Frameworks
Cloud security made simple with ISO 27017
Cloud security gaps happen when responsibility boundaries are unclear between your team and your provider.
Tidal eliminates the confusion. Implement cloud-specific security controls, define clear responsibility boundaries, and secure your cloud assets with proven best practices.

ISO 27017 in depth
ISO 27017 is an international standard that provides additional guidelines for information security in cloud environments. The standard builds on ISO 27001 and specifies security measures for both cloud service providers and cloud customers.
In practice, confusion arises about responsibilities within cloud environments. Without explicit agreements, security responsibilities between provider and customer remain vague, which increases risks.
By applying ISO 27017, clarity emerges in role division, responsibilities, and security measures within the cloud. Cloud security is thus structurally organised instead of implicitly assumed.
How Tidal helps you get certified
Hit the ground running
Start with our pre-built controls, policies, and risk assessment templates.
Our platform guides you through establishing your ISMS scope, identifying assets, and implementing right-sized controls that match your business needs.


Why Tidal Control
We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.
Made in Europe
Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.
Continuous automation
Automated evidence collection from cloud providers and development tools working 24/7 for you.
Real security
Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.
Go beyond ISO 27017
Explore complementary frameworks that enhance your cloud security strategy.
ISO 27001
Building a foundation for cloud security? ISO 27001 provides the information security framework that ISO 27017 builds upon with cloud-specific guidance.
CIS Controls
Implementing actionable cloud controls? CIS Controls provide specific, prioritised security recommendations that complement ISO 27017's cloud security requirements.
ISO 27018
Securing personal data in the cloud? ISO 27018 complements ISO 27017 by adding specific controls for protecting personally identifiable information in cloud environments.
NIST CSF
Aligning with global cloud security standards? NIST Cybersecurity Framework provides another approach to cloud security that aligns with ISO 27017's objectives.
Integrate with your existing tools

Testimonials
What our customers say
With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.
Frequently asked questions
ISO 27017 provides cloud security guidance based on ISO 27002, with additional controls for cloud computing. It's relevant for cloud service providers and organisations using cloud services who want to implement recognised cloud security practices.
ISO 27017 extends ISO 27002 (the control set for ISO 27001) with cloud-specific guidance. It addresses unique cloud security challenges like shared responsibility, virtualisation, and multi-tenancy. Our platform integrates both standards.
Yes, our platform addresses ISO 27017 from both cloud service provider and cloud customer perspectives. We help you implement appropriate controls based on your role and manage shared security responsibilities.
Our platform helps you define and document security responsibilities between cloud providers and customers. We guide you through implementing controls for your responsibility areas and managing interfaces with cloud providers.
Yes, implementing ISO 27017 demonstrates recognised cloud security practices and helps meet various regulatory requirements for cloud computing. Our platform maps ISO 27017 controls to common compliance frameworks.
Our platform continuously monitors cloud security controls, automatically collects evidence from cloud environments, and schedules required reviews. You'll receive alerts for gaps or changes, helping you maintain cloud security with less manual effort.


























