On this page
- Choose the correct published document
- Guidance for both sides of the cloud relationship
- Make responsibilities visible in the quotation
- Example: moving a business application into a hosted service
- Choose the related document for the actual objective
- Frequently asked questions
- Primary sources and edition check
- Explore more standards buying guides
The checked product is ISO/IEC 27017:2026, the published second edition. Both Genorma and ISO place the 2015 text among withdrawn predecessors. Confirm that proposals and training materials use the new edition rather than silently reusing an older cloud-security checklist. Genorma edition history; ISO publication record.
Choose the correct published document
ISO/IEC 27017:2026 — Information security controls for cloud services
The link below opens the exact published catalogue product named here.
Confirm the final price, taxes, available language, delivery format and permitted users at the merchant checkout. No fixed price is quoted here.
Guidance for both sides of the cloud relationship
The scope supplies cloud-specific guidance and additional controls based on ISO/IEC 27002:2022. It addresses cloud service customers and providers, including private-cloud arrangements where internal relationships may need adaptation. Published scope.
Before buying a service or implementation package, describe the cloud model and the service you will operate. A hosted application and rented infrastructure can leave very different tasks with the customer. Ask the provider to identify the responsibilities it assumes, the activities you must perform and any third parties participating in the service.
Make responsibilities visible in the quotation
| Area | Question to ask the provider | Question for the customer |
|---|---|---|
| Access | What access mechanisms and information are supplied? | Who approves and maintains the organisation’s users and roles? |
| Configuration | Which settings and changes are managed by the provider? | Which configuration decisions remain with your team? |
| Monitoring and incidents | What information and support are available? | Who receives it and decides on follow-up? |
| Continuity and exit | What service arrangements and export options are offered? | What information and capabilities are needed to continue or leave? |
This table is a discussion aid, not a reproduction of the standard’s control list. Use it to uncover unclear handovers. If two offers promise “managed security”, ask each supplier to define the same example activity. The difference may be whether the service supplies information, makes a decision or actually performs an operational task.
Example: moving a business application into a hosted service
Imagine an organisation migrating an internal application to a hosted environment. The commercial proposal describes the provider’s infrastructure as secure, but the organisation still has to decide who can use the application and how customer information moves in and out. It also wants to understand what happens when a staff member changes role or when the service relationship ends.
The buyer could choose a sample access change and ask both teams to explain the steps, information and responsibilities. It could then do the same for an incident notification and a data export. Those questions expose gaps between assumptions without prescribing a technical architecture. The scenario is an original purchasing example, not a finding that the hosted arrangement is safe or sufficient for every requirement.
Choose the related document for the actual objective
For the requirements of an information security management system, see EN ISO/IEC 27001. For privacy management, see EN ISO/IEC 27701. For business continuity management, see EN ISO 22301. Cloud guidance can support those discussions but should not be described as the same publication or service.
ISO explains that the guidance builds on ISO/IEC 27002 and reaches public, private and hybrid deployments. Select the controls and application approach for the actual risk and service context rather than assuming every cloud relationship has the same division of responsibilities. Publisher’s application explanation.
- Record the published 2026 designation and the edition basis used by a consultant.
- Define the cloud service boundary, including external parties and internal departments.
- Ask what evidence is available to the buyer and what is available only under an agreed review arrangement.
- Separate the standard purchase from implementation, testing and continuing service charges.
- Check licences for the people evaluating both the customer and provider responsibilities.
Frequently asked questions
Is this only for cloud providers?
No. The scope expressly addresses cloud service customers and providers. Use the document from the side of the relationship you are buying or managing. Customer/provider scope.
Is the 2015 text still the new-edition purchase?
The checked records identify the 2026 replacement and withdraw the older edition. If a legacy contract needs 2015, record that reason explicitly rather than buying it as the latest publication.
Does a claim of alignment cover my whole service configuration?
Ask which activities and assumptions support the claim. A supplier-level statement and the evidence for your particular service arrangement can have different boundaries.
Primary sources and edition check
- Genorma: published ISO/IEC 27017:2026 scope and history
- ISO: second edition and cloud customer/provider guidance
Publication and purchase records checked on 7 October 2026. The examples and procurement questions are original guidance. Detailed implementation requires the applicable licensed text and decisions for the actual project.
Explore more standards buying guides
Browse standards by reference and subject to compare related document choices.
Editorial information
How this page is maintained
No documented technical review of this version is recorded. Sources and an update date are not a conformity assessment.
Scope: Cloud-security controls and guidance for customers and providers, with explicit service responsibilities and the published 2026 replacement of 2015.
View registered primary sources
Keep this guide useful
Your reading list and topic feeds
Saves stay on this browser. Feeds cover guidance on this website, not every change to a standard.