Skip to content

ISO 27017:2015

Safeguard your cloud services through robust information security controls

Features and Benefits

The key features of ISO 27017:2015 can be summarized as follows:

ISO/IEC 27017 is a security standard designed for cloud service providers and users to create a more secure cloud environment and minimize security risks. It is part of the ISO/IEC 27000 family, which offers best practice recommendations for information security management. This standard is based on ISO/IEC 27002, with additional cloud-specific security controls that were not fully addressed in ISO/IEC 27002.

The International Standard provides guidelines for implementing information security controls for both cloud service customers and providers. It helps define the appropriate security controls to implement, based on a risk assessment, and considers legal, contractual, regulatory, and cloud-sector-specific requirements.

 

ISO/IEC 27017 introduces 7 additional cloud-related controls, covering:

  • The division of responsibilities between cloud service providers and customers.
  • Procedures for returning or removing assets at the end of a contract.
  • Protection and separation of the customer’s virtual environment.
  • Virtual machine configuration.
  • Administrative operations and procedures within the cloud environment.
  • Monitoring cloud customer activity.
  • Alignment of virtual and cloud network environments.

Organizations offering cloud services can benefit from ISO/IEC 27017 certification, which demonstrates adherence to stringent security standards and processes for handling potential issues.

If your organization provides cloud services, your customers will seek assurances that their data, documents, messages, and activities are protected at all times, with the ability to retrieve and move data as needed. ISO/IEC 27017 certification instills confidence in these areas.

Achieving ISO/IEC 27017 certification offers several advantages

  • Reduces operational risk: By following ISO/IEC 27017 guidelines, you can effectively identify vulnerabilities and mitigate risks, including data breaches and regulatory fines.
  • Builds market trust: An independent third-party certification showcases your commitment to global information security practices, giving you a competitive edge as investors and customers recognize you as a trustworthy partner.
  • Clarifies responsibilities: ISO/IEC 27017 clearly defines the roles, rights, and responsibilities between cloud service customers and providers, helping you establish yourself as a preferred provider and expand your global reach.

Applicability

As more businesses provide cloud-based services, purchasing departments are increasingly requesting proof that data stored on cloud servers is secure. ISO/IEC 27017 provides a set of guidelines designed to protect cloud environments and reduce the risk of security incidents.

Consulting Methodology