Apply cloud-specific security controls as an extension to ISO 27001.ISO/IEC 27017 is a code of practice that provides cloud-specific information security controls. It supplements the guidance in ISO 27002 with additional controls and implementation guidance for both cloud service providers and cloud service customers.
ISO 27017 is not independently certifiable — it is implemented alongside an ISO 27001 ISMS to address cloud-specific risks.
Who needs ISO 27017:2015?
Cloud providers
Organizations offering cloud services that want to demonstrate cloud-specific security.
Cloud customers
Organizations using cloud services that need guidance on their security responsibilities.
Key components
Shared responsibility
Clarifies the division of security responsibilities between provider and customer.
Cloud controls
Additional implementation guidance for 37 ISO 27002 controls in a cloud context.
Seven new controls
Cloud-specific controls not found in ISO 27002, such as virtual machine hardening.
Customer guidance
Helps customers understand and configure their cloud security posture.
How DSALTA helps with ISO 27017:2015
Frequently asked questions
Is ISO 27017 a standalone certification?
Is ISO 27017 a standalone certification?
No. It is implemented as an extension to ISO 27001 and assessed as part of that certification.
How is 27017 different from 27018?
How is 27017 different from 27018?
27017 covers cloud security broadly, while 27018 focuses specifically on protecting personal data (PII) in public clouds.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)