1. Purpose
The Cloud Exit Checklist defines the activities required to securely discontinue, migrate, replace, or terminate a cloud service.
The objective is to ensure that cloud exit activities:
- Protect organizational information.
- Prevent unauthorized access after termination.
- Return or securely delete information.
- Remove cloud identities and credentials.
- Disconnect integrations and dependencies.
- Preserve required records and evidence.
- Meet contractual and legal requirements.
- Maintain business continuity.
- Validate migration and data completeness.
- Address backup and residual copies.
- Reduce dependency and concentration risks.
- Confirm that the cloud service has been securely closed.
Cloud exit should be treated as a controlled change rather than simply cancelling a cloud subscription.
2. Scope
This checklist applies to the retirement, replacement, migration, or termination of:
- IaaS services
- PaaS services
- SaaS applications
- Cloud databases
- Cloud storage
- Cloud backup services
- Cloud security platforms
- Cloud monitoring services
- Cloud identity services
- Cloud development platforms
- Cloud-hosted applications
- Cloud infrastructure accounts
- Cloud service providers
It may be used when:
- A cloud service is no longer required.
- A provider is being replaced.
- The organization is migrating to another provider.
- A contract expires.
- A supplier relationship is terminated.
- A service is discontinued by the provider.
- Security or business risk requires migration.
- A critical cloud dependency needs to be replaced.
3. Core Exit Principle
The exit process should follow:
Exit Decision → Dependency Assessment → Exit Planning → Data Migration/Return → Validation → Access Revocation → Integration Removal → Data Deletion → Contract Closure → Verification → Register Update → Evidence Retention
The organization should understand not only the cloud service itself, but also everything that depends on it.
4. Exit Information
| Field | Details |
|---|---|
| Exit ID | |
| Cloud Service ID | |
| Cloud Service Name | |
| Provider | |
| Service Type | IaaS / PaaS / SaaS / Other |
| Business Owner | |
| Technical Owner | |
| Security Owner | |
| Criticality | Low / Medium / High / Critical |
| Information Classification | |
| Customer Data | Yes / No |
| Personal Data | Yes / No |
| Production Service | Yes / No |
| Exit Reason | |
| Planned Exit Date | |
| Actual Exit Date | |
| Replacement Service | |
| Exit Status |
5. Exit Trigger
Document the reason for exit.
Examples include:
- Business strategy change
- Cost or commercial decision
- Provider contract expiry
- Provider service discontinuation
- Security concerns
- Regulatory requirements
- Performance issues
- Availability concerns
- Technology replacement
- Migration to another cloud provider
- Consolidation of cloud services
- Supplier risk
- Acquisition or organizational change
The reason should be recorded without unnecessarily including confidential commercial information.
6. Business Dependency Assessment
Before beginning the exit, identify what depends on the cloud service.
Review:
- Business processes
- Applications
- APIs
- Databases
- Storage
- Identity systems
- Monitoring
- Security tooling
- Backup systems
- CI/CD pipelines
- DNS
- Network connections
- Customer integrations
- Supplier integrations
- Automated workflows
Determine whether the service is:
- Standalone
- Integrated
- Business-critical
- Customer-facing
- Security-critical
- Required for regulatory obligations
7. Criticality Review
Determine whether the cloud service is a critical dependency.
Consider:
- Business impact
- Customer impact
- Revenue impact
- Information sensitivity
- Production dependency
- Availability requirements
- Regulatory requirements
- Recovery requirements
- Replacement complexity
- Migration duration
- Supplier concentration
Critical cloud services should receive enhanced exit planning.
8. Exit Approval
Before execution, obtain appropriate approval.
Approval should consider:
- Business impact
- Security risk
- Data migration
- Service continuity
- Contractual obligations
- Customer commitments
- Regulatory requirements
- Recovery arrangements
- Replacement service
- Exit timeline
For a critical cloud service, security, technology, business, and management stakeholders may need to approve the plan.
9. Exit Plan
Create an exit plan covering:
- Activities
- Owners
- Dependencies
- Timeline
- Migration activities
- Validation activities
- Communication
- Access revocation
- Data deletion
- Contract closure
- Rollback/contingency
- Evidence requirements
A critical service should have an explicit fallback plan where practical.
