Frameworks

Cloud security made simple with ISO 27017

Cloud security gaps happen when responsibility boundaries are unclear between your team and your provider.

Tidal eliminates the confusion. Implement cloud-specific security controls, define clear responsibility boundaries, and secure your cloud assets with proven best practices.

Product screenshot

ISO 27017 in depth

ISO 27017 is an international standard that provides additional guidelines for information security in cloud environments. The standard builds on ISO 27001 and specifies security measures for both cloud service providers and cloud customers.

In practice, confusion arises about responsibilities within cloud environments. Without explicit agreements, security responsibilities between provider and customer remain vague, which increases risks.

By applying ISO 27017, clarity emerges in role division, responsibilities, and security measures within the cloud. Cloud security is thus structurally organised instead of implicitly assumed.

How Tidal helps you get certified

Why Tidal Control

We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.

Made in Europe

Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.

Continuous automation

Automated evidence collection from cloud providers and development tools working 24/7 for you.

Real security

Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.

Integrate with your existing tools

Testimonials

What our customers say

With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.

Profile picture of Chiel Bos
Chiel Bos
COO·CBYTE
CBYTE logo

Frequently asked questions

ISO 27017 provides cloud security guidance based on ISO 27002, with additional controls for cloud computing. It's relevant for cloud service providers and organisations using cloud services who want to implement recognised cloud security practices.

ISO 27017 extends ISO 27002 (the control set for ISO 27001) with cloud-specific guidance. It addresses unique cloud security challenges like shared responsibility, virtualisation, and multi-tenancy. Our platform integrates both standards.

Yes, our platform addresses ISO 27017 from both cloud service provider and cloud customer perspectives. We help you implement appropriate controls based on your role and manage shared security responsibilities.

Our platform helps you define and document security responsibilities between cloud providers and customers. We guide you through implementing controls for your responsibility areas and managing interfaces with cloud providers.

Yes, implementing ISO 27017 demonstrates recognised cloud security practices and helps meet various regulatory requirements for cloud computing. Our platform maps ISO 27017 controls to common compliance frameworks.

Our platform continuously monitors cloud security controls, automatically collects evidence from cloud environments, and schedules required reviews. You'll receive alerts for gaps or changes, helping you maintain cloud security with less manual effort.