud customer needs to confirm that these standards are met by determining if the cloud service provider has fulfilled all the necessary requirements making this an essential aspect of the study. Usually customers have contracts with the cloud service providers which details almost all of the services provided by the cloud service provider. A practical approach can be to assess the document to match it against each criterion, and determine whether the requirements are satisfied. Given the amount manual effort that is needed this section of the study aims to evaluate the use of a RAG model to address this challenge. The objective is therefore to create a RAG model where the customer and cloud service provider contract can be uploaded ,the RAG is then queried with each criterion of the 127 to check if it is satisfied according to the contract. The responses can then be evaluated to observe which criteria are not satisfied and then the proof for these criteria can be requested from the Cloud Service Provider. This can especially be useful if a company uses multiple different cloud service providers for different projects and each have different types of contracts with different tiers which the company has opted for where certain services might be or might not be provided. This is also essential in companies who do not want to use OpenAI or other AI models directly due to fear of breach of confidentiality. 4.1 RAG - Theoretical Background A RAG model stands for Retrieve - Augment - Generate model. Retrieval augmented generation is a method that can improve the efficiency of Large language models or LLM applications by utilizing context or custom provided data . This is done by retrieving data or documents relevant to a question or task and providing them as context for the LLM. RAG is utilized mostly in Question and Answer systems that need to maintain up to date information or access context based knowledge [Databricks (2023)] The benefits of using RAG are as follows [Databricks (2023)]- 1. RAG is fact based and unlike standalone generative models RAG makes sure that its responses are based on specific retrieved data which increases its reliability and reduces any kind of made up answers. [Databricks (2023)] 2. RAG is adaptable and can be linked to one or multiple knowledge bases which makes it more suitable for domains with specific and concise data like medical or law. [Databricks (2023)] 3. It is highly scalable which makes sure that companies can expand their knowledge base at any point of time and the RAG model can stay relevant without retraining. [Databricks (2023)] 4.2 RAG - Implementation RAG mainly utilizes a pre processed document which it queries which essentially means that the document is broken into small and meaningful manageable chunks of data. These chunks are converted into vector embeddings. Vector embeddings contain the meaning of these chunks of texts or data which belong to one single concept or idea, all these embeddings are stored in the vector database which can be searched and responses can be retrieved. Preprocessing of Document Retrieval-Augmented Generation systems rely heavily on accurate and efficient document preprocessing. In this context raw documents like PDFs are first converted into a machine readable format and then split into smaller chunks which are logically coherent. This step ensures that the system can handle large documents while maintaining semantic continuity within each chunk. The use of tools for eg. PyPDFLoader facilitates this process by automating the loading and splitting of PDF files which preserves essential metadata like page numbers and document sources. Metadata retention is particularly important as it allows the retrieval system to trace responses back to the original document context. The two contract documents OEV Online Dienste GmbH has with AWS were combines and loaded with PyPDFLoader and later split. [pypdf.readthedocs.io. (n.d.)] Vector Embeddings Vector embeddings are an important concept in RAG. They are used in Machine learning , search engines and Natural Language processing extensively. Machine learning generally uses numbers or data that can be translated into some sort of numeric values. Here in this case data is in the form of texts in a document. Vector embeddings are made out of paragraphs of text which essentially is a list of numbers and perform our required operations with them. To discuss vector embeddings it is important to understand semantic similarity. Similarity in a normal context can mean many things. A same word written in two different paragraphs can indicate similarity but semantic similarity means that the two different paragraphs or chunks of text have an overall meaning which is similar. In technical terms semantic similarity is a process of quantifying how closely the meanings of two data points which can be words, sentences or paragraphs are related in vector space. The vector embeddings represent the data as numerical vectors in a higher dimensional space and the similarity measures are used to determine the proximity of these vectors. The closer the two vectors are the more semantically similar their data points will be [Tripathi, R. (2023)] .The vector embeddings of the chunks of document is compared with the vector embedding of the query and the highest similarity chunks are selected. In this case OllamaEmbeddings will be utilized . To study Ollama it would also be important to discuss Langchain. In the RAG model code Ollama model and OllamaEmbeddings were utilized. Many Langchain solutions like DocArrayInMemorySearch , StrOutputParser and PyPDFLoader were also utilized. The difference between the two is that Ollama is a platform designed to enhance the development of AI capabilities especially focusing on providing embeddings whereas Langchain is a framework which is used to build applications with large language models (LLMs). Langchain allows developers to create complex workflows and enables LLMs to fetch data, streamline information processing and enhance decision making . It can integrate with multiple LLM models like Hugging Face , OpenAI GPT models , Ollama . It also integrates with pdf loaders , vector databases and many more. [Svenson, G. (2024)] Utilizing Ollama embeddings in the Langchain framework can enhance the efficiency of these workflows[Svenson, G. (2024)] and therefore llama2 model along with Langchain capabilities were chosen and utilized which will be discussed in the next subsection of dependencies. (Please refer to figure 3 in the Appendix for the screenshot of Vector Embeddings created) Required dependencies A robust RAG system depends on a series of interconnected dependencies, many of these are provided by LangChain. LangChain as discussed in the previous section is a software framework that helps facilitate the integration of large language models (LLMs) into applications. The following components are essential for the functioning of a RAG systemDocument Loaders - LangChain offers tools like PyPDFLoader to load and split documents which transforms text into structured data that can be indexed. Embedding Models - To create semantically rich vector embeddings LangChain supports integration with embedding models like OllamaEmbeddings and OpenAIEmbeddings. These models are used to transform text into numerical vectors that capture the meaning and context of the content. Vector Storage - LangChain’s vector storage solutions like DocArrayInMemorySearch creates easy storage and retrieval of document embeddings. This ensures that the retrieval system can access relevant information quickly during query processing. InMemorySearch stores embeddings in RAM instead of saving on disk like Vector database like Pinecone or ChromaDB. This was chosen as this is a small dataset and is being run