GlossaryISO 27001

ISO 27017

Short answer

ISO 27017 is the international code of practice for information security in cloud services. It adds cloud specific guidance to the ISO 27002 controls and introduces additional controls, clarifying which security responsibilities belong to the cloud provider and which to the cloud customer.

What it covers

For each relevant control in ISO 27002, ISO 27017 explains how it applies to cloud services, with separate guidance for providers and customers. It also adds controls specific to the cloud, such as shared roles and responsibilities, removal and return of customer assets when a contract ends, separation between customers in virtual environments, hardening of virtual machines, administrator operational security and monitoring of cloud services.

Who uses it

Mainly cloud providers, including SaaS companies, that want to show customers how they secure their service. Cloud customers can also use it to define what they should require from providers and what remains their own responsibility, such as configuration, identity and data. That customer side is where most cloud incidents originate, as explained under CSPM.

How it is certified

ISO 27017 is a code of practice, not a management system standard, so it is not certified on its own. Organisations usually have its controls assessed as part of their ISO 27001 certification.

Related standards

ISO 27017 is often implemented together with ISO 27018, which focuses on protecting personal data in public clouds. In Spain, cloud services for the public sector must also meet the ENS.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub