ISO 27017
Conditional standard · ISO/IEC 27017, Code of practice for cloud security controls
ISO/IEC
International
First published 2015
Assessed within an ISO 27001 certification scope
You provide or consume cloud services and must evidence the control split
Curated, versioned & cross-mapped
The obligation, plainly.
ISO 27017 extends the 27001 control set into cloud specifics: the shared-responsibility split between cloud provider and customer, virtual-machine hardening, tenant separation, and the cloud-only controls the base standard never contemplated.
Its core value is the explicit responsibility statement: for every control, who does what. That is the question every cloud due-diligence questionnaire circles, and the standard turns the answer into an auditable artefact.
Where programmes are tested.
The responsibility split
Provider and customer responsibilities stated per control, not assumed.
Cloud-specific controls
The CLD extensions: virtual environments, tenant separation, administrator operations.
Evidenced in the ISMS
Assessed within the 27001 scope, with the cloud estate in the Statement of Applicability.
Curated once, evidenced continuously.
- 27017's cloud controls are curated and cross-mapped to the technical control family, so a cloud-hosted institution evidences the split once for every framework that asks.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
ISO 27017, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Is ISO 27017 certifiable on its own?
No, it is a code of practice assessed as an extension of an ISO 27001 certification: the cloud controls join the Statement of Applicability and the auditor tests them within the ISMS. The certificate references the extension.
Do we need it as a cloud customer rather than a provider?
It cuts both ways: the standard defines customer-side responsibilities too, configuration, access, monitoring of the provider. For a regulated institution running on public cloud, evidencing your side of the split is exactly what supervisors now ask about.
How does it differ from ISO 27018?
27017 is cloud security generally, the responsibility split and cloud-specific controls; 27018 is specifically about protecting personal data in public clouds as a processor. Providers commonly hold both; customers rely on them and map their own duties accordingly.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.