This document discusses evaluating the security of cloud service providers. It recommends using a risk-based approach and tools from organizations like the Cloud Security Alliance to conduct due diligence assessments of providers. Key steps include understanding business needs and risk tolerance, examining the provider's security maturity and assertions, using standard assessment frameworks, and producing a fully informed decision. The goal is to determine if a provider can adequately protect data and systems according to the organization's security requirements.