10. Data Identification
Identify all organizational information stored, processed, or transmitted through the cloud service.
Consider:
- Production data
- Customer information
- Personal data
- Financial information
- Confidential information
- Source code
- Configuration data
- Logs
- Backups
- Snapshots
- Archives
- Encryption keys
- Metadata
- Audit records
- User information
- Security records
Map where the information exists before beginning deletion.
11. Data Classification Review
Confirm the classification of information being migrated or returned.
Example:
| Information | Classification | Exit Action |
|---|---|---|
| Customer database | Restricted | Secure migration |
| Application logs | Confidential | Retain/migrate |
| Public website assets | Public | Migrate if required |
| Encryption configuration | Restricted | Secure transfer |
| User account records | Confidential | Validate migration |
The exit process should follow applicable retention and deletion requirements.
12. Data Migration
Where information is being moved to another platform:
- Define migration scope.
- Identify source data.
- Identify destination.
- Use secure transfer mechanisms.
- Protect data during transfer.
- Restrict migration access.
- Maintain migration logs.
- Validate completeness.
- Validate integrity.
- Confirm destination security.
- Document migration results.
Sensitive data should not be transferred through uncontrolled channels.
13. Data Integrity Validation
After migration, validate that:
- Required records were transferred.
- Data is complete.
- Data is readable.
- Data relationships remain intact.
- Applications can use the migrated data.
- Permissions are appropriate.
- No unexpected corruption occurred.
- Critical business functions operate correctly.
Validation should be documented.
14. Backup Review
Before termination, identify backups and recovery copies.
Review:
- Active backups
- Snapshots
- Archived data
- Replicated data
- Disaster-recovery copies
- Provider-managed backups
- Third-party backups
Determine:
- What must be retained?
- What must be migrated?
- What can be securely deleted?
- What retention period applies?
- Who is responsible for deletion?
15. Retention Requirements
Before deleting information, consider:
- Legal retention
- Regulatory retention
- Contractual obligations
- Litigation holds
- Audit requirements
- Financial records
- Security investigation requirements
- Customer commitments
- Internal retention requirements
Data should not be deleted simply because the cloud contract is ending if a valid retention requirement applies.
16. Data Deletion
After migration/retention requirements are satisfied, initiate secure deletion.
Consider:
- Production data
- User accounts
- Databases
- Storage
- Snapshots
- Backups
- Logs
- Temporary files
- Caches
- Replicas
- Archived data
Where the provider manages deletion, obtain appropriate evidence or contractual confirmation where available.
17. Personal Data Deletion
Where personal data is involved, verify applicable requirements relating to:
- Retention
- Deletion
- Return
- Subprocessors
- Data transfers
- Data subject requirements
- Contractual obligations
- Applicable privacy law
Where a supplier acts as a processor, review the relevant DPA and contractual deletion requirements.
18. Access Revocation
Remove all access associated with the cloud service.
Review:
- User accounts
- Administrator accounts
- IAM roles
- Service accounts
- API keys
- Access keys
- OAuth credentials
- Tokens
- Certificates
- SSH keys
- SSO integrations
- Federated identities
- Supplier accounts
- Break-glass access
Access should be removed only after confirming that required migration and evidence activities are complete.
19. Privileged Access Removal
Perform an explicit review of privileged access.
Remove:
- Cloud administrators
- Security administrators
- Database administrators
- Network administrators
- IAM administrators
- Supplier administrators
- Emergency accounts associated with the service
Validate that no privileged identity remains unnecessarily active.
20. Secrets and Credential Rotation
Where credentials may have been exposed to or used by the retiring cloud service, consider rotation.
Review:
- Database credentials
- API keys
- Application secrets
- Access keys
- Tokens
- Certificates
- Encryption credentials
- CI/CD secrets
Rotation should be performed where required by risk.
