ISO 27017: The Complete Guide to Cloud Security Controls and Certification
Why Cloud Security Demands a Dedicated Standard
Organisations worldwide are migrating critical workloads to the cloud at an unprecedented pace. Yet many assume that their existing information security controls automatically extend to cloud environments — a dangerous misconception. Cloud computing introduces unique risks: shared infrastructure, multi-tenancy, dynamic resource allocation, and complex responsibility boundaries between providers and customers.
ISO/IEC 27017:2015 addresses these gaps directly. Built as a code of practice for cloud service information security controls, it supplements ISO/IEC 27001 and ISO/IEC 27002 with 37 cloud-specific control guidelines — seven of which are entirely new and not found in the base ISO 27002 standard. Whether you are a cloud service provider (CSP) or a cloud service customer (CSC), ISO 27017 gives you a structured framework to manage cloud security risks with clarity and accountability.
What ISO 27017 Covers
ISO 27017 is structured around the same control domains as ISO 27002 but adds cloud-specific implementation guidance throughout. Its scope covers Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) deployments.
The standard addresses both sides of the cloud relationship:
- Cloud Service Providers (CSPs) — organisations that deliver cloud infrastructure, platforms, or applications to customers
- Cloud Service Customers (CSCs) — organisations that consume cloud services and retain responsibility for their own data and configurations
For each control, ISO 27017 provides separate implementation guidance for CSPs and CSCs, making it one of the few standards that explicitly maps shared responsibility in a practical, actionable way.
The Seven Cloud-Specific Controls
Beyond the extended guidance on existing ISO 27002 controls, ISO 27017 introduces seven controls unique to cloud environments:
- Shared roles and responsibilities in a cloud computing environment — Formalising who is responsible for what between provider and customer
- Removal and return of cloud service customer assets — Ensuring data and assets can be retrieved or securely deleted when a service ends
- Protection and separation of the customer's virtual environment — Isolating customer workloads from other tenants on shared infrastructure
- Virtual machine hardening — Applying security baselines to virtual instances used in cloud deployments
- Administrative operations and procedures in a cloud computing environment — Governing how administrative access is managed and monitored
- Cloud service customer monitoring of cloud services — Enabling customers to audit and monitor their own cloud usage and security events
- Alignment of security management for virtual and physical networks — Ensuring network security policies apply consistently across virtualised and physical infrastructure
These controls directly address the most common cloud security failures: unclear ownership, inadequate tenant isolation, and insufficient visibility into provider-side operations.
Key Implementation Areas
Shared Responsibility Mapping
One of the most valuable contributions of ISO 27017 is its insistence on documented shared responsibility. Organisations must define, agree, and communicate which security controls are managed by the CSP, which by the CSC, and which are jointly managed. This eliminates the ambiguity that leads to security gaps — where both parties assume the other is handling a control.
Asset Management in the Cloud
ISO 27017 requires organisations to maintain an inventory of cloud-hosted assets and define clear procedures for data return or secure deletion at contract termination. This is critical for organisations subject to data protection regulations such as GDPR, where the right to erasure must be demonstrably fulfilled even when data resides with a third-party provider.
Identity and Access Management
The standard reinforces strong access controls for cloud environments, including privileged access management for administrative accounts, multi-factor authentication, and regular access reviews. For CSPs, this extends to controlling their own staff's access to customer environments — a significant trust concern for regulated industries.
Incident Management and Logging
ISO 27017 requires that CSPs provide customers with sufficient logging and monitoring capabilities to detect and investigate security incidents within their own cloud tenancy. Customers, in turn, must establish processes to act on those logs. This bidirectional obligation closes a common gap where customers lack visibility into their own cloud security events.
Benefits of ISO 27017 Certification
Achieving ISO 27017 certification — typically assessed alongside ISO 27001 — delivers tangible advantages for both providers and customers:
- Competitive differentiation: CSPs with ISO 27017 certification can demonstrate independently verified cloud security controls to enterprise customers, accelerating procurement decisions
- Regulatory alignment: The standard supports compliance with GDPR, NIS2, and sector-specific regulations that require demonstrable cloud security governance
- Reduced audit burden: Certification provides a recognised third-party attestation that reduces the frequency and depth of customer-driven security audits
- Clearer contracts: The shared responsibility framework encourages more precise service agreements, reducing disputes and liability exposure
- Improved incident response: Formalised logging, monitoring, and notification procedures mean security incidents are detected and contained faster
ISO 27017 and the Broader Security Framework
ISO 27017 is designed to work in concert with related standards. Organisations already certified to ISO 27001 will find that ISO 27017 extends their existing Information Security Management System (ISMS) into cloud-specific territory without requiring a separate management system. ISO 27018, which addresses the protection of personally identifiable information (PII) in public clouds, is a natural companion standard — together, ISO 27017 and ISO 27018 provide comprehensive coverage of both security and privacy in cloud environments.
For organisations in financial services, healthcare, or critical infrastructure, ISO 27017 also supports alignment with frameworks such as the Cloud Security Alliance (CSA) Cloud Controls Matrix and sector-specific regulatory requirements.
Getting Started with ISO 27017
The path to ISO 27017 certification typically involves four stages: gap assessment against the standard's controls, remediation of identified weaknesses, implementation of cloud-specific policies and procedures, and third-party audit by an accredited certification body.
Organisations without an existing ISO 27001 certification should consider pursuing both standards concurrently, as the audit scope and management system requirements overlap significantly. This integrated approach reduces cost and implementation time while delivering a more robust security posture.
Conclusion
As cloud adoption deepens, the security controls that protect on-premises environments are no longer sufficient on their own. ISO 27017 provides the cloud-specific framework that organisations need to manage shared responsibility, protect customer data, and demonstrate security assurance to regulators and clients alike.
MaxStandards Certification supports organisations through every stage of ISO 27017 certification — from initial gap assessment to successful audit. Contact our team to learn how we can help you build a certified cloud security programme that meets the demands of today's threat landscape.