locally. Language Models - LangChain also integrates with various language models like Ollama to generate human-like responses based on retrieved information. Prompt Templates - LangChain provides PromptTemplate which structures queries and responses in a consistent format making sure that the language model receives the correct context and query input. Together these dependencies form the backbone of the RAG workflow which allows seamless integration of document retrieval and language model generation. Querying Querying is the stage where the user searches their required question based on the document . There are multiple steps that take place during querying and they are as follows – Input Processing - The users query is passed through the embedding model which this case is Ollamaembeddings , this was also previously used in preprocessing of our document. Using the same embeddings is important as both the query and document are represented in the same semantic space. Fig 4. UML Diagram of Similarity Process during Retrieval. SourceAuthors creation Retrieval - A vector is created out of the users query and this is compared to the vectors in the vector database formed out of the document. Using similarity search algorithms the model finds and retrieves relevant chunks of the document based on the vector of the query. Augmentation - The retrieved chunks are combined with the original query to form a relevant context and the augmented input ensures that an accurate response is created. Generation - The model processes the result of the augment which is the checked retrieved chunk and creates an understandable response. Here llama2 model was utilized to generate human readable answers. Output Parsing - The result is parsed and redone in a user friendly and readable format using StrOutputParser which is a function that is used to convert the output of a language model, whether from an LLM or a Chat model into a string format.[Andres (2024)] The method of querying utilized is using the template “Is this compliance satisfied -” followed by each compliance criterion in the 127 C5 requirements. The results provided by the RAG model was positive. If the compliance was satisfied by any manner according to the contract document , the model provided a positive response stating that the compliance criterion was satisfied along with providing reasons as to where it found the criterion to be satisfied in the document. (Please refer to the appendix figure 5 for the RAG Model results) For AWS , the Cloud service provider provides a Compliance certificate report to the customer which proves the 127 requirements of the Cloud service provider to be satisfied along with audit reports of the same. The RAG model for evaluating C5 compliance as a method was created as a way for customers to assess C5 compliance of a CSP incase they do not provide the compliance report to their customers. 5 . Company Application For the purpose of this thesis the application RiskRanger belonging to OEV Online Dienste GmbH was selected to implement the C5 requirements on. RiskRanger is an insurance service to simplify the way insurance companies create, manage and offer their products online. It is designed for seamless integration with existing websites, RiskRanger provides a streamlined solution for insurers to handle different offerings while providing a smooth experience for end users. For insurance companies, RiskRanger is a powerful tool to develop and launch new insurance products, such as car insurance easily. The platform allows insurers to define the parameters of their products including coverage options, pricing and eligibility criteria all through a centralized interface. On the customer facing side the process is straightforward , the end users fill out a form providing essential details such as their name, address and bank account information. Once the form is submitted RiskRanger makes an API call to the backend, automatically creating the policy for the user. This automated process eliminates the need for manual data entry or paperwork. RiskRanger also allows insurers to have centralized control over their customer and product management. Insurers can view, organize and update customer information and policies in real time allowing for better oversight and operational flexibility. One of the standout features of RiskRanger is its ability to dynamically adjust pricing. For example, if an insurance company updates the price of a product on their homepage the change is instantly reflected across all customer facing pages where the product is displayed. This ensures consistency and transparency while reducing administrative overhead. RiskRanger application uses AWS cloud platform, it runs using 2 EC2 instance , 13 S3 Buckets , Internet Gateway , Security Groups and Network ACLs Fig 6. RiskRanger application Architecture, Source - OEV internal The architecture is a scalable two tier deployment model within an AWS Virtual Private Cloud (VPC). The public subnet hosts a web server that is the entry point for users accessing the application via internet. User traffic flows through an Internet Gateway, enabling the web server to handle static content delivery or forward requests to the backend. The private subnet contains the application server, which is isolated from direct internet access to ensure security. Communication between the web server and the application server is handled internally within the VPC, using private IP addresses.The application server hosts the database which would be OrientDB which is deployed in a docker container on it. To enable the application server to access external resources (like updates or APIs) a NAT Gateway in the public subnet allows secure outbound internet traffic while preventing direct inbound connections. Routing between these components is managed by route tables with the public route table directing traffic to the Internet Gateway and the private route table channelling outbound traffic through the NAT Gateway. Network security is further enhanced through Security Groups and Network ACLs which control traffic at both instance and subnet levels. A C5 pathway will be created and the criteria will be implemented on RiskRanger. 6. C5 compliance pathway As discussed before the C5 certification criteria has the Complementary customer criteria section which will be the object of focus in the scope of this thesis. Out of the total 127 criteria present 47 have the complementary customer criteria section. In this section the pathway to understanding and satisfying the 47 Complementary customer criteria which can help organizations achieve the C5 certification will be discussed. 6.1 OIS-03: Interfaces and Dependencies The OIS-03 : Interfaces and Dependencies criterion focuses on the importance of clearly defining , documenting and communicating the interfaces and dependencies between the Cloud Service Provider (CSP) and third parties which refers to the customer or any other service provider. This criterion ensures that all the parties involved in cloud service delivery have to understand their roles , responsibilities and obligations. This criterion requires a documentation which needs to include guidelines , service descriptions and contracts or agreements which define the responsibilities and obligations. The documentation requires details onto how security incidents will be handled and collaboration between the CSP and customer on these matters and the contract will define the boundaries of responsibilities for the same and SLA’s (Service Level Agreements) on communicating and addressing the security concerns , vulnerabilities and system malfunctions. