Cloud & Certification

ISO/IEC 27017

Cloud Security Controls

Formal standard Global ISO/IEC JTC 1/SC 27 Since 2015

A code of practice adding cloud-specific implementation guidance to the ISO/IEC 27002 controls, plus seven controls that exist only in a cloud context: shared roles, virtual machine hardening, administrator operations, monitoring, and segregation in virtual environments.

Certification is normally an extension of a 27001 audit rather than a standalone exercise.

At a glance

Category
Cloud & Certification
Jurisdiction
Global
Governance
ISO/IEC JTC 1/SC 27
Status
ISO/IEC 27017:2015
First released
2015

Links

Related frameworks

Other entries under Cloud & Certification.

See ISO/IEC 27017 in context

Open the interactive Data Landscape for Regulation to compare ISO/IEC 27017 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.