Cloud & Certification
ISO/IEC 27017
Cloud Security Controls
Formal standard
Global
ISO/IEC JTC 1/SC 27
Since 2015
A code of practice adding cloud-specific implementation guidance to the ISO/IEC 27002 controls, plus seven controls that exist only in a cloud context: shared roles, virtual machine hardening, administrator operations, monitoring, and segregation in virtual environments.
Certification is normally an extension of a 27001 audit rather than a standalone exercise.
At a glance
- Category
- Cloud & Certification
- Jurisdiction
- Global
- Governance
- ISO/IEC JTC 1/SC 27
- Status
- ISO/IEC 27017:2015
- First released
- 2015
Links
Related frameworks
Other entries under Cloud & Certification.
- CSA CCM: Cloud Controls Matrix
- BSI C5: Cloud Computing Compliance Criteria Catalogue
- EU Cloud CoC: EU Cloud Code of Conduct
See ISO/IEC 27017 in context
Open the interactive Data Landscape for Regulation to compare ISO/IEC 27017 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.