What it covers
For each relevant control in ISO 27002, ISO 27017 explains how it applies to cloud services, with separate guidance for providers and customers. It also adds controls specific to the cloud, such as shared roles and responsibilities, removal and return of customer assets when a contract ends, separation between customers in virtual environments, hardening of virtual machines, administrator operational security and monitoring of cloud services.
Who uses it
Mainly cloud providers, including SaaS companies, that want to show customers how they secure their service. Cloud customers can also use it to define what they should require from providers and what remains their own responsibility, such as configuration, identity and data. That customer side is where most cloud incidents originate, as explained under CSPM.
How it is certified
ISO 27017 is a code of practice, not a management system standard, so it is not certified on its own. Organisations usually have its controls assessed as part of their ISO 27001 certification.
Related standards
ISO 27017 is often implemented together with ISO 27018, which focuses on protecting personal data in public clouds. In Spain, cloud services for the public sector must also meet the ENS.