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions From the cloud customers perspective the complementary criterion requires taking proactive measures to ensure that the defined interfaces , roles and obligations are addressed and implemented. The customers must have suitable controls to confirm that the CSP's guidelines and requirements align with the contractual agreements. This means that the customers need to ensure that recent security incidents , vulnerabilities and system malfunctions are reported and also updates are provided till rectification as per the agreement. Managing these incidents and vulnerabilities are well documented with description of procedures used to rectify. The cloud customer is not responsible for the documentation but rather for ensuring that they have frequent audits , checks or controls in place to ensure that this is satisfied. No separate implementation is required from the Customer end. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] needs to be observed. In most cases if the action is blocked then there has been no breach . If it was not blocked then this incident has to be investigated further and the resources need to be contained. (Please refer to the appendix figure 8 for an example of an attack with attack vectors on the AWS Console ) To avoid disruption the instance can be replicated using the last available image of the instance backed up before the attack and network security can be assessed and altered to avoid further attack. Unmanaged attack surface and its resultant disruption was previously discussed in section 2.2. Extended threat detection connects individual findings and signals into an attack sequence. An attack sequence is steps that the attacker takes to cause damage and it involves multiple steps , such as gaining initial access , escalating privileges , moving laterally and exfiltrating data. Enabling GuardDuty S3 Protection , EKS Protection , EC2 extended protection can help in finding attack sequence and addressing issue from root cause. Enabling extended threat detection is not manadatory but would give the organization deep insights to understand the attack from intial stage and check how widespread it is, it is also easier to remidiate as all the vulnerable resources can be viewed at once for a particular attack which can save time during an ongoing attack. 6.7 OPS-06: Data Backup and Recovery – Concept and OPS-06: Data Backup and Recovery - Monitoring These 2 criteria focus on importance of documenting, communicating and implementing robust data backup and recovery policies by the Cloud Service Provider (CSP). These policies ensure that data backup procedures are according to the contract between the CSP and cloud customers and addresses important aspects such as the scope , frequency and duration of backups and also compliance with Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).[Bundesamt für Sicherheit in der Informationstechnik. (2025)] RTO (Recovery Time Objective) is the maximum allowable downtime after a disruption RPO (Recovery Point Objective) is the maximum acceptable data loss measured in time. Complementary Customer Criteria Actions Cloud customers must make sure that the CSP’s backup and recovery policies align with their business requirements. This includes verifying that the frequency, scope and duration of data backups meet their operational continuity needs. Customers should also make sure that backup and recovery processes under their control are implemented and tested for effectiveness and that they collaborate with the CSP to ensure a proper backup strategy. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS For the purpose of this criterion AWS Backups will be implemented which is the flagship backup service of AWS . AWS Backups is used for creating , assigning and managing backups. This has multiple features and benefits which includes centrally managing Backups , automating backup processes , backup dashboards which help in activity monitoring and backup compliance. [docs.aws.amazon.com. (n.d.) 4] [Mitchell, D.O. (2022)] A backup plan needs to be created first which includes backup rules. Here backup rules will have frequency of backup , retention period and cold storage. Cold storage is an effective cost saving method where storage cost is extremely low but retrieval cost is higher. This is effective on a long run when weekly or daily backups of EC2 , S3 buckets , Cloud Formation stacksets etc is taken. AWS Backups contain Backup dashboard which shows the total number of backups and can be monitored for any failed backups. Using this service any backup can be retrieved incase of attacks or loss of data due to disruption or security breach. 6.8 OPS-10: Logging and Monitoring – Concept and OPS-15 Logging and Monitoring – Accountability The OPS-10: Logging and Monitoring – Concept and OPS-15 Logging and Monitoring – Accountability criterion requires Cloud Service Providers (CSPs) to implement policies for logging and monitoring events in their systems. These policies must address identifying security related events , managing log activation and retention , defining roles and responsibilities. It also requires unambiguous identification of user accesses to support forensic analysis. Complementary Customer Criteria Actions Cloud customers must ensure logging and monitoring for the cloud service layers under their control. This means tracking critical events such as administrator activities, system failures and any kind of data deletions.Customers should also ensure through suitable controls that unique user id’s are assigned to users and incidents on their end for easier analysis of security events. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS For logging and Monitoring in sections 6.2 and 6.5 solutions the Cloud Trail and Cloud Watch were discussed which will be utilized for the OPS - 10 criterion as well because it requires managing logs , tracking activities of users , system failures , data deletions etc along with having unique event id’s and user names displayed for easy analysis of logs.[Mitchell, D.O. (2022)] 6.9 OPS-18: Managing Vulnerabilities, Malfunctions and Errors – Concept and OPS-22: Testing and Documentation of Known Vulnerabilities The OPS-18 and OPS-22 criterion requires Cloud Service Providers (CSPs) to establish guidelines for identifying, assessing and addressing vulnerabilities in their systems and also automatically scan the system components for known vulnerabilities and assess based on severity. These include regular assessments, severity based prioritization and timely remediation. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must regularly identify and mitigate vulnerabilities in the systems under their control, implement controls to manage risks and ensure a secure cloud environment. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS In AWS there is only one existing Cloud Native Vulnerability Management tool which is Amazon Inspector. Amazon Inspector is an automated security assessment service which is helps improve the security and compliance in the applications deployed on AWS. It continuously scans AWS workloads such container images and EC2 instances for vulnerabilities, misconfigurations and any kind of deviations from security best practices. This service gives detailed findings with recommendations which can be used by teams to address potential risks proactively therefore Amazon Inspector was chosen to satisfy the two criterion OPS-18 and OPS-22 . [Amazon.com. (2025) 2]. Utilizing Amazon Inspector is quite simple. The user would have to navigate to the Amazon Inspector page on their AWS Console and click on the get started button. Once this is done the user needs to setup scans. These scans are comprised of EC2 instance based scans , ECR scans, Lambda scans which scans the code for any misconfigurations which was previously discussed in section 2.2 of this thesis. All scans are automatically activated for utilization but the duration between scans can be set based on requirement. According to OPS-18 it is required to have scans once in 30 days to maintain compliance with C5. 