Skip to content
All articles
Standards explained

What Is ISO 27017? Cloud Security Certification Explained

ISO 27017 is the international standard for cloud security. What it covers, the cloud controls it adds, how it is certified as an extension of ISO 27001, and who needs it.

9 min read
Padlock silhouette captioned Cloud Security, against a burst of blue binary code
Share

Almost every organisation now runs part of its business in the cloud, but a general information security programme was not designed for the cloud's particular risks. ISO/IEC 27017 fills that gap. It is the international standard for cloud security, giving both cloud providers and their customers a clear set of controls for protecting data in cloud services. This guide explains what ISO 27017 is, what it covers, how certification actually works, and who needs it, in plain terms.

What ISO 27017 is, in brief

ISO/IEC 27017 is an international standard that provides security guidance and controls specifically for cloud services. It was created because moving to the cloud changes the nature of information security in ways a standard information security management system does not fully address on its own. The current edition, ISO/IEC 27017:2015, sits within the wider ISO 27000 family and builds directly on ISO/IEC 27002, the code of practice for information security controls.

What makes ISO 27017 distinctive is that it speaks to both sides of the cloud relationship. It gives guidance to cloud service providers, the organisations that operate cloud platforms and services, and to cloud service customers, the organisations that use them. Because responsibility for security in the cloud is shared between these two parties, and because confusion over who is responsible for what is a common source of risk, this dual focus is one of the standard's most useful features.

Why cloud security needs its own standard

When an organisation runs its systems on its own infrastructure, it controls the whole environment. In the cloud, that is no longer true. Your data sits on infrastructure owned and operated by someone else, and security becomes a shared undertaking between you and your cloud provider. The question of exactly where the provider's responsibility ends and yours begins is not always obvious, and getting it wrong leaves gaps that neither party is watching.

A general information security programme, even a strong one, does not automatically account for this. It was built for an environment the organisation controls directly. Cloud computing introduces specific concerns: how responsibilities are divided, how virtual environments are secured and separated, how a customer's data is returned or deleted when they leave a service, and how activity in the cloud is monitored. ISO 27017 exists precisely to address these cloud-specific issues, extending established information security practice into the cloud rather than leaving the cloud as a blind spot.

What ISO 27017 covers

ISO 27017 works in two ways. First, it takes a large set of the controls already defined in ISO 27002 and provides cloud-specific implementation guidance for them, explaining how each should be applied in a cloud context. Second, it adds a set of new controls that exist only because of the cloud and are not found in the general standard.

These cloud-specific additions address the issues that matter most in a shared cloud environment. They cover the shared responsibilities between provider and customer, making explicit who is accountable for each aspect of security. They address the removal and return of customer assets when a cloud service contract ends, so data does not linger where it should not. They cover the separation and hardening of virtual environments, so one customer's data is properly isolated from another's. And they address the monitoring of cloud services, so both provider and customer have visibility into what is happening. Together, these turn the vague idea of “cloud security” into a concrete, assessable set of practices.

How ISO 27017 certification actually works

This is the point most worth understanding clearly, because it differs from how many people assume certification works. ISO 27017 is not certified as a standalone standard with its own separate certificate. Instead, certification is achieved by extending the scope of an ISO 27001 audit to include the ISO 27017 cloud controls.

The logic is straightforward. ISO 27017 builds on the foundation of an information security management system, so it makes sense to assess it as part of that system rather than in isolation. In practice, an organisation that holds or is pursuing ISO 27001 certification has the ISO 27017 cloud controls assessed alongside its core information security controls, in one coordinated audit. The result is recognised confirmation that the organisation's cloud security has been independently assessed against the standard.

This has a practical implication worth planning for: ISO 27017 sits naturally on top of ISO 27001, not apart from it. For an organisation already serious about information security, adding cloud security certification is an extension of work already underway rather than a wholly separate project. Certiva Global assesses ISO 27017 in exactly this way, as part of the information security certification, so cloud security is covered coherently rather than bolted on.

Who needs ISO 27017

ISO 27017 is relevant to two broad groups, and often to both at once.

Cloud service providers use it to demonstrate that the services they offer are secured to a recognised international standard. As enterprise customers grow more careful about where their data lives, the ability to show independently assessed cloud security is increasingly a condition of winning and keeping business. For a provider, ISO 27017 is a way to turn “trust us, it's secure” into something a customer can verify.

Cloud service customers use it to show that they manage their own use of the cloud responsibly. It is a mistake to assume that because a provider is secure, the customer's responsibilities are covered; the shared-responsibility model means the customer always retains a share. Organisations in IT and software, banking and financial services, and healthcare, sectors where sensitive data routinely moves into cloud services, use ISO 27017 to demonstrate that they take that responsibility seriously.

In short, if your organisation delivers cloud services, depends on them for anything sensitive, or both, ISO 27017 is the recognised way to prove that dependence is well managed.

ISO 27017 and ISO 27018: the cloud pair

ISO 27017 is very often mentioned alongside ISO 27018, and the two are complementary rather than competing. ISO 27017 addresses cloud security in general. ISO 27018 focuses specifically on the protection of personal data, the personally identifiable information (PII) that a cloud provider handles on behalf of its customers.

