ISO/IEC 27017 - Security Controls for Cloud Services
Home
Services
ISO Certifications
ISO/IEC 27017 - Security Controls for Cloud Services
Table of Contents
What is ISO 27017?
Secure Your Cloud, Build Customer Trust
Important Note: ISO/IEC 27017 is not a standalone certification standard. It is an extension to ISO/IEC 27001 (Information Security Management Systems). ISO 27017 certification is always conducted as part of an ISO 27001 certification audit, adding cloud-specific security controls to your existing ISO 27001 ISMS. Organizations must first achieve ISO 27001 certification before ISO 27017 controls can be certified.
Cloud computing has transformed how organizations deliver and consume IT services, offering scalability, flexibility, and cost-efficiency. However, the cloud also introduces unique security challenges that require specialized controls and expertise. At NextGen Assure, we specialize in providing independent third-party ISO/IEC 27017 certification that validates your organization's cloud security controls as an extension to ISO 27001. As a leader in the Testing, Inspection, and Certification industry, we conduct thorough ISO 27017 audits integrated with ISO 27001 that verify your cloud security implementation meets international standards, helping you demonstrate security excellence and build trust with cloud customers and stakeholders.
What is ISO/IEC 27017?
ISO/IEC 27017:2015 is the international standard providing guidance on information security controls applicable to the provision and use of cloud services. It is based on ISO/IEC 27002 (Code of Practice for Information Security Controls) and provides additional implementation guidance for cloud-specific controls referenced in ISO/IEC 27002, as well as additional controls specifically for cloud services.
ISO/IEC 27017 is not a standalone certification standard. It is an extension to ISO/IEC 27001 (Information Security Management Systems). ISO 27017 cannot be certified independently—it must be certified as part of an ISO 27001 certification. Organizations must first establish and certify their ISO 27001 ISMS, and then ISO 27017 controls are added and audited as an extension during the ISO 27001 certification process. The ISO 27017 certificate is issued alongside the ISO 27001 certificate, confirming that cloud-specific controls have been implemented and verified within the ISO 27001 framework.
The standard addresses security from both perspectives: cloud service providers (CSPs) and cloud service customers (CSCs). ISO/IEC 27017 supplements the ISO 27001 Information Security Management System (ISMS) and provides cloud-specific security control guidance for IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and SaaS (Software as a Service) environments.
Key Components of ISO/IEC 27017
ISO 27002 Cloud Guidance: Additional implementation guidance for cloud-relevant ISO 27002 controls
Cloud-Specific Controls: Seven new controls specifically for cloud computing environments
Shared Responsibility Model: Guidance on responsibilities between cloud providers and customers
Cloud Service Categories: Applicable to IaaS, PaaS, and SaaS models
Data Security: Controls for protecting data in multi-tenant cloud environments
Virtualization Security: Controls for securing virtualized infrastructure
Why is ISO/IEC 27017 Important?
ISO/IEC 27017 is essential for organizations providing or using cloud services seeking to address cloud-specific security risks. Here's why this standard is crucial:
1. Cloud-Specific Security Challenges
ISO/IEC 27017 addresses unique cloud security challenges including:
Multi-tenancy and data segregation in shared environments
Virtualization security and hypervisor protection
Data location and sovereignty concerns
Cloud service supply chain security
Secure data deletion and asset disposal in cloud
2. Shared Responsibility Clarity
Implementing ISO/IEC 27017 enables organizations to:
Clearly define security responsibilities between provider and customer
Understand which security controls are managed by whom
Establish appropriate cloud service agreements
Reduce security gaps and misunderstandings
3. Customer Confidence
ISO/IEC 27017 provides a framework for:
Demonstrating cloud security competence to customers
Building trust in cloud service offerings
Meeting customer due diligence requirements
Differentiating services in competitive cloud market
4. Regulatory Compliance
ISO/IEC 27017 certification helps organizations meet regulatory requirements for cloud security including GDPR, HIPAA, PCI DSS, and other data protection regulations requiring appropriate security controls for cloud-processed data.
ISO/IEC 27017 Cloud Security Controls
ISO/IEC 27017 provides comprehensive cloud security controls organized into categories:
Cloud-Specific Controls (New Controls)
Shared Responsibility
Allocation of responsibilities between CSP and CSC
Asset Removal
Procedures for secure removal of customer assets
Customer Data Protection
Protection and segregation of customer data