6.10 OPS-21: Involvement of Cloud Customers in the Event of Incidents The OPS-21 criterion ensures that Cloud Service Providers (CSPs) keep cloud customers informed about incidents affecting their services. CSPs must periodically update customers on the status of incidents and whenever necessary involve them in the resolution process according to the contractual agreements. Once an incident is resolved the CSP must inform the customer about the actions taken for transparency and accountability. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must implement controls to ensure they receive incident notifications from the CSP and forward these alerts promptly to the appropriate teams for further action. This process allows timely responses and mitigates potential impacts. Documenting these incidents and evaluating whether notifications and resolutions are consistently tracked and shared with customers is the responsibility of the customer. From implementation perspective there is no further action required to be taken by the cloud customer. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] 6.11 OPS-23: Managing Vulnerabilities, Malfunctions and Errors – System Hardening The OPS-23 criterion requires Cloud Service Providers to implement system hardening measures for components used in the production environment. These components must follow industry accepted standards such as CIS Security Benchmarks or BSI IT-Grundschutz. Hardening requirements for every component including configurations are documented to ensure security during information processing storage and transmission. If immutable (nonmodifiable) images are used, compliance with hardening standards is verified during image creation and logs & configuration files are retained for continuous monitoring. CSPs must also implement automated monitoring systems to check compliance with hardening specifications. Any deviations are reported immediately to the appropriate departments for assessment and remediation. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers are responsible for ensuring that the components under their control are hardened in accordance with recognized industry standards. Hardening requirements should be based on a risk assessment of their intended use of the cloud service. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS Using Hardened AMIs can ensure higher level of security and compliance with this criterion. Choosing AWS Marketplace Amazon Machine Image (AMIs) that are prehardened and compliant with CIS Benchmarks is one major way to ensure a Hardened VM. An Amazon Machine Image in AWS is a template that provides the information required to launch an EC2 instance. This image is pre configured with required software packages, Operating System and System configurations. AWS provides multiple choices of AMI’s to choose from across different OS and configurations. This can be accessed by navigating to the AMI catalogue on the Console. The required image can be selected and Instance launched. [AWS (2019).] (Please refer to appendix Figure 9 for Amazon Machine Images available with different Configurations) Ensuring accurate inbound and outbound rules for the application will improve the hardening of the machine, this can be set on the security group attached to the instance. Additionally AWS config can be used to monitor and avoid any configuration changes. Please refer to section 6.5 for description regarding AWS Config. 6.12 OPS-24: Separation of Datasets in the Cloud Infrastructure The OPS-24 criterion ensures that cloud customer data stored on shared resources is securely separated to maintain confidentiality and integrity. This separation is based on risk analysis and uses techniques like firewalls. When segregation mechanisms are complex, third-party reviews like penetration tests can validate their effectiveness. Complementary Customer Criteria Actions Cloud customers must use the cloud service’s segregation features to isolate their data and address risks based on protection requirements. Regular reviews and testing should be done to ensure compliance and security. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS The Cloud Customer is responsible for isolating their data and for this Data Segregation through VPC (Virtual Private Cloud) would be the right approach. By creating a VPC for each application or project within the same cloud account the risk of unauthorized access or accidental data exposure is significantly reduced. This approach ensures that resources belonging to one application cannot interact with resources from another application unless explicitly configured. The resources can be segmented using private and public subnets within VPCs. Private subnets are used for backend resources such as databases which need not be exposed to the internet and public subnets allow access to the internet. VPC Endpoint needs to be configured and used to connect to resources such as S3 bucket or DynamoDB. Through this the data is isolated and not shared with any other resources on the same account. [Amazon Web Services (2023).] 6.13 CRY-02: Encryption of Data for Transmission (Transport Encryption) , CRY03: Encryption of Sensitive Data for Storage and COS-08: Policies for Data Transmission The CRY-02 ,CRY-03 and COS-08 criterion ensures that Cloud Service Providers (CSPs) implement strong encryption and authentication measures for transmitting cloud customer data over public networks and during storage . Encryption protocols, such as TLS 1.2 and TLS 1.3, combined with Perfect Forward Secrecy are recommended as state of the art methods. For data transmitted within the CSP’s trusted internal network encryption may not be mandatory if the network is not public. For CRY-03 Encryption keys especially private keys must be exclusively known to the cloud customer in compliance with legal and regulatory requirements. Any exceptions such as the use of a master key by the CSP must follow predefined procedures and according to contract. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must ensure that data transmitted and stored within their control is encrypted according to protection requirements. Regular reviews should verify compliance with encryption standards to secure data during transmission. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS To implement CRY-02 ,CRY-03 and COS-08 complementary customer criterion the following will be a possible pathwayFor data in transit use of TLS 1.2 or TLS 1.3 can be enforced for secure transmission.security settings can be edited in CloudFront and ELB to support TLS 1.3 . Server-Side Encryption (SSE) needs to be enabled using SSE-KMS (Key Management Service) for encryption and key management in S3 Buckets. This can be done by navigating to the bucket and editing the encryption type. Enabling S3 Bucket Policies to require HTTPS for all access requests can help satisfy this requirement allowing only secure traffic.To edit bucket policy of an existing bucket AWS console can be used to navigate to the S3. Under bucket permissions there would be an option to edit policy. The following policy was written which ensures only HTTPS access to the S3 bucket to make sure that all requests to the bucket are encrypted during transit. The policy explicitly denies any non secure access. Fig 10. Bucket policy created to allow only HTTPS access, Source - AWS Console Similarly Elastic Load Balancer (ELB) can be used with HTTPS listener to handle encrypted traffic between clients and servers. On Amazon Cloudfront Viewer Protocol Policy to Redirect HTTP to HTTPS or HTTPS only can be configured. Keys can be encrypted using AWS KMS for consistent management of encryption keys. This can be done by creating either a Symmetric or Asymmetric key in AWS KMS. Symmetric Keys use the same key for encryption and decryption, making them ideal for data encryption at rest (exampleS3, RDS, DynamoDB). They are fast, secure and managed entirely in AWS. Asymmetric Keys consist of a public and private key pair, suitable for digital signatures and secure data exchange. The public key can be exported while the private key remains secure in AWS. Key rotation needs to be enabled to automatically rotate keys annually for enhanced security. 