ISO/IEC 27017
ISO 27017 is a code of practice that adds cloud-specific implementation guidance to ISO 27002 controls, plus seven cloud-only controls. Certified as an extension to ISO 27001.
Who it applies to
Cloud service providers and organisations using cloud services.
How ISO-STANDARD.app helps with ISO 27017
10 in-depth articles
The seven ISO 27017 cloud-specific controls
27017's own controls (beyond the enhanced 27002 guidance). Cloud customers and providers each have a stake.
Shared roles and responsibilities
The customer and provider must document who is responsible for what. Without this, the entire ISMS scope is ambiguous.
Removal of cloud service customer assets
On termination, customer data must be returned or securely deleted with confirmation. This is a specific control, not implied.
Segregation in virtual computing environments
Multi-tenant isolation controls: hypervisor security, network segmentation, access boundaries.
Virtual machine hardening
Base image control, configuration baselines, snapshot management.
Administrator's operational security
Cloud admin identity, MFA, session logging, break-glass processes.
Monitoring of cloud services
Customer-visible logs, alerting, retention. If the provider doesn't expose it, the customer can't monitor.
Alignment of security management for virtual and physical networks
Consistent policies across virtual and physical estates — no gap where the boundary sits.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
ISO 27017 vs ISO 27018: which do you need?
27017 is cloud security. 27018 is cloud-specific PII protection. Most cloud providers pursue both.
Different scopes
27017 addresses cloud security controls broadly. 27018 addresses processor obligations for PII in the cloud.
Customer vs provider view
27017 has controls for both cloud customers and providers. 27018 is primarily for processors.
Certification stacking
Both certify as extensions to ISO 27001. A cloud provider commonly holds ISO 27001 + 27017 + 27018.
What buyers ask for
Enterprise procurement often asks for both certificates. Answer once with a well-structured certification pack.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Cloud customer vs cloud provider controls
ISO 27017 explicitly separates 'guidance for customers' from 'guidance for providers' for many controls.
The split matters
The same control has different guidance depending on which side you sit. Following the wrong side produces awkward audit evidence.
Customer-side highlights
Consuming provider logs, validating provider assurances, managing customer-controlled configuration.
Provider-side highlights
Multi-tenant isolation, customer-facing security features, provider transparency obligations.
Shared responsibility model
Every provider now publishes a shared responsibility model — ISO 27017 formalises it as a control expectation.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Multi-tenant isolation for ISO 27017
Isolation is the control that separates 'a cloud service' from 'a shared server with a login screen'.
Compute isolation
Hypervisor hardening, dedicated vs shared instances, side-channel controls.
Network isolation
Virtual networks per tenant, egress controls, no shared broadcast domains.
Storage isolation
Per-tenant encryption keys, storage-level access controls, deletion assurance across replicas.
Identity isolation
Tenant IDs enforced at every service call. No cross-tenant admin without explicit customer request and logging.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Managing customer-configurable cloud controls
Providers ship secure defaults but customers often turn them off. 27017 addresses both sides.
Secure defaults
Encryption at rest, MFA on admin, logging on. Providers under 27017 should ship these on.
Customer misconfiguration
S3-style open bucket incidents happen when customers change defaults. Providers add rails; customers hold responsibility.
Guardrails
SCPs, org-level policies, config rules. These are 27017-friendly implementations of customer-side responsibilities.
Awareness
Customers need to understand what they configure. Provider documentation, training and Trust Center content help.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Cryptographic key management under ISO 27017
Who holds the keys is the central cloud question. 27017 doesn't dictate — it dictates that you decide and document.
Provider-managed keys
Fastest, cheapest, least isolation from provider. Acceptable for many customer risk appetites.
Customer-managed keys (BYOK)
Customer controls the key material; provider uses it. Common in regulated industries.
Hold-your-own-key (HYOK)
Customer holds the key entirely; provider never sees it. Highest isolation, biggest operational cost.
Documentation
The choice must be documented and communicated. A change in choice is a change control matter.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Cloud audit logs: what ISO 27017 expects
Logs the customer cannot see are not evidence the customer can rely on.
Log content
Admin actions, data-plane operations, tenant boundary events. Enough to reconstruct 'what happened'.
Log delivery
Customer-accessible via API or SIEM feed. Retention window disclosed.
Provider self-monitoring
Provider monitors its own operators. Break-glass access is logged and reviewed.
Immutable retention
Where legal or contractual, immutable log retention. WORM storage or equivalent.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Documenting the shared responsibility model for auditors
Every ISO 27001+27017 audit asks 'who does what?' Documented answers save days.
A single artefact
One page per service tier (IaaS/PaaS/SaaS) with a table: control area → provider / customer / shared.
Contractual alignment
The artefact reflects your contract. Divergence between contract and diagram is a finding waiting to happen.
Change management
Provider service model changes = artefact update = customer notification. Instrument this loop.
Buyer publication
Publish the shared-responsibility artefact in the Trust Center. It answers a lot of enterprise questionnaires by itself.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Data return and deletion on cloud contract termination
'We deleted the data' is not evidence. 27017 pushes providers to deliver actual assurance.
Return format
Standard, portable format. CSV, JSON, or a documented export API. Not a proprietary blob.
Deletion assurance
Certificate of deletion, or logs demonstrating deletion across replicas and backups within the specified timeframe.
Backup rotation
Deletion is usually eventual because of backup rotation. Disclose the maximum window.
Testing
Test the export at least annually. A never-tested export is a fiction.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Consuming ISO 27017-certified cloud services as a customer
27017 is a supplier-assurance shortcut. Use it well and your vendor risk work compresses.
Scope check
Certification scope varies. 'Provider X is ISO 27017 certified' — for which service, in which region?
Certification package
SoA, scope statement, certificate. Save them in your evidence vault against the vendor.
Recertification tracking
Track expiry dates. Recertification gap = questionnaire time again.
Reduce your questionnaire
Trust the certification for the areas it covers; ask targeted questions on the rest. Faster procurement, better supplier relationship.
How ISO-STANDARD.app helps with ISO 27017
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27017 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27017 shape.
Ready to evidence ISO 27017?
Load the pre-mapped controls, capture evidence continuously, and publish your ISO 27017 posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.