21. Integration Review
Identify and remove integrations such as:
- APIs
- Webhooks
- DNS
- SSO
- Identity federation
- Payment systems
- Monitoring
- SIEM
- Security tools
- Backup tools
- CI/CD
- Ticketing systems
- Email systems
- Customer integrations
- Third-party integrations
Each integration should be identified as:
- Removed
- Migrated
- Retained
- Reconfigured
- No longer required
22. Network Disconnection
Remove unnecessary network connectivity.
Review:
- VPN connections
- Peering
- Private endpoints
- Direct connections
- Firewall rules
- Security groups
- Routing
- IP allowlists
- DNS records
- Load balancers
- Network tunnels
Validate that removal does not unintentionally affect another service.
23. Application Configuration
Review applications that reference the retiring cloud service.
Check:
- Connection strings
- API endpoints
- Environment variables
- Secrets
- DNS
- Configuration files
- Infrastructure-as-Code
- CI/CD pipelines
- Monitoring configuration
- Application dependencies
References to the old service should be removed or updated.
24. Infrastructure-as-Code Review
Search infrastructure repositories for references to the retiring cloud service.
Review:
- Terraform
- CloudFormation
- Bicep
- Kubernetes manifests
- CI/CD configuration
- Deployment scripts
- Automation
- Monitoring-as-Code
- Security configuration
Remove obsolete infrastructure definitions after confirming they are no longer required.
Changes should follow the organization’s change-management process.
25. Logging and Monitoring
Before disabling the service, determine whether historical logs need to be retained.
Review:
- Security logs
- Audit logs
- Access logs
- Application logs
- Cloud activity logs
- Incident records
- Monitoring alerts
Required records should be securely retained or migrated.
After exit, remove obsolete monitoring rules and integrations.
26. Security Tool Integration
Review whether the retiring service is connected to:
- SIEM
- SOC platform
- Vulnerability scanners
- EDR
- CSPM
- Security Hub
- CloudTrail
- Monitoring platforms
- Alerting platforms
Remove or reconfigure integrations after confirming that they are no longer required.
27. Customer Impact
For customer-facing cloud services, assess:
- Customer availability
- Service interruption
- Data migration
- Customer contracts
- SLAs
- Security commitments
- Privacy commitments
- Customer notifications
Customer communications should follow the organization’s contractual and incident/change-management requirements.
28. Business Continuity
Before terminating a critical cloud service, confirm:
- Replacement service is available.
- Required data has been migrated.
- Critical applications are operational.
- Recovery arrangements exist.
- Required backups are available.
- Dependencies have been tested.
- Business owners have confirmed readiness.
For critical services, a rollback or contingency plan should be considered.
29. Cloud Provider Contract Review
Review the contract for:
- Termination requirements
- Notice period
- Data return
- Data deletion
- Backup deletion
- Assistance with migration
- Transition support
- Subprocessor requirements
- Confidentiality
- Security obligations
- Audit rights
- Record retention
- Post-termination obligations
Contractual obligations should be completed before the relationship is considered fully closed.
30. Subprocessor Review
If the cloud service involves subprocessors, determine:
- Which subprocessors were involved
- What information they handled
- Whether data was transferred
- Whether data needs to be returned/deleted
- Whether termination notifications are required
- Whether contractual deletion obligations are satisfied
Do not assume that terminating the primary cloud service automatically terminates every downstream data copy.
31. Cloud Provider Confirmation
Where appropriate, request confirmation from the provider regarding:
- Account termination
- Data deletion
- Backup deletion
- Service termination
- Data return
- Remaining contractual obligations
Retain the provider’s confirmation as evidence where appropriate.
32. Cloud Account / Subscription Closure
After completing migration and security activities:
- Disable unnecessary accounts.
- Remove unnecessary users.
- Remove resources.
- Remove integrations.
- Remove network connectivity.
- Cancel services.
- Close subscriptions/accounts where appropriate.
- Confirm billing termination.
- Retain required records.
Do not close the account before confirming that all required evidence and data have been secured.
33. AWS SaaS Example
Consider a SaaS company migrating from an AWS production environment to another approved cloud platform.