6.14 COS-01: Technical Safeguards The COS-01 criterion requires Cloud Service Providers (CSPs) to implement safeguards for detecting and responding to network-based attacks, such as DDoS, MAC spoofing and XSS . These measures monitor traffic patterns and feed data into a SIEM system to enable quick responses. DDoS (Distributed Denial of Service): It is an attack that overwhelms a target server or network with high amount of traffic which disrupts availability of the server. [Baker, K. (2024).] MAC Spoofing: It is an attack where the attacker fakes the MAC address of a device to impersonate another device on the network. [nordvpn.com. (2024)] XSS (Cross-Site Scripting): It is an attack that injects malicious scripts into web pages which are viewed by users to steal cookies , information or sessions. [Baker, K. (2024).] Complementary Customer Criteria Actions Cloud customers must monitor and respond to attacks in their areas of responsibility, such as virtual machines in IaaS solutions. They should ensure protective measures are in place and use automated auditing tools for continuous monitoring and threat detection. The description and details of IaaS can be referenced in section 2 of the thesis. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS For implementing the Complementary Customer Criterion for COS-01 the following can be a possible pathwayAmazon GuardDuty needs to utilized to detect unauthorized access, malicious activity and anomalies in traffic patterns. (Please refer to 6.6 for implementation and details regarding GuardDuty) Distributed Denial of Service (DDoS) protection is provided by WAF (Web Application Firewall) and AWS Shield which is a Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS by filtering and monitoring HTTP/HTTPS requests. These can help secure against DDoS attacks , Injections and Cross site scripting. Another basic way to improve security posture is by having Security Groups and NACLs .Security Groups function such as firewalls at the instance level allowing or denying inbound and outbound traffic based on defined rules. They automatically permit return traffic for allowed inbound requests which simplifies management. But Security Groups only support allow rules and cannot explicitly deny traffic. NACLs have explicit inbound and outbound rules which can be configured based on requirement which can be utilized. 6.15 COS-03: Monitoring of Connections in the Cloud Service Provider’s Network The COS-03 criterion requires Cloud Service Providers (CSPs) to separate trusted and untrusted networks into security zones based on a risk assessment. Physical and virtual networks must be configured to restrict and monitor connections according to defined security requirements. The network setup is reviewed annually to assess vulnerabilities, track deviations and implement follow-up measures. Regular reviews also validate the business justification for using services, protocols and ports including compensatory measures for insecure protocols.[Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must ensure their virtual networks are designed, configured and documented to meet their security requirements. This means logical segmentation for organizational units and regular monitoring for compliance. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS For implementing the Complementary Customer Criterion of COS-03 VPCs with private and public subnets for logical segmentation of trusted and untrusted networks can be created. For an existing VPC a private and public subnets can be created with CIDR blocks of their own. An internet gateway needs to be created for the public subnet for public access.[Amazon Web Services (2023)] 6.16 COS-04: Cross-Network Access The COS-04 criterion requires Cloud Service Providers (CSPs) to control cross-network access through security gateways at each network perimeter. Access authorizations must be based on security assessments aligned with cloud customer requirements. For enhanced protection, redundant and highly available security gateways are recommended to ensure reliability and prevent failures. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must implement controls to manage access across virtual network perimeters within their responsibility. Security gateways should enforce access restrictions based on protection needs. Continuous auditing of logs and security evaluations can be automated to monitor compliance and ensure secure cross network access. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS To implement Complementary Customer Criterion for COS-04 NACL’s , WAF and Security Groups can be implemented . Please refer to 6.14 for the description of the same. 6.17 COS-06: Segregation of Data Traffic in Jointly Used Network Environments The COS-06 criterion requires Cloud Service Providers (CSPs) to segregate cloud customer data traffic in shared network environments at the network level. This segregation must follow a documented concept to ensure the confidentiality and integrity of transmitted data. For IaaS/PaaS environments, secure segregation is achieved through physically separated networks or strongly encrypted VLANs. When logical segmentation cannot be easily validated due to complexity, third party audits or security reviews may be used to demonstrate effectiveness. If physical segregation is employed instead of shared environments, this criterion does not apply. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must ensure virtual networks under their control in IaaS or PaaS environments are designed, configured and documented to meet network security requirements like logical segmentation of organizational units. While continuous auditing is not feasible due to the static nature of configurations, periodic reviews and validations should be conducted to maintain compliance. The description and details of IaaS and PaaS can be referenced in section 2 of the thesis. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS The COS-06 criterion requires segmentation which in AWS refers to Organizational Units. Organizational units are logical groupings of AWS accounts that manage and organize accounts based on business needs, departments, or workloads. They allow centralized governance and allow control over multiple AWS accounts within an organization. channel of communication with the CSP to ensure clear communication and information sharing. 6.28 PSS-01: Guidelines and Recommendations for Cloud Customers The PSS-01 criterion requires the Cloud Service Providers (CSPs) to provide guidelines and recommendations to help customers securely configure, install and use the cloud service. These guidelines are tailored for IT, Compliance and Audit teams.The guidelines and recommendations should be related to secure configuration instructions, error handling and logging , authentication mechanisms , vulnerability and update information , roles and rights management . [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Customers must use the CSP's guidelines to develop policies, strategies, and measures for securely configuring and using the cloud service. Regular checks should ensure compliance with these measures and updates from the CSP should be assessed for its impact on the environment. There is no specific implementation for this criterion the implementation will depend on the guidelines provided by the CSP. