What ISO 27017 covers
ISO/IEC 27017 provides cloud-specific information security controls and implementation guidance, based on ISO/IEC 27002. It extends ISO 27001 and ISO 27002 with guidance tailored to the cloud — addressing the shared responsibilities between a cloud service provider and its customers, and the security issues that are unique to cloud computing.
It is relevant both to cloud service providers and to organisations that consume cloud services and want to manage the associated risks to a recognised standard.
The 2026 edition
The current edition is ISO/IEC 27017:2026 — Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services. Published in July 2026, it replaces the 2015 edition, which ISO has withdrawn. The new edition follows the structure of ISO/IEC 27002:2022 — organisational, people, physical and technological controls — with cloud-specific guidance and controls added. If your cloud controls were designed against the 2015 edition, we help you review them against the new structure.
What implementation involves
ISO/IEC 27017 provides cloud-specific information security control guidance for cloud service customers and providers. It is generally implemented alongside ISO/IEC 27001 and is not an independent management-system certification standard. ABS assists organisations in identifying applicable cloud-security controls, allocating responsibilities between cloud customers and providers, updating risk assessments and integrating the controls into the ISMS, typically including:
- Shared roles and responsibilities between cloud provider and customer
- Removal and return of assets when a cloud contract ends
- Segregation and protection in virtualised and shared environments
- Administrator and operational security for cloud services
It sits within the IT-security part of the ISO Certifications portfolio and is frequently pursued alongside ISO 27018 for PII in public clouds.
Timeline & process
For an organisation that already holds ISO 27001, adding ISO 27017 typically takes around 10–14 weeks, depending on the scope and size of the cloud services covered; implementing both together takes longer. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.
Common questions
Do we need ISO 27001 before ISO 27017?
Not to use it. ISO/IEC 27017 is guidance, so any cloud provider or cloud customer can apply it. If you want your cloud controls independently assessed, yes: ISO 27017 is not certified on its own, so the controls are assessed within an ISO 27001 certification scope. That is why most organisations implement the two together.
What is the difference between ISO 27017 and ISO 27018?
Both extend ISO 27001 for the cloud. ISO 27017 covers cloud security controls generally; ISO 27018 focuses specifically on protecting personally identifiable information (PII) in public clouds. Cloud providers often pursue both.