Before migration
The organization identifies:
- ECS application workloads
- RDS databases
- S3 customer documents
- IAM roles
- KMS keys
- CloudTrail logs
- CloudWatch monitoring
- WAF
- Secrets Manager
- CI/CD pipelines
- Backup and snapshots
Migration
The organization:
- Creates the replacement environment.
- Applies the approved security baseline.
- Migrates application data securely.
- Validates database completeness.
- Tests the application.
- Validates customer access.
- Confirms backup and recovery.
- Obtains business-owner approval.
AWS exit
After successful migration:
- Remove obsolete IAM users and roles.
- Revoke access keys.
- Remove application integrations.
- Review S3 data.
- Review RDS snapshots.
- Review backups.
- Rotate credentials where required.
- Remove DNS and network dependencies.
- Retain required CloudTrail/security records.
- Delete remaining data according to retention requirements.
- Close unused AWS resources/accounts.
- Obtain appropriate evidence of completion.
The exit should not be considered complete merely because the AWS bill has stopped.
34. Exit Security Verification
Before closure, verify:
- No unauthorized user access remains.
- Privileged access has been removed.
- Supplier access has been removed.
- API credentials have been revoked or rotated.
- Network connectivity has been removed.
- DNS references have been updated.
- Applications no longer depend on the old service.
- Required data has been migrated.
- Data integrity has been validated.
- Required backups have been retained or migrated.
- Unnecessary data has been securely deleted.
- Required logs have been retained.
- Monitoring integrations have been removed or updated.
- Contractual requirements are completed.
- Provider confirmation has been obtained where applicable.
35. Residual Risk Review
After exit, assess whether any residual risks remain.
Examples:
- Historical data retained with the provider
- Backup copies awaiting expiry
- Contractual obligations
- Legacy credentials
- Archived logs
- Customer commitments
- Remaining integrations
- Data retention requirements
- Migration gaps
Each significant residual risk should be:
- Documented
- Assigned an owner
- Risk assessed
- Treated or accepted
- Monitored until closure
36. Exit Findings and Corrective Actions
| Finding | Risk | Corrective Action | Owner | Due Date | Status |
|---|---|---|---|---|---|
| Old API credential remains active | High | Revoke credential | Cloud Team | Open | |
| Backup copy remains under retention | Medium | Confirm expiry/deletion date | Security | In Progress | |
| Old monitoring integration remains | Low | Remove integration | DevOps | Closed |
37. Exit Evidence Register
Evidence may include:
- Approved exit plan
- Migration plan
- Data migration report
- Data validation report
- Access-revocation report
- IAM report
- Credential-revocation evidence
- Backup review
- Data deletion confirmation
- Provider confirmation
- Contract termination
- Network-disconnection evidence
- DNS changes
- Change tickets
- Application testing
- Business-owner approval
- Security verification
- Final exit report
Evidence should be retained according to the organization’s information-retention requirements.
38. Cloud Exit Status
Use a controlled status such as:
| Status | Meaning |
|---|---|
| Planned | Exit approved but not started |
| In Progress | Exit activities underway |
| Migration Complete | Data/service migration completed |
| Security Verification | Exit undergoing security validation |
| Pending Provider Closure | Waiting for provider action |
| Closed | Exit successfully completed |
| Closed With Residual Risk | Service closed but documented residual risks remain |
| Blocked | Exit cannot currently proceed |
39. Exit Approval
The final exit should be reviewed by appropriate stakeholders.
Approval should confirm:
- Migration is complete.
- Data requirements have been addressed.
- Access has been removed.
- Integrations have been removed.
- Required evidence has been retained.
- Contractual requirements are complete.
- Residual risks are understood.
- Registers have been updated.
For critical services, management and security approval may be appropriate.
40. Update ISMS and Asset Records
After successful exit, update relevant records:
Cloud Services Register
Mark service as:
Retired / Closed
ICT Dependency Register
Remove or update the dependency.
Supplier Register
Update supplier relationship status.
Critical Supplier Register
Remove the provider if it is no longer critical.
Asset Inventory
Retire associated assets.
Cloud Access Register
Remove obsolete access.
Risk Register
Close or update related risks.
Data Inventory
Update information location and processing records.