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] 6.29 PSS-03: Online Register of Known Vulnerabilities The Cloud Service Provider (CSP) maintains or refers to a daily updated online register of known vulnerabilities. This register includes vulnerabilities affecting the CSP and any assets provided by the CSP that cloud customers are responsible for installing, providing, or operating. The vulnerabilities are presented using the Common Vulnerability Scoring System (CVSS) and the register is easily accessible to cloud customers.The register serves as a foundation for customers risk assessments and follow-up actions. For each vulnerability the register specifies whether software updates and patches are available, timeline , responsibility of deployment of updates. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers ensure that the CSP is maintaining and updating the online register, the customer must also integrate information from the register into their risk management processes. They should evaluate this information and implement necessary actions to address vulnerabilities within their scope of responsibility. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] As per the AWS vulnerability page [Vulnerability Reporting - Amazon Web Services (AWS) (no date).] AWS uses an online register for their vulnerability reporting , bug detection and bug bounty.[HackerOne. (2025).] There is no implementation required for this criterion. 6.30 PSS-04: Error Handling and Logging Mechanisms The Cloud Service Provider (CSP) equips its cloud service with robust error handling and logging mechanisms. These mechanisms provide cloud users with security related information about the status of the cloud service and its associated data, services or functions. The logged data ensures transparency in Audit Logs , Error Tracking and Security Configurations.The logs are protected from unauthorized access or modification and can be deleted by the cloud customer. If logging needs activation or specific configurations by the customer, the CSP must provide suitable tools. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must activate and configure error handling and logging mechanisms according to their security requirements. These logs should be integrated into the customer’s Information Security Management System (ISMS) to ensure consistent monitoring and handling of security events. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS This criterion requires implementation of logging , security management and error tracking required. For logging Cloudwatch and Cloudtrail logs can be utilized . Please refer to 6.2. and 6.5 for description and implementation of Cloudtrail and Cloudwatch. For security Management and Error tracking the Amazon Inspector described in 6.9 can be utilized. 6.31 PSS-05: Authentication Mechanisms The Cloud Service Provider (CSP) implements authentication mechanisms to enforce strong authentication like multi factor authentication for users, IT components and applications interacting with the cloud service. These mechanisms are mandatory for privileged users, IT components or applications and are deployed at all access points like login screens or network interfaces allowing access to the cloud service. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must ensure that the authentication mechanisms provided by the CSP are integrated into their identity and authorization management systems. These mechanisms should be configured and used to meet the customer’s specific security and authorization requirements. AWS provides the AWS IAM Identity Centre which is the Single Sign On or SSO feature of AWS that can be initially integrated with any organization once the account is setup. There is no additional implementation required on the customers end. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] 6.32 PSS-06: Session Management The Cloud Service Provider (CSP) ensures the use of a session management system that meets state of the art security standards to safeguard confidentiality, availability and integrity during interactions with the cloud service. The system should include mechanisms to invalidate sessions after inactivity is detected. The session timeout duration can be configured by the CSP or by the cloud customer. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers ensure that the session management protection features offered by the CSP are utilized in accordance with their Information Security Management System (ISMS). [Bundesamt für Sicherheit in der Informationstechnik. (2025)] The AWS SSO which is now the AWS IAM Identity Centre has an automatic session timeout feature for customers which help in session management . For a further line of security customers can utilize Cloudtrail for logging session information and can be periodically reviewed in audits.Please refer to 6.2 for description and implementation of CloudTrail. 6.33 PSS-07: Confidentiality of Authentication Information The Cloud Service Provider (CSP) ensures the confidentiality of passwords used as authentication information for the cloud service .Users either create passwords themselves or are required to change an initial password upon first login, with the initial password expiring after a maximum of 14 days.The password creation enforces length and complexity requirements as specified by the CSP or the cloud customer. Users are notified during password changes or resets and serverside password storage utilizes state of the art cryptographic hash functions combined with at least 32 bit salt values for enhanced security. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers ensure that they create and use passwords that meet high security standards based on their internal assessments. They bear the responsibility for risks associated with unauthorized access due to their password management practices. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS In IAM account settings the password policy can be custom set. It is important to use an uppercase letter , lowercase letter , numbers and alphanumeric characters. Password expiration can be turned on with a 90 day time and denying password reuse so that new passwords are required to be setup every 3 months for additional security.Setting this up in the management account will ensure all sub accounts also have the same policy applied. AWS secrets manager can also be used to store other passwords or keys in use. 6.34 PSS-08: Roles and Rights Concept The Cloud Service Provider (CSP) offers a roles and rights concept that defines access rights for cloud service functions. This concept includes rights profiles enabling cloud users to manage access permissions based on the principle of least privilege and functional separation of duties. The concept ensures that permissions are aligned with task requirements while maintaining operational and controlling independence. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers should ensure through suitable controls within their cloud responsibility that permissions granted to users that are authorized and aligned with their roles .The assigned permissions are regularly reviewed and adjusted as required including access revocing in cases like employee resignations or role changes. There is no implementation for this criterion , the customer needs to have access review audits and manually provide or remove accesses periodically. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] 6.35 PSS-11: Images for Virtual Machines and Containers The Cloud Service Provider ensures that customers can restrict virtual machine or container image selection to approved options. Providers must notify customers of changes to provided images, which are hardened according to industry standards like CIS benchmarks. Integrity checks at startup and runtime detect manipulations and report them to customers.[Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must ensure the images they use meet their security requirements and process integrity check results to address any issues, maintaining secure and reliable virtual environments. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Solution path for AWS Cloud customers can opt for CSP provided images such as AWS Marketplace Amazon Machine Image (AMIs) that are prehardened and compliant with CIS Benchmarks is one major way to ensure a Hardened VM. Please refer to 6.11 for details regarding AMI’s. 6.36 PSS-12: Locations of Data Processing and Storage The Cloud Service Provider enables customers to specify the locations for data processing and storage, including backups according to the contract. This requirement is supported by the cloud architecture ensuring compliance with customer-specific data location preferences. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] Complementary Customer Criteria Actions Cloud customers must use appropriate controls to verify the available data processing and storage locations when selecting a service provider and configuring the cloud service. They should choose locations that align with their operational and regulatory requirements. Customers should consider legal obligation like data protection laws when using services from providers based in different jurisdictions. There is no specific implementation required for this criteria, the customer must select the appropriate storage locations and availability zones. [Bundesamt für Sicherheit in der Informationstechnik. (2025)] 7. Conclusion In the context of C5 criterion it is essential to have a clear picture of how to achieve compliance. This thesis has explored the relationship between Cloud Computing and compliance focusing specifically on the Cloud Computing Compliance Criteria Catalogue (C5). It provides a structured approach to understanding the importance of C5 in today’s digital landscape and creates a pathway for achieving compliance. The thesis began by introducing essential Cloud concepts and then went on to highlight why compliance frameworks like C5 is important in ensuring data security, privacy and trust in Cloud environments. The introduction laid a solid foundation explaining the significance of the research and clearly defining its objectives and scope. The research questions guided the investigation giving it a focused and purposeful approach. The study then went on to delve deep into C5 and its 17 objectives which provided a clear understanding of the requirements that organizations must meet to ensure compliance which answered our first research question of section 1.4. The thesis took a step further by introducing Retrieval Augmented Generation (RAG) as an innovative tool to support C5 compliance implementation. The RAG framework was thoroughly analyzed with discussions on its preprocessing techniques, vector embeddings, querying and dependencies. By integrating RAG the research demonstrated how advanced technologies can streamline the compliance process making it more efficient for a company to utilize and implement compliance. The practical application of RAG in the context of C5 was important in bridging the gap between theoretical concepts and real world solutions which answered our second research question of section 1.4. Research was done on the Company application RiskRanger by OEV Online Dienste GmbH to understand a real world application over which C5 compliance needs to be fulfilled. Application components were analyzed to understand and develop an example pathway for C5. The research then continued with exploring the Cloud Computing Compliance Criteria Catalogue components and understanding the Cloud customer responsibilities . The C5 Pathway is an essential element of this thesis providing a roadmap for organizations to meet the rigorous requirements of the Cloud Computing Compliance Criteria Catalogue. The research explored each criterion and developed a detailed pathway with solutions specifically for the AWS Cloud platform. This answered the third research question that was discussed initially in section 1.4 . In conclusion the C5 Pathway is a roadmap and a comprehensive step by step guide that provides solutions which can be adopted by organizations easily . It transforms C5 compliance from being a complex and tough challenge to an easy implementation to provide higher security and be aligned with the highest standards. This thesis not only contributes to the academic understanding of C5 but also provides a basic blueprint for organizations looking to utilize this compliance effectively. 7.1 Challenges and Limitations This study while offering valuable insights into compliance and C5 and also creating a step by step guide to achieving this compliance encountered certain limitations.The C5 criteria being a compliance criteria established by the BSI most resources and researches available were in German language which can be challenging for multinational corporations having branches in germany or non german companies to understand in depth and implement. There were also very few upto date , previously researched and created pathways to C5 that would serve as a base and first iteration of a plan that this thesis could have been developed on which meant that this would be the first time an in depth researched pathway was created in English. This inturn meant that the scope of this thesis could not be extended to all Cloud platforms and had to be specific to one platform. The AWS Cloud platform was chosen along with a company application to implement C5 pathway on as AWS holds the highest market share among all Cloud platforms. [Richter, F. (2024).] Therefore this thesis focussed on AWS as it might help the highest number of organizations to achieve C5 compliance The dynamic nature of compliance is also a limitation, though this study stands relevant to the current C5 standards with new security breaches and threats being created every day compliance norms tend to change to adapt to the scenario this would mean that the study would not be completely suited to next version of the C5 compliance and can only serve as a basic guide. Another limitation of this study is that the study explored implementing C5 compliance on public cloud infrastructure due to the scope it could not explore hybrid cloud which is a combination of public and on premises cloud which many organizations use. These challenges and limitations answered our fourth research question of section 1.4 . 7.2 Future Research Directions This thesis lays a strong foundation for understanding and implementing C5 compliance on the AWS Cloud platform but it also opens several paths for future research. The thesis could further be expanded to exploring C5 compliance in all other major Cloud Service Platforms such as Microsoft Azure , Google Cloud Platform , Oracle Cloud Platform , Alibaba Cloud etc.The RAG model created can also be validated for all different cloud platforms using contracts of clients with other Cloud providers and the existing C5 compliance criteria. Similarly more research can be done on Hybrid cloud scenarios where the criteria needs to be implemented on architectures consisting of both public and on premises cloud which will require taking care of a lot more intricacies. More studies can be done on implementing the criteria on different organizations to understand the challenges faced by different industries. Research needs to be continued on the new compliance requirements when the newer version of C5 compliance is released to keep up with the dynamic nature of security and Cloud compliance. This direction will ensure that the research keeps up with the ever evolving nature of Cloud and also to help every organization achieve Compliance resulting in higher economic growth and sense of security. 