Independent certification is the best way to assure the claims made by a CSP. However, it is important to properly understand that what is certified is relevant to your needs. ISO/IEC 27001:2005 remains a key information security standard (although a new standard for cloud services is being developed). Although they are not specifically focussed on cloud, the recent standards for SOC reports (service organization control reports) are very relevant.
9. Trust but verify
Using the cloud inherently involves an element of trust between the consumer and the provider of the cloud service. However, this trust must not be unconditional and it is vital to ensure that the trust can be verified.