41. Common Mistakes
Avoid:
- Treating contract cancellation as cloud exit
- Deleting data before migration validation
- Forgetting backups and snapshots
- Forgetting service accounts
- Leaving API keys active
- Leaving supplier accounts active
- Forgetting DNS records
- Leaving VPN or network connections
- Leaving CI/CD references
- Ignoring SaaS integrations
- Failing to retain required audit logs
- Assuming provider deletion covers all subprocessors
- Closing the account before collecting evidence
- Failing to test the replacement environment
- Ignoring residual risk
42. Internal Audit Checklist
An auditor may verify:
- Cloud exit was formally initiated.
- Exit reason was documented.
- Business dependencies were identified.
- Criticality was assessed.
- Exit plan was approved.
- Data was identified.
- Data migration was controlled.
- Migration integrity was validated.
- Backup copies were reviewed.
- Retention requirements were considered.
- Data deletion was performed where required.
- Personal-data requirements were addressed.
- User access was revoked.
- Privileged access was removed.
- Supplier access was removed.
- Credentials were revoked/rotated.
- Network connections were removed.
- DNS/integration dependencies were addressed.
- Monitoring and security integrations were reviewed.
- Infrastructure-as-Code references were removed.
- Contractual obligations were completed.
- Provider confirmation was obtained where appropriate.
- Residual risks were assessed.
- Cloud/asset/supplier registers were updated.
- Exit evidence was retained.
- Final approval was obtained.
43. Relationship With Other ISMS Documents
The Cloud Exit Checklist works together with:
Cloud Services Register
Identifies the service being retired.
Cloud Service Onboarding Checklist
Documents how the service was originally introduced.
Cloud Security Risk Assessment
Provides the risk context for the service.
Cloud Access Review Checklist
Supports access removal and verification.
Cloud Security Configuration Standard
Provides configuration expectations during operation and before closure.
Cloud Provider Due Diligence Questionnaire
Provides provider and contractual information.
Supplier Offboarding Checklist
Addresses broader supplier relationship termination.
ICT Dependency Register
Identifies business and technology dependencies.
Backup and Recovery Process
Supports continuity and data-recovery requirements.
Change Management Procedure
Controls significant technical changes.
Incident Response Procedure
Handles security incidents discovered during exit.
44. ISO/IEC 27001 Connection
The Cloud Exit Checklist supports applicable ISO/IEC 27001:2022 requirements and controls relating to areas such as:
- Cloud services
- Access rights
- Information deletion
- Information transfer
- Backup
- Configuration management
- Change management
- Supplier relationships
- Supplier service termination
- Information security during disruption
- Redundancy
- Logging and monitoring
- Data protection
- ICT readiness and continuity
The exact controls and activities should be determined through the organization’s:
- ISMS scope
- Risk assessment
- Risk treatment process
- Statement of Applicability
- Legal requirements
- Contractual requirements
- Business continuity requirements
This checklist is an organizational implementation tool and is not itself a universally mandatory ISO document.
45. Final Cloud Exit Audit Trail
A complete exit should demonstrate:
Exit Trigger → Business Dependency Assessment → Criticality Assessment → Exit Approval → Exit Plan → Data Identification → Migration/Return → Data Validation → Backup Review → Access Revocation → Credential Revocation/Rotation → Integration Removal → Network Disconnection → Data Deletion → Contract Closure → Provider Confirmation → Security Verification → Residual Risk Review → Register Updates → Final Approval → Evidence Retention
For a critical cloud service:
Critical Dependency → Exit Strategy → Replacement Service → Migration → Validation → Business Continuity Verification → Security Verification → Controlled Decommissioning → Exit Evidence
46. Final Principle
Cloud exit is not simply:
Cancel the subscription.
A secure cloud exit means:
Know what depends on the service, protect and migrate the information, validate the replacement, remove access and connectivity, address backups and residual copies, complete contractual obligations, verify that the old environment is no longer creating risk, and retain evidence of the exit.
Secure Cloud Exit = Planned Migration + Data Protection + Access Revocation + Dependency Removal + Verified Deletion + Contract Closure + Evidence.
