ISO 27017 — Cloud Security Controls

ISO/IEC 27017 provides additional information-security controls specific to cloud service providers and customers, extending ISO 27001 into shared-responsibility cloud environments.

Why it matters

As organisations increasingly rely on cloud infrastructure, ISO 27017 clarifies the division of security responsibilities between cloud provider and customer, and adds controls for virtualisation, cloud admin operations and tenant isolation.

Certification is typically pursued alongside ISO 27001, extending your existing ISMS scope to cover cloud-specific risks.

Why pursue this

Benefits of ISO 27017 certification

Certification gives cloud providers and their customers a shared, auditable understanding of security responsibilities across the cloud stack.

Supporting the UN Sustainable Development Goals

9
SDG 9: Industry, Innovation and Infrastructure
16
SDG 16: Peace, Justice and Strong Institutions
8
SDG 8: Decent Work and Economic Growth
17
SDG 17: Partnerships for the Goals

Clear responsibility boundaries

Removes ambiguity over who secures what across provider and customer.

Stronger tenant isolation

Additional controls for virtualisation and multi-tenant environments.

Customer assurance

A credible, independently verified answer to cloud security due diligence.

Builds on ISO 27001

Extends your existing ISMS scope rather than starting from scratch.

"In the cloud, trust isn't assumed, it's demonstrated through clear, auditable controls."
Marcus Lindqvist, Lead Information Security Assessor, RBA Registrars

Organisations that benefit

Cloud service providers
SaaS platforms
Managed IT service providers
Data centre operators
Public sector digital services
Financial services & fintech

Key requirement areas

Shared Responsibilities
Clear provider / customer division
Virtualization Security
Tenant isolation and hardening
Admin Operations
Privileged access controls
Data Removal
Secure disposal on contract end