EN ISO/IEC 27017:2026 PDF
Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)
Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 43
- Дата публикации:
- 5 августа 2026 г.
- Издание:
- CEN/CENELEC EN 27017 edition 2 version 1
- ICS:
- 03.100.70
This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides: additional guidance for relevant controls specified in ISO/IEC 27002:2022; additional controls with guidance that specifically relate to cloud services. This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs). This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Abstract
Overview
EN ISO/IEC 27017:2026 is an international standard developed by CEN, focusing on information security, cybersecurity, and privacy protection in cloud services. This standard provides comprehensive guidance for cloud service customers (CSCs) and cloud service providers (CSPs) on implementing information security controls, based on the structure and recommendations of ISO/IEC 27002:2022. EN ISO/IEC 27017:2026 addresses the unique information security challenges found in cloud environments and offers cloud-specific controls in addition to those outlined in ISO/IEC 27002.
The standard is designed to establish a common understanding and set of best practices for ensuring information security in all deployment models of cloud computing, including private, public, community, and hybrid clouds. It serves as a foundational, horizontal document applicable to a wide range of organizations utilizing or offering cloud services.
Key Topics
EN ISO/IEC 27017:2026 covers an extensive array of topics pertaining to cloud information security:
- Organizational Controls: Guidance on policies, roles and responsibilities, segregation of duties, management responsibilities, and supplier relationship management in cloud contexts.
- People Controls: Recommendations on screening, employment terms, security awareness training, disciplinary processes, and confidentiality agreements for staff involved with cloud services.
- Physical Controls: Security perimeter definition, physical entry controls, securing facilities, asset protection and management, and handling storage media within a cloud infrastructure.
- Technological Controls: Best practices for authentication, access rights, configuration management, malware protection, secure software lifecycle, cryptography, logging, and monitoring in cloud environments.
- Cloud-specific Controls: Additional guidance specifically targeting cloud service models and deployments, addressing risks such as data segregation, multitenancy, and management of cloud supply chains.
- Incident Management: Cloud-focused procedures for reporting, assessing, and responding to security incidents, as well as for evidence collection and business continuity.
The standard emphasizes the importance of clear agreements between customers and providers regarding responsibilities and security measures, helping manage risks unique to cloud computing.
Applications
EN ISO/IEC 27017:2026 is highly valuable in practical scenarios involving cloud computing and information security, including:
- Cloud Service Providers (CSPs): Implementing governance and technical controls to protect customer data, assure compliance, manage incidents, and meet contractual requirements.
- Cloud Service Customers (CSCs): Assessing and managing security risks when selecting, adopting, and operating cloud solutions, including specifying required controls in service agreements.
- Regulated Industries: Ensuring legal, statutory, and regulatory compliance across sectors such as finance, healthcare, and government where protection of personally identifiable information (PII) and business-critical data in the cloud is essential.
- Internal/Private Clouds: Adapting recommended controls for private cloud environments, taking into account internal organizational relationships and delegated responsibilities.
- Supply Chain Security: Managing information security throughout the cloud supply chain, including scenarios where organizations act as both CSC and CSP, and ensuring proper flow-down of control requirements.
Organizations using EN ISO/IEC 27017:2026 demonstrate commitment to robust information security management, improved trust with clients, and alignment with international cybersecurity best practices.
Related Standards
To achieve a holistic approach to information security in cloud services, EN ISO/IEC 27017:2026 should be considered alongside these related standards:
- ISO/IEC 27002:2022 - Information security controls, serving as the baseline reference for control definitions and guidance.
- ISO/IEC 27001 - Information security management systems (ISMS) for establishing, implementing, and continually improving organizational security frameworks.
- ISO/IEC 27018 - Guidelines for the protection of personally identifiable information (PII) in cloud computing.
- ISO/IEC 27036 - Information security for supplier relationships, with Part 4 focusing on cloud services.
- ISO/IEC 22123-1:2023 - Cloud computing vocabulary, for clarity and consistency of terms.
Organizations seeking to address cloud security holistically are encouraged to integrate EN ISO/IEC 27017:2026 as part of a broader information security and compliance program, promoting alignment with internationally recognized cloud security requirements.
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 27017:2026
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
SIST EN ISO/IEC 27018:2020
ДействующийInformation technology - Security techniques - Code of practice for protection of personally identifiable inf…
Overview EN ISO/IEC 27018:2020 (ISO/IEC 27018:2019) is a code of practice for protecting personally identifiable information (PII) processed in public cloud environments where the cloud provider acts…