8. References [Mell, P. and Grance, T. (2011)]. The NIST Definition of Cloud Computing Recommendations of the National Institute of Standards and Technology. [online] NIST. Available at: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf. [Bundesamt für Sicherheit in der Informationstechnik. (2025)]. Bundesamt für Sicherheit in der Informationstechnik. [online] Available at: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-undEmpfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/KriterienkatalogC5/C5_AktuelleVersion/C5_AktuelleVersion_node.html [Crowdstrike.com. (2024).] 12 Cloud Security Issues: Risks, Threats & Challenges | CrowdStrike. [online] Available at: https://www.crowdstrike.com/en-us/cybersecurity101/cloud-security/cloud-securityrisks/?srsltid=AfmBOopMJc4cmf83hWnIetCYmriYGYeQeFJ6fGFqmuADtoLroHb8tSVD [Baker, K. (2024).] 12 Most Common Types of Cyberattacks. [online] Crowdstrike.com. Available at: https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/commoncyberattacks/. [Amazon (2024)]. What is Cloud Computing? - Amazon Web Services. [online] Amazon Web Services, Inc. Available at: https://aws.amazon.com/what-is-cloud-computing/. [Batelle, H. (2020).] Five Things People Hate About the Cloud | AtScale. [online] AtScale. Available at: https://www.atscale.com/blog/five-things-people-hate-about-cloud/ [Databricks (2023).] Retrieval Augmented Generation. [online] Databricks. Available at: https://www.databricks.com/glossary/retrieval-augmented-generation-rag. [Tripathi, R. (2023).] What are Vector Embeddings? [online] Pinecone. Available at: https://www.pinecone.io/learn/vector-embeddings/. [Andres (2024).] LangChain StrOutputParser guide - November 2024. [online] Restack.io. Available at: https://www.restack.io/docs/langchain-knowledge-langchain-stroutputparserguide [docs.aws.amazon.com. (n.d.).] AWS services for logging and monitoring - AWS Prescriptive Guidance. [online] Available at: https://docs.aws.amazon.com/prescriptiveguidance/latest/logging-monitoring-for-application-owners/aws-services-loggingmonitoring.html. [Amazon.com. (2025).] Working with CloudTrail Insights - AWS CloudTrail. [online] Available at: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-insightsevents-with-cloudtrail.html?icmpid=docs_cloudtrail_console . [Svenson, G. (2024).] How to Use Ollama Embeddings in Langchain Effectively. [online] Medium. Available at: https://medium.com/@garysvenson09/how-to-use-ollamaembeddings-in-langchain-effectively-a9486b5b6f52 . [Statista. (n.d.).] Public cloud computing: market size 2009-2022. [online] Available at: https://www.statista.com/statistics/273818/global-revenue-generated-with-cloud-computingsince-2009/. [Statista. (n.d.2).] Complaints on internet crime annual 2022. [online] Available at: https://www.statista.com/statistics/267546/number-of-complaints-about-us-internet-crime/. [Sasovets, I. (2024)] What is Multi-Cloud Security? Challenges and best practices. https://www.techmagic.co/blog/multi-cloud-security? [SentinelOne. (2025).] 17 Security Risks of Cloud Computing in 2025. [online] Available at: https://www.sentinelone.com/cybersecurity-101/cloud-security/security-risks-of-cloudcomputing/? . [Wadhwa, P. (2024).] Cloud Compliance: What is it and how to implement it? [online] Sprinto. Available at: https://sprinto.com/blog/cloud-compliance/. [Dikla Akrat (2024).] The Importance of Compliance in Building Trust with Clients | Dikla Akrat | Business. [online] Dikla Akrat | Business | Business. Available at: https://diklaakrat.net/the-importance-of-compliance-in-building-trust-with-clients/ [pypdf.readthedocs.io. (n.d.).] Welcome to pypdf — pypdf 4.0.1 documentation. [online] Available at: https://pypdf.readthedocs.io/en/stable/. [AWS (2024).] What is Amazon CloudWatch? - Amazon CloudWatch. [online] Amazon.com. Available at: https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/WhatIsCloudWatch.htm l. [docs.aws.amazon.com. (n.d.)2 ]. Monitoring and Logging - Introduction to AWS Security. [online] Available at: https://docs.aws.amazon.com/whitepapers/latest/introduction-awssecurity/monitoring-and-logging.html. [docs.aws.amazon.com. (n.d.)3.] Security, Identity, and Compliance - Overview of Amazon Web Services. [online] Available at: https://docs.aws.amazon.com/whitepapers/latest/awsoverview/security-services.html. [docs.aws.amazon.com. (n.d.) 4]. Backup and recovery using AWS Backup - AWS Prescriptive Guidance. [online] Available at: https://docs.aws.amazon.com/prescriptiveguidance/latest/backup-recovery/aws-backup.html. [docs.aws.amazon.com. (n.d.)5]. Getting started with GuardDuty - Amazon GuardDuty. [online] Available at: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_settingup.html. [AWS (2019).] Amazon Machine Images (AMI) - Amazon Elastic Compute Cloud. [online] Amazon.com. Available at: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html. [Amazon.com. (2025) 2]. Was ist Amazon Inspector? - Amazon Inspector. [online] Available at: https://docs.aws.amazon.com/de_de/inspector/latest/user/what-is-inspector.html [Amazon.com. (2020)]. What is AWS Security Hub? [online] Available at: https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html. [Amazon Web Services (2023)]. What Is Amazon VPC? - Amazon Virtual Private Cloud. [online] Amazon.com. Available at: https://docs.aws.amazon.com/vpc/latest/userguide/whatis-amazon-vpc.html. [Vulnerability Reporting - Amazon Web Services (AWS) (no date).] https://aws.amazon.com/security/vulnerability-reporting/. [Mitchell, D.O. (2022)]. Cloud Computing Compliance Controls Catalogue am Beispiel von Amazon Web Services analysieren und bewerten. Kobv.de. [online] doi:https://opus4.kobv.de/opus4-htw/frontdoor/index/index/docId/1591. [HackerOne. (2025).] AWS VDP - Vulnerability Disclosure Program | HackerOne. [online] Available at: https://hackerone.com/aws_vdp?type=team [Richter, F. (2024).] Infographic: Amazon Dominates Public Cloud Market. [online] Statista Infographics. Available at: https://www.statista.com/chart/18819/worldwide-market-share-ofleading-cloud-infrastructure-service-providers/. [Fortinet (n.d.)]. Lateral Movement: How To Detect and Prevent It. [online] Fortinet. Available at: https://www.fortinet.com/resources/cyberglossary/lateral-movement. Statutory Declaration I herewith formally declare that I have written the submitted thesis independently in all parts. I did not use any outside support except for the quoted literature and other sources mentioned in the paper. I declare that the thesis has not been presented in the same or a similar form in any other examination. I clearly marked and separately listed all of the literature and all of the other sources which I employed when producing this academic work, either literally or in content. I am aware that the violation of this regulation will lead to failure of the thesis. Information on the use of AI-based tools I declare that I have not used any AI-based tools whose use has been explicitly excluded in writing by the examiner. I am aware that the use of texts or other content and products generated by AI-based tools does not guarantee their quality. I am fully responsible for the adoption of any machine-generated passages used by me and bear responsibility for any incorrect or distorted content generated by the AI, incorrect references, violations of data protection and copyright law or plagiarism. I also declare that my creative influence predominates in this work. Anusha Suresh Akshintala Student’s name Student’s signature s0590683 Matriculation number Berlin,03/02/2025