Code of practice for information security controls for cloud services.
Overview
What is ISO/IEC 27017?
ISO/IEC 27017 is an international standard that provides additional information security guidance specifically for cloud computing environments. The standard extends the controls contained within ISO/IEC 27002 by providing cloud-specific implementation guidance for both cloud service providers and cloud service customers.
ISO/IEC 27017 is a code of practice — a guidance standard — rather than a management system standard against which organizations can be independently certified. It provides structured, cloud-specific security controls and implementation guidance that organizations can adopt to clarify security responsibilities, improve cloud governance, strengthen cloud security controls, and manage risks associated with cloud service delivery and consumption.
The standard is commonly used alongside ISO/IEC 27001 as part of a broader information security and cloud security framework. Organizations that have established an Information Security Management System under ISO/IEC 27001 can incorporate ISO/IEC 27017 guidance into their existing control framework to address the specific security challenges of cloud environments.
Key Themes
What does the standard focus on?
Cloud Security Governance
ISO/IEC 27017 provides structured guidance for governing information security within cloud environments, including the allocation of security responsibilities, management of cloud assets, and oversight of security practices across cloud service relationships between providers and customers.
Shared Responsibility Models
The standard addresses the fundamental cloud security challenge of defining and documenting which security responsibilities are held by the cloud service provider and which are retained by the cloud service customer. Clear shared responsibility models are essential to avoiding security gaps in cloud environments.
Virtual Environment Security
ISO/IEC 27017 provides guidance on securing virtual machines, virtual networks, and other cloud-native components that do not exist in traditional on-premises environments, including the separation of virtual environments and controls over virtualisation infrastructure.
Cloud Service Administration
The standard covers security requirements for the administration of cloud services, including controls over administrative access, privileged user management, audit logging of administrative activities, and the governance of changes to cloud service configurations.
Customer and Provider Responsibilities
ISO/IEC 27017 explicitly addresses the respective obligations of cloud service providers and cloud service customers, providing structured guidance that can be used to negotiate, document, and verify security responsibilities in cloud service agreements and operational procedures.
Asset Ownership and Control
The standard provides guidance on the ownership and control of information assets in cloud environments, including the classification and governance of cloud-hosted assets, and the return or appropriate destruction of assets upon termination of cloud service arrangements.
Monitoring and Logging
ISO/IEC 27017 addresses the monitoring and logging of security events in cloud environments, including the management of log data generated by cloud services, governance of monitoring activities across shared environments, and the responsibilities of both providers and customers for event detection and response.
Cloud Risk Management
The standard supports a structured approach to identifying, assessing, and treating security risks associated with cloud services, including risks related to data sovereignty, multi-tenancy, supply chain dependencies, and the security posture of cloud service providers across the service relationship.
Applicability
Who typically uses ISO/IEC 27017?
Cloud Service Providers
Organizations that supply cloud computing services to external customers, where the standard provides guidance on implementing security controls appropriate to the services delivered and the responsibilities assumed under cloud service agreements.
Infrastructure as a Service Providers
Providers of virtualised computing infrastructure — including compute, storage, and networking resources — where security responsibilities are divided between the provider and the customer, typically with the customer retaining responsibility for operating systems, applications, and data.
Platform as a Service Providers
Providers of cloud platforms on which customers develop and deploy applications, where the division of security responsibilities extends across platform infrastructure, development tooling, and application-level controls governed by the service agreement.
Software as a Service Providers
Providers of cloud-delivered software applications where the provider assumes responsibility for most security controls beneath the application layer, and customers retain responsibility principally for data, identity, and access management within the service.
Managed Service Providers
Organizations that manage cloud infrastructure, platforms, or services on behalf of customers, where security responsibilities span both provider and customer environments and are governed by service agreements and shared responsibility frameworks.
Data Center Operators
Organizations operating data center facilities that support cloud service delivery, where physical and environmental security controls intersect with cloud-specific requirements for virtualisation infrastructure and multi-tenant environments.
Organizations Consuming Cloud Services
Any organization that uses cloud services to support its information processing activities — regardless of service model or deployment type — and that retains security responsibilities for its data, identities, and applications within shared cloud environments.
Government Cloud Environments
Government agencies and public sector bodies operating cloud environments or consuming cloud services, where security governance requirements are typically more stringent and include specific obligations around data sovereignty, access control, and security assurance.
Financial Institutions Using Cloud Services
Banks, insurers, and other regulated financial institutions operating under sector-specific security requirements that increasingly address cloud service risk, including expectations from prudential regulators around cloud governance, security management, and outsourcing controls.
Technology Organizations
Technology companies building products and services on cloud infrastructure, where cloud security governance is both an internal operational requirement and a capability that may be assessed by customers, partners, and regulators as part of supplier assurance activities.
Benefits
Why organizations adopt ISO/IEC 27017
Improved Cloud Security Governance
A structured approach to cloud security governance, grounded in recognized international guidance, enables organizations to manage cloud-specific risks systematically and embed cloud security requirements into existing information security management frameworks.
Clearer Security Responsibilities
ISO/IEC 27017 provides structured guidance for defining and documenting the respective security responsibilities of cloud service providers and customers, reducing ambiguity, preventing security gaps, and supporting more effective cloud service agreements.
Enhanced Customer Confidence
Demonstrating that cloud security practices align with ISO/IEC 27017 guidance supports customer confidence in the security posture of cloud service providers, and helps organizations consuming cloud services provide assurance to their own stakeholders.
Improved Cloud Risk Management
Structured guidance on cloud security risks — including multi-tenancy, data sovereignty, shared environments, and supply chain dependencies — supports more effective identification, assessment, and treatment of risks associated with cloud service delivery and consumption.
Stronger Cloud Security Controls
Cloud-specific controls covering virtual environment security, administrative access, monitoring, logging, and asset governance strengthen the overall information security control environment in ways that generic security frameworks do not fully address.
Better Supplier and Customer Alignment
Organizations on both sides of cloud service relationships benefit from a shared reference framework that clarifies security expectations, supports due diligence activities, and provides a common language for negotiating and verifying contractual security obligations.
Improved Transparency
ISO/IEC 27017 supports transparency in cloud security arrangements by encouraging the clear documentation of security responsibilities, service boundaries, and security controls — making it easier for customers to evaluate the security posture of cloud service providers.
Support for Regulatory and Contractual Requirements
Adopting ISO/IEC 27017 guidance may support compliance with data protection legislation, sector-specific security requirements, and contractual obligations related to cloud service security, where structured cloud security governance is expected or required.
Regulatory Context
Why is ISO/IEC 27017 important?
Organizations increasingly rely on cloud services to support critical business activities. As cloud adoption has expanded, so have the security expectations placed on both cloud service providers and the organizations that consume their services. ISO/IEC 27017 provides a recognized framework for addressing cloud-specific security concerns and demonstrating responsible cloud governance.
Cloud security expectations arise from a range of sources. Customer due diligence, regulatory guidance, data protection requirements, cybersecurity governance programs, supplier assurance obligations, and risk management frameworks all create pressure on organizations — both as providers and consumers of cloud services — to demonstrate structured, evidenced cloud security practices.
FAQ
Common questions
ISO/IEC 27017 is an international standard that provides additional information security controls and implementation guidance specifically for cloud computing environments. It is part of the ISO/IEC 27000 family of standards and extends the control set in ISO/IEC 27002 with cloud-specific guidance for both cloud service providers and cloud service customers. The standard addresses the unique security challenges associated with cloud service delivery, including shared responsibility, virtual environment security, cloud service administration, and the respective obligations of providers and customers within cloud service relationships.
No. ISO/IEC 27017 is a code of practice — a guidance standard — not a management system standard against which organizations can be independently certified. Organizations cannot obtain a standalone ISO/IEC 27017 certificate in the same way they can be certified against ISO/IEC 27001. The standard provides cloud-specific controls and implementation guidance that organizations can adopt to strengthen their information security posture in cloud environments, typically within the context of an ISMS established under ISO/IEC 27001.
ISO/IEC 27001 is the management system standard against which organizations can be independently certified. It specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System and provides the governance framework within which information security is managed. ISO/IEC 27017 is a guidance standard that extends the controls in ISO/IEC 27002 with cloud-specific implementation guidance. It does not carry its own certification scheme. Its controls and guidance are typically incorporated into an existing ISMS framework established under ISO/IEC 27001, rather than implemented independently.
ISO/IEC 27017 is intended for both cloud service providers and cloud service customers — organizations that supply cloud services and organizations that consume them. It is relevant to IaaS, PaaS, and SaaS providers, managed service providers, data center operators, and any organization that relies on cloud services to support its information processing activities. The standard provides guidance applicable across all cloud deployment models and to organizations of any size, sector, or industry that operate in or rely upon cloud environments.
Yes. ISO/IEC 27017 is designed for both cloud service customers and cloud service providers. It addresses the respective security responsibilities of both parties, providing guidance on how cloud customers should approach security governance, shared responsibility models, and contractual arrangements with their cloud providers. Cloud customers can use the standard to strengthen their cloud security controls, assess provider arrangements, manage risks associated with cloud service consumption, and demonstrate responsible cloud governance to their own stakeholders.
Yes. ISO/IEC 27017 provides specific guidance for cloud service providers on security controls that should be implemented to protect customer data, manage virtual environments, govern administrative access, and clarify the respective responsibilities of provider and customer. Cloud providers can use the standard to structure their security governance, strengthen their security controls, support customer due diligence assessments, and demonstrate to customers and regulators that they operate in accordance with recognized cloud security guidance.
ISO/IEC 27017 provides a structured framework for addressing cloud-specific security requirements that frequently arise in regulatory and contractual contexts. Adopting the standard’s guidance may support compliance with data protection legislation, sector-specific security requirements, and contractual obligations related to cloud service security. However, alignment with ISO/IEC 27017 is not in itself a demonstration of compliance with any specific regulation; organizations should assess which regulatory obligations apply to their cloud activities and use the standard as one input into their broader compliance and risk management program.
ISO/IEC 27017 provides cloud-specific guidance on security governance, including the definition of security responsibilities between cloud providers and customers, management of virtual environments, monitoring and logging of cloud activities, and security arrangements in cloud service supply chains. By providing structured guidance on these topics, the standard helps organizations establish clear accountabilities, strengthen their cloud security controls, and maintain consistent security governance across cloud service relationships and across the lifecycle of cloud service arrangements.
There is no formal prerequisite, but ISO/IEC 27017 is designed to complement and extend an ISMS established under ISO/IEC 27001. Organizations that have already implemented ISO/IEC 27001 will find it straightforward to integrate ISO/IEC 27017 guidance into their existing control framework and ISMS scope. Organizations without an established ISMS may still use the standard’s guidance for cloud security purposes, though the most effective and comprehensive implementation typically occurs within the context of a broader information security management framework governed under ISO/IEC 27001.
Organizations can begin by identifying the cloud services currently in use or under consideration, mapping existing security controls against the guidance in ISO/IEC 27017, and identifying gaps that should be addressed. Defining clear security responsibilities between cloud providers and customers — and ensuring those responsibilities are reflected in service agreements and operational procedures — is a practical starting point. Organizations with an existing ISMS under ISO/IEC 27001 should review their current ISMS scope and control framework to determine how ISO/IEC 27017 guidance can be integrated to address cloud-specific security requirements within their established management system.