Overview
EN ISO/IEC 27017:2026 is an international standard developed by CEN, focusing on information security, cybersecurity, and privacy protection in cloud services. This standard provides comprehensive guidance for cloud service customers (CSCs) and cloud service providers (CSPs) on implementing information security controls, based on the structure and recommendations of ISO/IEC 27002:2022. EN ISO/IEC 27017:2026 addresses the unique information security challenges found in cloud environments and offers cloud-specific controls in addition to those outlined in ISO/IEC 27002.
The standard is designed to establish a common understanding and set of best practices for ensuring information security in all deployment models of cloud computing, including private, public, community, and hybrid clouds. It serves as a foundational, horizontal document applicable to a wide range of organizations utilizing or offering cloud services.
Key Topics
EN ISO/IEC 27017:2026 covers an extensive array of topics pertaining to cloud information security:
- Organizational Controls: Guidance on policies, roles and responsibilities, segregation of duties, management responsibilities, and supplier relationship management in cloud contexts.
- People Controls: Recommendations on screening, employment terms, security awareness training, disciplinary processes, and confidentiality agreements for staff involved with cloud services.
- Physical Controls: Security perimeter definition, physical entry controls, securing facilities, asset protection and management, and handling storage media within a cloud infrastructure.
- Technological Controls: Best practices for authentication, access rights, configuration management, malware protection, secure software lifecycle, cryptography, logging, and monitoring in cloud environments.
- Cloud-specific Controls: Additional guidance specifically targeting cloud service models and deployments, addressing risks such as data segregation, multitenancy, and management of cloud supply chains.
- Incident Management: Cloud-focused procedures for reporting, assessing, and responding to security incidents, as well as for evidence collection and business continuity.
The standard emphasizes the importance of clear agreements between customers and providers regarding responsibilities and security measures, helping manage risks unique to cloud computing.
Applications
EN ISO/IEC 27017:2026 is highly valuable in practical scenarios involving cloud computing and information security, including:
- Cloud Service Providers (CSPs): Implementing governance and technical controls to protect customer data, assure compliance, manage incidents, and meet contractual requirements.
- Cloud Service Customers (CSCs): Assessing and managing security risks when selecting, adopting, and operating cloud solutions, including specifying required controls in service agreements.
- Regulated Industries: Ensuring legal, statutory, and regulatory compliance across sectors such as finance, healthcare, and government where protection of personally identifiable information (PII) and business-critical data in the cloud is essential.
- Internal/Private Clouds: Adapting recommended controls for private cloud environments, taking into account internal organizational relationships and delegated responsibilities.
- Supply Chain Security: Managing information security throughout the cloud supply chain, including scenarios where organizations act as both CSC and CSP, and ensuring proper flow-down of control requirements.
Organizations using EN ISO/IEC 27017:2026 demonstrate commitment to robust information security management, improved trust with clients, and alignment with international cybersecurity best practices.
Related Standards
To achieve a holistic approach to information security in cloud services, EN ISO/IEC 27017:2026 should be considered alongside these related standards:
- ISO/IEC 27002:2022 - Information security controls, serving as the baseline reference for control definitions and guidance.
- ISO/IEC 27001 - Information security management systems (ISMS) for establishing, implementing, and continually improving organizational security frameworks.
- ISO/IEC 27018 - Guidelines for the protection of personally identifiable information (PII) in cloud computing.
- ISO/IEC 27036 - Information security for supplier relationships, with Part 4 focusing on cloud services.
- ISO/IEC 22123-1:2023 - Cloud computing vocabulary, for clarity and consistency of terms.
Organizations seeking to address cloud security holistically are encouraged to integrate EN ISO/IEC 27017:2026 as part of a broader information security and compliance program, promoting alignment with internationally recognized cloud security requirements.