Many cloud providers pursue both, because they answer different questions that enterprise customers ask during due diligence. ISO 27017 answers “is your cloud service secure.” ISO 27018 answers “and how specifically do you protect the personal data within it.” Both are extensions of an ISO 27001 information security management system, so they can be assessed together in a coordinated audit. For a cloud provider handling personal data, the two standards together present a strong, complete picture of cloud security and cloud privacy.

Why cloud security matters more each year

The direction of travel is clear. Organisations are placing ever more of their operations and data into cloud services, and their customers, and increasingly their regulators, are paying closer attention to how that data is protected. It is no longer enough to use reputable cloud providers and assume the matter is handled. Enterprise buyers now ask specific questions about cloud security during procurement, and vague answers do not pass.

For organisations in India serving domestic and international clients, this scrutiny is rising alongside broader expectations around data protection. Demonstrating cloud security through a recognised standard is becoming a practical requirement for doing business, particularly for the IT and software companies, financial services organisations, and healthcare providers that handle sensitive data in the cloud. ISO 27017 gives these organisations a credible, independent way to show that their cloud security is real and assessed, not merely asserted.

What an ISO 27017 assessment looks at

Because ISO 27017 is assessed as part of an ISO 27001 audit, it helps to understand what the auditor actually examines when the cloud controls come into scope. The focus is practical: not whether the cloud is used, but whether it is used securely and with responsibilities clearly understood.

The auditor looks first at how the shared responsibility model is defined and documented. In a cloud arrangement, some controls are the provider's to operate, some are the customer's, and some are shared, and the standard expects an organisation to be clear about which is which for the services it uses or offers. An organisation that cannot say where its responsibility begins and ends has a gap the auditor will find. The assessment examines whether this division is understood, agreed, and reflected in how the cloud is actually run.

The auditor also examines the cloud-specific controls in operation: how virtual environments are separated and hardened, how access to cloud services is granted and reviewed, how activity in the cloud is logged and monitored, and how customer data is handled at the end of a service, including its return or secure deletion. As with any part of an ISO 27001 audit, the emphasis is on evidence. It is not enough to describe a control; the organisation must be able to show it operating. This is what makes an ISO 27017 assessment meaningful rather than a paper exercise, and it is why the resulting certification carries weight with the customers who ask for it.

Common misunderstandings about ISO 27017

A few misunderstandings come up often, and clearing them away helps an organisation approach the standard sensibly.

The most common is the belief that ISO 27017 is a standalone certificate you pursue on its own. As explained above, it is not; it is certified as an extension of an ISO 27001 information security management system. Understanding this early avoids wasted effort and sets the right expectation about what the certification journey involves.

A second misunderstanding is that using a secure, reputable cloud provider means cloud security is fully handled. It is not. The shared responsibility model means the customer always retains a portion of responsibility, however capable the provider. A provider can secure its infrastructure, but how an organisation configures its services, manages access, and handles its data within them remains the organisation's own responsibility. ISO 27017 exists partly to make this division explicit, so that nothing falls through the gap between the two parties.

A third is the assumption that cloud security and cloud privacy are the same thing. They are related but distinct. ISO 27017 addresses cloud security in general; the protection of personal data specifically is the domain of ISO 27018. An organisation that handles personal data in the cloud usually needs to think about both, which is why the two standards are so often pursued together.

Bringing it together

ISO 27017 is the international standard that makes cloud security concrete. It provides cloud-specific controls and guidance for both providers and customers, clarifies the shared responsibilities that so often cause confusion, and is certified as an extension of an ISO 27001 information security management system. For any organisation that delivers or depends on cloud services, and particularly for those in IT, financial services, and healthcare, it is a clear and recognised way to demonstrate that data in the cloud is protected to an international standard.

Certiva Global provides independent ISO 27017 certification as part of ISO 27001 information security certification, operating in compliance with ISO/IEC 17021-1. To find out how it would apply to your organisation, request a no-obligation scoping discussion with our technical team.

Questions

Frequently asked questions

ISO 27017 is the international standard for cloud security. It provides cloud-specific security controls and implementation guidance for both cloud service providers and cloud service customers, building on the ISO 27002 code of practice and the foundation of an ISO 27001 information security management system.

No. ISO 27017 is not certified as a standalone standard with a separate certificate. Certification is achieved by extending the scope of an ISO 27001 audit to include the ISO 27017 cloud controls, so it is assessed alongside your information security management system.

ISO 27017 addresses cloud security in general and applies to both providers and customers. ISO 27018 focuses specifically on protecting personal data (PII) that a cloud provider handles on behalf of its customers. They are complementary and are often certified together, both as extensions of ISO 27001.

Cloud service providers, who use it to demonstrate their services are secured to a recognised standard, and cloud service customers, including IT and software companies, banking and financial services organisations, and healthcare providers, who use it to show they manage their use of the cloud responsibly.

Yes, in practice. Because ISO 27017 builds on an information security management system and is certified as an extension of an ISO 27001 audit, an organisation needs an ISO 27001 management system in place to certify its cloud controls under ISO 27017.

Beyond providing cloud guidance for existing ISO 27002 controls, ISO 27017 adds controls covering shared responsibilities between provider and customer, the removal and return of customer assets at the end of a service, the separation and hardening of virtual environments, and the monitoring of cloud services.

Ready to begin your certification journey?

Get a transparent, no-obligation scoping discussion with our technical team.