WHAT IT IS
Cloud security controls
A code of practical for cloud services
CURRENT VERSION
ISO/IEC 27017:2015
Soon to be updated
CERTIFIABLE?
Yes - with ISO 27001
Added to your ISO 27001 scope
BEST FOR
Cloud providers & users
Anyone selling or using cloud-based services
STANDARD EXPLANATION
What is ISO 27017?
ISO/IEC 27017 is a code of practice for information security in cloud services. Rather than being a standalone standard, it sits on top of ISO/IEC 27002 — the control guidance behind ISO 27001 — and adds cloud-specific detail. It does two things: it gives extra implementation guidance for existing controls when they're applied to the cloud, and it introduces a handful of new controls (seven) that only really make sense in a cloud context.
Its real value is clarifying the shared responsibility model — the perennial source of cloud security confusion. It spells out what a cloud service provider is responsible for and what the customer has to handle themselves, covering things like separating one customer's virtual environment from another's, hardening virtual machines, returning or removing customer data when a contract ends, and giving customers the ability to monitor their own activity.
Unusually, it's written for both sides: cloud service providers and cloud service customers. The current edition is ISO/IEC 27017:2015, confirmed as still current in 2024, with a revised second edition aligned to ISO/IEC 27002:2022 now in the final stages of publication.
You can't certify to ISO 27017 on its own. It extends an existing ISO 27001 certification — once you implement its controls, your ISO 27001 certificate references 27017 in its scope.
WHY PEOPLE COME TO US FOR IT
Do you actually need ISO 27017?
It tends to matter most when the cloud is central to your business — as a provider or a heavy consumer. The trigger usually looks like one of these.
01
You sell a cloud or SaaS product. Customers want assurance you've addressed the cloud-specific risks, not just generic information security.
02
You rely heavily on cloud providers. You want genuine clarity on where your responsibility ends and your provider's begins — before something falls through the gap.
03
You already hold or want ISO 27001. And you want to extend it to address the cloud properly, rather than leaving an obvious gap in your scope.
HOW WE HELP
Two ways in. Same principle throughout.
Whether we're independently auditing your SMS or helping you build it, you stay involved and walk away understanding it. Here's how that splits for ISO 20000.
Audit & Assessment · Independent
We assess your cloud controls against it.
Impartial, evidence-based work — including how your shared-responsibility split actually holds up in practice.
-
Gap analysis of your cloud controls against ISO 27017
-
Review of how provider vs customer responsibility is handled
-
Readiness to add 27017 to your ISO 27001 scope
-
Clear findings and a prioritised plan
Implementation Support · Collaborative
We help you put the controls in place.
Hands-on help applying the cloud-specific controls, with your team driving the work.
-
Implementing the seven cloud-specific controls
-
Clarifying and documenting shared responsibilities
-
Extending your existing ISMS to cover the cloud
-
Preparing for your 27001-plus-27017 audit
COMMON QUESTIONS
ISO 27017 questions we hear a lot
Can I get certified to ISO 27017 on its own?
No. It isn't a standalone certifiable standard — it extends ISO 27001 and builds alongside ISO 27002. When you implement its controls, your ISO 27001 certificate references 27017 in its scope statement. So it always rides alongside a 27001 certification.
Do I need ISO 27001 first?
Effectively, yes. ISO 27017 builds on the ISO 27002 control set and an ISO 27001 management system, so it's implemented as an extension of that — either alongside a fresh 27001 project or added to an existing certification.
Is it for cloud providers or cloud customers?
Both — which is a tad bit unusual. It gives guidance to cloud service providers on the controls they should offer, and to cloud customers on what they should expect and handle themselves. That two-sided view is much of its value.
What does it actually add?
Cloud-specific implementation guidance for a large set of existing ISO 27002 controls, plus seven new controls unique to the cloud — covering things like separating customers' virtual environments, hardening virtual machines, and returning data when a contract ends.
What's the current version?
ISO/IEC 27017:2015, which was reviewed and confirmed as current in 2024. A revised second edition, aligned to ISO/IEC 27002:2022, is in the final stages of publication — so it's worth keeping an eye on if you're starting now. Keep an eye on the ISO website for further details.
How does it relate to ISO 27018?
ISO 27017 covers cloud security in general; ISO 27018 focuses specifically on protecting personal data (PII) in the cloud. They're complementary, and cloud providers often implement both together as extensions to the same ISO 27001 system.
RELATED STANDARDS
Often comes up alongside
ISO 27001
The security half of the MSP conversation - extremely common to run both together.
Information Security
ISO 27018
The privacy-focused companion - protecting personal data in the same cloud environments.
Cloud Privacy (PII)
ISO 27701
A broader privacy management system, where cloud privacy is one piece.

