Overview
ISO/IEC 27017:2015 - “Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services” - is an international code of practice that adapts and extends ISO/IEC 27002 guidance specifically for cloud security. Published as a joint ISO/IEC standard (also issued as ITU‑T X.1631), it provides additional implementation guidance and cloud-specific controls to help both cloud service providers and cloud service customers manage information security in cloud environments.
Key topics
ISO/IEC 27017 aligns with the structure of ISO/IEC 27002 while emphasizing cloud-sector concerns. Major subject areas covered include:
- Governance and policies: management direction for cloud security and the structure of responsibilities.
- Supplier and customer relationships: guidance on contracts, service delivery management and shared responsibilities between providers and customers.
- Access control: cloud-appropriate user access management, system and application access measures.
- Operations and monitoring: operational procedures, logging and monitoring tailored for multi-tenant/cloud architectures.
- Cryptography: selection and use of cryptographic controls in cloud services.
- Incident management and continuity: cloud-focused incident response, business continuity and redundancies.
- Compliance and audits: meeting legal, contractual and regulatory requirements related to cloud-hosted data and services.
- Extended cloud control set: Annex A provides additional cloud-specific controls and implementation guidance.
Practical applications
ISO/IEC 27017 is designed to be pragmatic and actionable for organizations involved in cloud computing:
- Cloud service providers (CSPs) - implement provider-side controls, demonstrate secure service design, and support customer control objectives.
- Cloud service customers - assess provider offerings, negotiate security clauses, and apply controls where responsibility remains with the customer.
- Procurement and legal teams - use the standard to define contractual security requirements and SLAs.
- Security architects and engineers - map cloud-specific risks to controls for secure configuration, monitoring and encryption.
- Auditors and compliance officers - evaluate cloud controls against a recognized international code of practice.
Benefits include clearer allocation of shared responsibilities, improved supplier risk management, and better alignment with existing ISO security programs.
Related standards
- ISO/IEC 27002 - baseline code of practice for information security controls (ISO/IEC 27017 extends this for cloud services).
- ISO/IEC 27001 - information security management system (ISMS) requirements; ISO/IEC 27017 supports ISMS control implementation for cloud contexts.
- ITU‑T X.1631 - identical text published by ITU (cloud computing security design).
Keywords: ISO/IEC 27017, cloud security, information security controls, cloud service providers, cloud service customers, ISO/IEC 27002.