Overview
ISO/IEC 27017:2026 is an international standard developed by ISO and IEC providing comprehensive guidance on information security controls for cloud services. Based on ISO/IEC 27002:2022, this standard addresses the unique challenges and requirements associated with cloud computing environments. It serves both cloud service customers (CSCs) and cloud service providers (CSPs), offering a unified approach to strengthen information security, cybersecurity, and privacy protection in cloud deployments.
This horizontal document applies to all cloud deployment models, including private, public, hybrid, and multi-cloud environments. It covers controls and practical guidance designed to support risk management, compliance, and the effective implementation of security measures tailored for the cloud context.
Key Topics
-
Supplemental Guidance for ISO/IEC 27002 Controls
ISO/IEC 27017:2026 adapts and extends the controls defined in ISO/IEC 27002:2022 to address technical and operational cloud-specific considerations, ensuring security requirements are effectively met for both CSCs and CSPs.
-
Cloud-Specific Controls
Additional controls are introduced to mitigate risks unique to cloud services, such as shared responsibility models, segregation in virtual environments, and detection/prevention of unauthorized cloud usage.
-
Roles and Responsibilities
The standard emphasizes the need for clear agreements and documentation of roles and responsibilities between cloud stakeholders, ensuring accountability and transparency in cloud security management.
-
Risk Management in Cloud Services
Guidance is provided for the management of information security risks, referencing ISO/IEC 27001 and ISO/IEC 27005 for risk-based approaches to the selection and application of security controls in cloud environments.
-
Supplier Relationships
Cloud service provision is addressed as a form of supplier relationship; the standard references additional guidance from the ISO/IEC 27036 series, specifically for handling the security of supply chains in cloud ecosystems.
Applications
ISO/IEC 27017:2026 is vital for organizations adopting, supplying, or managing cloud services, including:
-
Cloud Service Customers (CSCs):
- Selecting cloud providers with robust information security controls.
- Ensuring compliance with regulatory, contractual, and internal security requirements.
- Managing risks related to data storage, processing, and transfer in the cloud.
- Clarifying shared responsibilities with CSPs.
-
Cloud Service Providers (CSPs):
- Demonstrating commitment to cloud information security best practices.
- Supporting customer compliance and audit needs.
- Implementing and maintaining security controls aligned with international standards.
- Providing transparency on security capabilities in agreements and documentation.
-
Hybrid and Multi-Cloud Deployments:
- Coordinating security controls across diverse cloud models and multiple providers.
- Managing complex supplier relationships and ensuring consistent risk mitigation.
Organizations using ISO/IEC 27017:2026 can enhance their trustworthiness, facilitate global business, and foster robust cloud security postures.
Related Standards
- ISO/IEC 27001: Information security management systems - requirements, including risk management.
- ISO/IEC 27002: Baseline controls for information security, cybersecurity, and privacy protection.
- ISO/IEC 27036 Series: Guidance on information security in supplier relationships, critical for cloud ecosystems.
- ISO/IEC 27005: Comprehensive guidance for information security risk management.
- ISO/IEC 22123-1: Vocabulary for cloud computing, supporting clear communication.
- ISO/IEC 5140: Further explanation of cloud deployment models and their security implications.
ISO/IEC 27017:2026 offers practical, actionable guidance to help organizations securely adopt and manage cloud services, aligning cloud operations with global best practices for information security, privacy, and compliance.