Glossary

ISO 27017

Standard with specific guidelines for information security in cloud services.

A

B

C

D

E

F

G

H

I

ISO/IEC 27017:2015 provides specific guidelines for information security controls relevant to cloud service providers and cloud customers. It supplements ISO 27001 by addressing security controls specific to cloud computing environments.

The standard covers controls for both cloud service providers and customers, addressing the unique risks associated with cloud computing such as data location, availability, and shared infrastructure security.

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is ISO 27017?
ISO 27017 is a standard that provides cloud-specific information-security guidance, extending the controls of ISO 27002 for cloud service providers and customers.
What is the difference between ISO 27001 and ISO 27017?
ISO 27001 sets the requirements for an information-security management system, while ISO 27017 adds cloud-specific control guidance on top of it.
Who is ISO 27017 for?
Both cloud service providers and organisations that use cloud services and want assurance over shared security responsibilities. ISO 27017 is not certifiable on its own; it is typically added to the scope of an ISO 27001 certification.