ISO 27017
ISO 27017 cloud security compliance software
Organisations using or providing cloud services that need the shared-responsibility boundary evidenced.
ISO 27017 extends the ISO 27002 controls to cloud services and adds controls specific to them. ComplyTrain holds each one as a requirement, including the ones that belong to your provider rather than to you.
ComplyTrain fully supports this standard
What ISO 27017 is
ISO/IEC 27017 is a code of practice for information security in cloud services. It does two things: it gives cloud-specific implementation guidance for controls you already know from ISO 27002, and it adds controls that only exist because the service is cloud - segregation in virtual environments, administrator operations, monitoring, and the return or removal of assets when a contract ends.
It is written for both sides. A cloud service customer and a cloud service provider read the same control and each has their own part of it, which is the point of the standard.
The shared responsibility boundary is the whole exercise
Most cloud security findings are not a control that failed. They are a control that both parties assumed the other one owned. ISO 27017 exists to make that boundary explicit, and the useful output of applying it is a documented division of responsibility you can show an auditor and hand to a customer.
It is guidance, not a certification
There is no standalone ISO 27017 certificate. It extends an ISO 27001 ISMS, and the controls you adopt from it become part of your Statement of Applicability.
The controls that only exist because it is cloud
Alongside the cloud-specific guidance on familiar controls, ISO 27017 adds a small set that has no on-premises equivalent. They cover the shared roles and responsibilities between customer and provider, the removal or return of customer assets when a service ends, the separation of customers in a shared virtual environment, hardening of virtual machines, administrator operations that could affect many customers at once, monitoring that the customer can actually see, and alignment of the virtual and physical networks.
Read as a group, they are a list of the things that go wrong specifically because a service is multi-tenant and someone else runs it. That is a useful way to approach them: not extra paperwork, but the failure modes the model introduces.
How ComplyTrain helps you apply it
- Cloud controls held as requirements alongside the rest of your ISMS, so the cloud ones are not a separate spreadsheet.
- The responsibility split recorded against each control - yours, your provider's, or shared - which is the artefact your own customers will ask for.
- Provider assurance held where it belongs: the certificates, reports and assessments you rely on, attached to the controls they actually evidence, with review dates.
- Exit and asset-return obligations tracked as requirements rather than remembered at the end of a contract.
Where a control depends on a supplier, vendor management holds the assessment, and requirements management keeps the control traceable to the evidence that satisfies it.
ComplyTrain itself runs in the EU, in AWS eu-central-1, and isolates each customer at the database, identity, storage and key level - a separate schema, a separate identity pool, a separate bucket and a separate encryption key per tenant. If you are applying ISO 27017 to your own suppliers, that is the answer to the question you will be asking us.
Questions
Can we be certified to ISO 27017?
Not on its own. ISO 27017 extends an ISO 27001 ISMS, and the cloud controls you adopt become part of your Statement of Applicability. Some certification bodies will note the extension on an ISO 27001 certificate.
What is the difference between ISO 27017 and ISO 27018?
ISO 27017 covers information security in cloud services generally. ISO 27018 covers the protection of personally identifiable information specifically, when you process it in a public cloud as a processor. Many organisations apply both, and they share the same ISMS.
Does ISO 27017 apply to us if we only consume cloud services?
Yes, and that is the more common case. The standard is written for customers as well as providers, and the customer-side controls are the ones most often assumed to belong to the provider.
Who owns a control that is shared?
Both of you, in different parts, which is why recording the split matters more than the label. The failure mode is not disagreement about a boundary, it is never having drawn one.
Our provider is certified. Does that cover us?
It covers their half. A provider certificate tells you the controls on their side of the boundary were assessed; it says nothing about the controls on yours, and those are usually the majority for a customer. The useful artefact is your own record of which is which.
How long is provider assurance good for?
Until its scope or its date stops matching what you rely on, which is sooner than most registers assume. A certificate collected once and never reviewed is evidence about a moment that has passed - which is why the review date belongs on the control, not in someone's calendar.
The process
Applying ISO 27017 to a cloud service
ISO 27017 is not certifiable on its own. It extends an ISO 27001 certificate with controls written for cloud, and it addresses the provider and the customer separately.
Decide which side you are on
The same control reads differently for a cloud service provider than for a customer of one. Most organisations are both, for different services, and the scope has to say which is which.
Apply the cloud-specific guidance
ISO 27017 adds controls that ISO 27002 does not cover, including virtual machine hardening, administrative operations and the removal of your data when a service ends.
Agree who does what
Cloud security is shared, and the split is only useful if it is written down. Record which controls your provider operates, which are yours, and what evidence each side supplies.
Evidence it across both sides
Your own controls produce their own evidence. For the provider side, keep the certificates, reports and contract terms you rely on, and review them when they expire.
