Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 27017

Cloud Services Information Security Controls

Technology & Innovation Published: 2026

ISO 27017:2026 at a glance

Current edition
ISO/IEC 27017:2026 - Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Published
2026
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO/IEC 27017:2015
Official ISO page
View ISO 27017:2026 on iso.org
Last verified

Overview

Cloud-specific information security guidance extending ISO/IEC 27002 for cloud service providers and cloud service customers; second edition published 2026

ISO/IEC 27017 gives guidance on information security controls for cloud services. It extends ISO/IEC 27002 by adding cloud-specific implementation guidance to existing controls and by introducing additional controls that only arise in a cloud context. The second edition, ISO/IEC 27017:2026, was published in July 2026 and replaces ISO/IEC 27017:2015, which is withdrawn; it reflects the restructured control set introduced by ISO/IEC 27002:2022.

The standard is unusual in addressing both sides of the relationship. For each control area it distinguishes guidance for the cloud service provider from guidance for the cloud service customer, which makes it a practical tool for working out the shared responsibility model — the single most common source of cloud security failures, where each party assumes the other is handling a control.

Cloud-specific subject matter includes: shared roles and responsibilities within a cloud computing environment; removal and return of cloud service customer assets on termination; segregation in virtual computing environments; virtual machine hardening; administrator operational security; monitoring of cloud service use by the customer; and alignment of security management for virtual and physical networks.

It also addresses the practical questions customers ask during due diligence: what the provider will disclose about the geographic location of data and processing, how the provider manages its own subservice organizations, what logging and monitoring data the customer can access, how virtualisation boundaries are maintained between tenants, and what happens to data at the end of the contract.

ISO/IEC 27017 is a code of practice / guidance document rather than a requirements standard, so there is no accredited certification against ISO/IEC 27017 on its own. In the market, certification bodies commonly audit ISO/IEC 27017 (and ISO/IEC 27018) as an extension to an ISO/IEC 27001 certification, issuing a statement or supplementary certificate that the cloud-specific controls have been assessed within the scope of the ISMS. Buyers evaluating a provider's claim should therefore check that a valid ISO/IEC 27001 certificate underlies it and that the ISMS scope covers the service in question.

The natural companions are ISO/IEC 27001 (ISMS requirements), ISO/IEC 27002 (the base control set), ISO/IEC 27018 (protection of personally identifiable information in public clouds where the provider is a PII processor), ISO/IEC 27701 (privacy information management), and the ISO/IEC 17788 and 17789 cloud vocabulary and reference architecture documents.

Purpose

To provide cloud service providers and cloud service customers with cloud-specific information security guidance built on ISO/IEC 27002, so that responsibilities are clearly divided and cloud-specific risks are addressed by both parties.

Key Benefits

  • Adds cloud-specific implementation guidance to the familiar ISO/IEC 27002 control structure
  • Gives separate guidance for providers and customers, clarifying the shared responsibility model
  • Addresses virtualisation and multi-tenancy risks that generic control sets do not cover
  • Provides a common reference for cloud security clauses in contracts and due diligence questionnaires
  • Covers asset return and deletion at the end of a cloud service agreement
  • Supports customer visibility requirements such as logging, monitoring and administrator activity
  • Frequently audited as an extension to ISO/IEC 27001, providing recognisable assurance to buyers
  • Applies across IaaS, PaaS and SaaS and to public, private and hybrid deployments
  • Pairs with ISO/IEC 27018 to cover both security and privacy aspects of public cloud services
  • Second edition aligns with the modern ISO/IEC 27002:2022 control themes and attributes

Key Requirements

  • Note: ISO/IEC 27017 is guidance built on ISO/IEC 27002 — it is applied within an ISO/IEC 27001 ISMS rather than certified against on its own
  • Define and document shared roles and responsibilities between cloud service provider and customer
  • Agree and document the scope of the cloud service and the security responsibilities attached to it
  • Address removal and return of cloud service customer assets on termination of the agreement
  • Implement segregation between cloud service customers in virtual computing environments
  • Harden virtual machines and manage the security configuration of virtualised infrastructure
  • Control and monitor administrator operations, including privileged access to the cloud platform
  • Provide the customer with capability to monitor its own use of the cloud service
  • Align security management for virtual networks with the security of physical networks
  • Disclose relevant information to customers, including geographic location of data and use of subservice providers
  • Manage cryptographic key ownership and responsibilities between provider and customer
  • Apply the corresponding ISO/IEC 27002 controls with the cloud-specific implementation guidance

Who Needs This Standard?

Cloud service providers of all kinds (IaaS, PaaS, SaaS) that need to evidence cloud security to customers, and cloud service customers — including enterprises, public bodies and regulated firms — that need a structured basis for assessing providers and configuring their own side of the shared responsibility model.

Where to get ISO 27017

The full text of ISO 27017 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27017 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 27017, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 27017 — it is guidance, and no accredited scheme exists for it. The closest standard you can certify against is ISO 27001 (Information Security Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with it. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards