ISO 27017 — Cloud Security Controls
ISO/IEC 27017 provides additional information-security controls specific to cloud service providers and customers, extending ISO 27001 into shared-responsibility cloud environments.
Why it matters
As organisations increasingly rely on cloud infrastructure, ISO 27017 clarifies the division of security responsibilities between cloud provider and customer, and adds controls for virtualisation, cloud admin operations and tenant isolation.
Certification is typically pursued alongside ISO 27001, extending your existing ISMS scope to cover cloud-specific risks.

Supporting the UN Sustainable Development Goals
Clear responsibility boundaries
Removes ambiguity over who secures what across provider and customer.
Stronger tenant isolation
Additional controls for virtualisation and multi-tenant environments.
Customer assurance
A credible, independently verified answer to cloud security due diligence.
Builds on ISO 27001
Extends your existing ISMS scope rather than starting from scratch.
Organisations that benefit





