ISO/IEC 27017

ISO 27017 is a code of practice that adds cloud-specific implementation guidance to ISO 27002 controls, plus seven cloud-only controls. Certified as an extension to ISO 27001.

Who it applies to

Cloud service providers and organisations using cloud services.

How ISO-STANDARD.app helps with ISO 27017

Pre-loaded ISO 27017 control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current ISO 27017 posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to ISO 27017 clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

The seven ISO 27017 cloud-specific controls

27017's own controls (beyond the enhanced 27002 guidance). Cloud customers and providers each have a stake.

Shared roles and responsibilities

The customer and provider must document who is responsible for what. Without this, the entire ISMS scope is ambiguous.

Removal of cloud service customer assets

On termination, customer data must be returned or securely deleted with confirmation. This is a specific control, not implied.

Segregation in virtual computing environments

Multi-tenant isolation controls: hypervisor security, network segmentation, access boundaries.

Virtual machine hardening

Base image control, configuration baselines, snapshot management.

Administrator's operational security

Cloud admin identity, MFA, session logging, break-glass processes.

Monitoring of cloud services

Customer-visible logs, alerting, retention. If the provider doesn't expose it, the customer can't monitor.

Alignment of security management for virtual and physical networks

Consistent policies across virtual and physical estates — no gap where the boundary sits.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

ISO 27017 vs ISO 27018: which do you need?

27017 is cloud security. 27018 is cloud-specific PII protection. Most cloud providers pursue both.

Different scopes

27017 addresses cloud security controls broadly. 27018 addresses processor obligations for PII in the cloud.

Customer vs provider view

27017 has controls for both cloud customers and providers. 27018 is primarily for processors.

Certification stacking

Both certify as extensions to ISO 27001. A cloud provider commonly holds ISO 27001 + 27017 + 27018.

What buyers ask for

Enterprise procurement often asks for both certificates. Answer once with a well-structured certification pack.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Cloud customer vs cloud provider controls

ISO 27017 explicitly separates 'guidance for customers' from 'guidance for providers' for many controls.

The split matters

The same control has different guidance depending on which side you sit. Following the wrong side produces awkward audit evidence.

Customer-side highlights

Consuming provider logs, validating provider assurances, managing customer-controlled configuration.

Provider-side highlights

Multi-tenant isolation, customer-facing security features, provider transparency obligations.

Shared responsibility model

Every provider now publishes a shared responsibility model — ISO 27017 formalises it as a control expectation.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Multi-tenant isolation for ISO 27017

Isolation is the control that separates 'a cloud service' from 'a shared server with a login screen'.

Compute isolation

Hypervisor hardening, dedicated vs shared instances, side-channel controls.

Network isolation

Virtual networks per tenant, egress controls, no shared broadcast domains.

Storage isolation

Per-tenant encryption keys, storage-level access controls, deletion assurance across replicas.

Identity isolation

Tenant IDs enforced at every service call. No cross-tenant admin without explicit customer request and logging.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Managing customer-configurable cloud controls

Providers ship secure defaults but customers often turn them off. 27017 addresses both sides.

Secure defaults

Encryption at rest, MFA on admin, logging on. Providers under 27017 should ship these on.

Customer misconfiguration

S3-style open bucket incidents happen when customers change defaults. Providers add rails; customers hold responsibility.

Guardrails

SCPs, org-level policies, config rules. These are 27017-friendly implementations of customer-side responsibilities.

Awareness

Customers need to understand what they configure. Provider documentation, training and Trust Center content help.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Cryptographic key management under ISO 27017

Who holds the keys is the central cloud question. 27017 doesn't dictate — it dictates that you decide and document.

Provider-managed keys

Fastest, cheapest, least isolation from provider. Acceptable for many customer risk appetites.

Customer-managed keys (BYOK)

Customer controls the key material; provider uses it. Common in regulated industries.

Hold-your-own-key (HYOK)

Customer holds the key entirely; provider never sees it. Highest isolation, biggest operational cost.

Documentation

The choice must be documented and communicated. A change in choice is a change control matter.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Cloud audit logs: what ISO 27017 expects

Logs the customer cannot see are not evidence the customer can rely on.

Log content

Admin actions, data-plane operations, tenant boundary events. Enough to reconstruct 'what happened'.

Log delivery

Customer-accessible via API or SIEM feed. Retention window disclosed.

Provider self-monitoring

Provider monitors its own operators. Break-glass access is logged and reviewed.

Immutable retention

Where legal or contractual, immutable log retention. WORM storage or equivalent.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Documenting the shared responsibility model for auditors

Every ISO 27001+27017 audit asks 'who does what?' Documented answers save days.

A single artefact

One page per service tier (IaaS/PaaS/SaaS) with a table: control area → provider / customer / shared.

Contractual alignment

The artefact reflects your contract. Divergence between contract and diagram is a finding waiting to happen.

Change management

Provider service model changes = artefact update = customer notification. Instrument this loop.

Buyer publication

Publish the shared-responsibility artefact in the Trust Center. It answers a lot of enterprise questionnaires by itself.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Data return and deletion on cloud contract termination

'We deleted the data' is not evidence. 27017 pushes providers to deliver actual assurance.

Return format

Standard, portable format. CSV, JSON, or a documented export API. Not a proprietary blob.

Deletion assurance

Certificate of deletion, or logs demonstrating deletion across replicas and backups within the specified timeframe.

Backup rotation

Deletion is usually eventual because of backup rotation. Disclose the maximum window.

Testing

Test the export at least annually. A never-tested export is a fiction.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Consuming ISO 27017-certified cloud services as a customer

27017 is a supplier-assurance shortcut. Use it well and your vendor risk work compresses.

Scope check

Certification scope varies. 'Provider X is ISO 27017 certified' — for which service, in which region?

Certification package

SoA, scope statement, certificate. Save them in your evidence vault against the vendor.

Recertification tracking

Track expiry dates. Recertification gap = questionnaire time again.

Reduce your questionnaire

Trust the certification for the areas it covers; ask targeted questions on the rest. Faster procurement, better supplier relationship.

How ISO-STANDARD.app helps with ISO 27017

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.

Ready to evidence ISO 27017?

Load the pre-mapped controls, capture evidence continuously, and publish your ISO 27017 posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.