PAKISTAN CLOUD FIRST POLICY
9.3
Registration of Cloud Service Providers
CSP that intend to host Open Data (Annex-E) are required to get registered with Cloud Office with
minimal registration requirements to ensure provision of quality cloud services. Cloud Office will
prioritise the ease of doing business for CSP and ensure business enabling environment for cloud
adoption.
9.4
ICT Audits
Audits are means to ensure that CSP provide adequate levels of protection for the treatment of
information assets in accordance with the standards set by the Cloud Office. This policy mandates that
CSP provide satisfactory audit reports or respond to audit requests made by the Cloud Office. Relevant
authorities and other certified third parties will be able to monitor and perform audits to validate the
contractually agreed controls. Moreover, the CSP should also employ internal audit mechanisms to
ensure the prescribed requirements are adhered to. Audits can either be carried out at regular intervals
or on as the need be. The Cloud Office can designate any auditing body to carry out the audits based on
the criteria outlined by the Cloud Office.
9.5
Cloud Acquisition Office
A Cloud Acquisition Office (CAO) will be established in the federal jurisdiction. Similarly, the province
that adopts Cloud Policy in line with this policy will establish CAO in their jurisdictions to support
provincial PSE in their transition to the cloud. CAO will facilitate PSE in designing, architecting,
procuring, building, migrating, and managing their workloads and applications on the cloud. CAO will
initiate call offs for the requirements of PSE. Only CSP accredited by the Cloud Office will be eligible
to take part in call offs. CSP with the most advantageous offering will be selected in the call off. SLA
will be signed between the CSP and PSE accordingly. Any breach of the SLA between PSE and CSP
will be reported to CAO by the PSE. CAO will report continued serious non-compliance of SLA by
CSP to Cloud Office. Apart from other remedies available to PSE, the Cloud Office will take
appropriate action depending upon the nature and seriousness of non-compliance.
9.6
Restrictions on Investments in Fragmented ICT infrastructure
With the approval of this policy GoP will require all PSE to review any projects which involve setting
up a data center/ICT infrastructure/Server Room and will prioritise cloud-based solutions for any future
ICT investments. Same provisions will apply on any projects in the public sector implemented via a
third-party or donor agency. Federal Government will also advise provincial governments to share the
same directives to its subordinate organizations to restrict investments on fragment ICT infrastructure
and prioritise cloud. After 1st July 2022, all new ICT investments should adhere to the directions of
Cloud Office.
9.7
Data Classification
Data classification is the process of organizing data into categories so that the data can be utilized
according to its sensitivity and criticality. PSE will have different types of information and that
information will be associated with varying levels of sensitivity. Data classification framework provides
a tool to classify and categorize data based on respective sensitivities and hence enable PSE to define
controls against each classification category.
A clear data classification framework is essential to ensure that the critical benefits of cloud computing
are achieved cost-effectively. This ultimately enables decision-makers to better understand what types
of data can be stored on each type of cloud model. Such a framework can be used when considering
any type of cloud service as this will allow PSE to better align costs for bespoke security technology
Page 11 of 21