Skip to content

Independent standards discovery and compliance platform

How we work
European standard guide European standard guide

ISO/IEC 27017

ISO/IEC 27017

Choose ISO/IEC 27017 when the security question concerns the provision or use of cloud services and the division of responsibilities between the parties. The buyer needs to know who performs which activity and what evidence each side can provide. A cloud provider’s broad assurance statement may not answer the questions arising from a particular configuration or service relationship.
Editorial guide Content updated 7 October 2026
On this page
  1. Choose the correct published document
  2. Guidance for both sides of the cloud relationship
  3. Make responsibilities visible in the quotation
  4. Example: moving a business application into a hosted service
  5. Choose the related document for the actual objective
  6. Frequently asked questions
  7. Primary sources and edition check
  8. Explore more standards buying guides

The checked product is ISO/IEC 27017:2026, the published second edition. Both Genorma and ISO place the 2015 text among withdrawn predecessors. Confirm that proposals and training materials use the new edition rather than silently reusing an older cloud-security checklist. Genorma edition history; ISO publication record.

Choose the correct published document

Guidance for both sides of the cloud relationship

The scope supplies cloud-specific guidance and additional controls based on ISO/IEC 27002:2022. It addresses cloud service customers and providers, including private-cloud arrangements where internal relationships may need adaptation. Published scope.

Before buying a service or implementation package, describe the cloud model and the service you will operate. A hosted application and rented infrastructure can leave very different tasks with the customer. Ask the provider to identify the responsibilities it assumes, the activities you must perform and any third parties participating in the service.

Make responsibilities visible in the quotation

An original cloud-security procurement discussion
AreaQuestion to ask the providerQuestion for the customer
AccessWhat access mechanisms and information are supplied?Who approves and maintains the organisation’s users and roles?
ConfigurationWhich settings and changes are managed by the provider?Which configuration decisions remain with your team?
Monitoring and incidentsWhat information and support are available?Who receives it and decides on follow-up?
Continuity and exitWhat service arrangements and export options are offered?What information and capabilities are needed to continue or leave?

This table is a discussion aid, not a reproduction of the standard’s control list. Use it to uncover unclear handovers. If two offers promise “managed security”, ask each supplier to define the same example activity. The difference may be whether the service supplies information, makes a decision or actually performs an operational task.

Example: moving a business application into a hosted service

Imagine an organisation migrating an internal application to a hosted environment. The commercial proposal describes the provider’s infrastructure as secure, but the organisation still has to decide who can use the application and how customer information moves in and out. It also wants to understand what happens when a staff member changes role or when the service relationship ends.

The buyer could choose a sample access change and ask both teams to explain the steps, information and responsibilities. It could then do the same for an incident notification and a data export. Those questions expose gaps between assumptions without prescribing a technical architecture. The scenario is an original purchasing example, not a finding that the hosted arrangement is safe or sufficient for every requirement.

For the requirements of an information security management system, see EN ISO/IEC 27001. For privacy management, see EN ISO/IEC 27701. For business continuity management, see EN ISO 22301. Cloud guidance can support those discussions but should not be described as the same publication or service.

ISO explains that the guidance builds on ISO/IEC 27002 and reaches public, private and hybrid deployments. Select the controls and application approach for the actual risk and service context rather than assuming every cloud relationship has the same division of responsibilities. Publisher’s application explanation.

  • Record the published 2026 designation and the edition basis used by a consultant.
  • Define the cloud service boundary, including external parties and internal departments.
  • Ask what evidence is available to the buyer and what is available only under an agreed review arrangement.
  • Separate the standard purchase from implementation, testing and continuing service charges.
  • Check licences for the people evaluating both the customer and provider responsibilities.

Frequently asked questions

Is this only for cloud providers?

No. The scope expressly addresses cloud service customers and providers. Use the document from the side of the relationship you are buying or managing. Customer/provider scope.

Is the 2015 text still the new-edition purchase?

The checked records identify the 2026 replacement and withdraw the older edition. If a legacy contract needs 2015, record that reason explicitly rather than buying it as the latest publication.

Does a claim of alignment cover my whole service configuration?

Ask which activities and assumptions support the claim. A supplier-level statement and the evidence for your particular service arrangement can have different boundaries.

Primary sources and edition check

Publication and purchase records checked on 7 October 2026. The examples and procurement questions are original guidance. Detailed implementation requires the applicable licensed text and decisions for the actual project.

Explore more standards buying guides

Browse standards by reference and subject to compare related document choices.

From reading to action

Need help interpreting, implementing or testing against this standard?

Describe the product, organisation, target market and decision you need to make. We will direct you to the most relevant guide or specialist route available on the platform.

Describe your project