ISO/IEC 27017:2015 PDF
Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services
Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 30
- Дата публикации:
- 30 ноября 2015 г.
- Издание:
- ISO/IEC IS 27017 edition 1 version 1
- ICS:
- 03.100.70
ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing: - additional implementation guidance for relevant controls specified in ISO/IEC 27002; - additional controls with implementation guidance that specifically relate to cloud services. This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers.
Abstract
Overview
ISO/IEC 27017:2015 - “Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services” - is an international code of practice that adapts and extends ISO/IEC 27002 guidance specifically for cloud security. Published as a joint ISO/IEC standard (also issued as ITU‑T X.1631), it provides additional implementation guidance and cloud-specific controls to help both cloud service providers and cloud service customers manage information security in cloud environments.
Key topics
ISO/IEC 27017 aligns with the structure of ISO/IEC 27002 while emphasizing cloud-sector concerns. Major subject areas covered include:
- Governance and policies: management direction for cloud security and the structure of responsibilities.
- Supplier and customer relationships: guidance on contracts, service delivery management and shared responsibilities between providers and customers.
- Access control: cloud-appropriate user access management, system and application access measures.
- Operations and monitoring: operational procedures, logging and monitoring tailored for multi-tenant/cloud architectures.
- Cryptography: selection and use of cryptographic controls in cloud services.
- Incident management and continuity: cloud-focused incident response, business continuity and redundancies.
- Compliance and audits: meeting legal, contractual and regulatory requirements related to cloud-hosted data and services.
- Extended cloud control set: Annex A provides additional cloud-specific controls and implementation guidance.
Practical applications
ISO/IEC 27017 is designed to be pragmatic and actionable for organizations involved in cloud computing:
- Cloud service providers (CSPs) - implement provider-side controls, demonstrate secure service design, and support customer control objectives.
- Cloud service customers - assess provider offerings, negotiate security clauses, and apply controls where responsibility remains with the customer.
- Procurement and legal teams - use the standard to define contractual security requirements and SLAs.
- Security architects and engineers - map cloud-specific risks to controls for secure configuration, monitoring and encryption.
- Auditors and compliance officers - evaluate cloud controls against a recognized international code of practice.
Benefits include clearer allocation of shared responsibilities, improved supplier risk management, and better alignment with existing ISO security programs.
Related standards
- ISO/IEC 27002 - baseline code of practice for information security controls (ISO/IEC 27017 extends this for cloud services).
- ISO/IEC 27001 - information security management system (ISMS) requirements; ISO/IEC 27017 supports ISMS control implementation for cloud contexts.
- ITU‑T X.1631 - identical text published by ITU (cloud computing security design).
Keywords: ISO/IEC 27017, cloud security, information security controls, cloud service providers, cloud service customers, ISO/IEC 27002.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27017:2015
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…