ISO/IEC 27017:2026 PDF
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 39
- Дата публикации:
- 27 июля 2026 г.
- Издание:
- ISO/IEC IS 27017 edition 2 version 1
- ICS:
- 03.100.70
This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides: additional guidance for relevant controls specified in ISO/IEC 27002:2022; additional controls with guidance that specifically relate to cloud services. This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs). This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Abstract
Overview
ISO/IEC 27017:2026 is an international standard developed by ISO and IEC providing comprehensive guidance on information security controls for cloud services. Based on ISO/IEC 27002:2022, this standard addresses the unique challenges and requirements associated with cloud computing environments. It serves both cloud service customers (CSCs) and cloud service providers (CSPs), offering a unified approach to strengthen information security, cybersecurity, and privacy protection in cloud deployments.
This horizontal document applies to all cloud deployment models, including private, public, hybrid, and multi-cloud environments. It covers controls and practical guidance designed to support risk management, compliance, and the effective implementation of security measures tailored for the cloud context.
Key Topics
-
Supplemental Guidance for ISO/IEC 27002 Controls ISO/IEC 27017:2026 adapts and extends the controls defined in ISO/IEC 27002:2022 to address technical and operational cloud-specific considerations, ensuring security requirements are effectively met for both CSCs and CSPs.
-
Cloud-Specific Controls Additional controls are introduced to mitigate risks unique to cloud services, such as shared responsibility models, segregation in virtual environments, and detection/prevention of unauthorized cloud usage.
-
Roles and Responsibilities The standard emphasizes the need for clear agreements and documentation of roles and responsibilities between cloud stakeholders, ensuring accountability and transparency in cloud security management.
-
Risk Management in Cloud Services Guidance is provided for the management of information security risks, referencing ISO/IEC 27001 and ISO/IEC 27005 for risk-based approaches to the selection and application of security controls in cloud environments.
-
Supplier Relationships Cloud service provision is addressed as a form of supplier relationship; the standard references additional guidance from the ISO/IEC 27036 series, specifically for handling the security of supply chains in cloud ecosystems.
Applications
ISO/IEC 27017:2026 is vital for organizations adopting, supplying, or managing cloud services, including:
-
Cloud Service Customers (CSCs):
- Selecting cloud providers with robust information security controls.
- Ensuring compliance with regulatory, contractual, and internal security requirements.
- Managing risks related to data storage, processing, and transfer in the cloud.
- Clarifying shared responsibilities with CSPs.
-
Cloud Service Providers (CSPs):
- Demonstrating commitment to cloud information security best practices.
- Supporting customer compliance and audit needs.
- Implementing and maintaining security controls aligned with international standards.
- Providing transparency on security capabilities in agreements and documentation.
-
Hybrid and Multi-Cloud Deployments:
- Coordinating security controls across diverse cloud models and multiple providers.
- Managing complex supplier relationships and ensuring consistent risk mitigation.
Organizations using ISO/IEC 27017:2026 can enhance their trustworthiness, facilitate global business, and foster robust cloud security postures.
Related Standards
- ISO/IEC 27001: Information security management systems - requirements, including risk management.
- ISO/IEC 27002: Baseline controls for information security, cybersecurity, and privacy protection.
- ISO/IEC 27036 Series: Guidance on information security in supplier relationships, critical for cloud ecosystems.
- ISO/IEC 27005: Comprehensive guidance for information security risk management.
- ISO/IEC 22123-1: Vocabulary for cloud computing, supporting clear communication.
- ISO/IEC 5140: Further explanation of cloud deployment models and their security implications.
ISO/IEC 27017:2026 offers practical, actionable guidance to help organizations securely adopt and manage cloud services, aligning cloud operations with global best practices for information security, privacy, and compliance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27017:2026
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
SIST EN ISO/IEC 27005:2024
ДействующийInformation security, cybersecurity and privacy protection - Guidance on managing information security risks…
Overview SIST EN ISO/IEC 27005:2024 (adoption of ISO/IEC 27005:2022 as EN ISO/IEC 27005:2024) provides detailed guidance on managing information security risks to support implementation of an Informa…
BS ISO/IEC 27036-4:2016
ДействующийInformation technology. Security techniques. Information security for supplier relationships. Guidelines for…
SIST EN ISO 22123-1:2026
ДействующийInformation technology - Cloud computing - Part 1: Vocabulary (ISO/IEC 22123-1:2023)
Overview SIST EN ISO 22123-1:2026, titled Information technology - Cloud computing - Part 1: Vocabulary, is a European standard developed by CEN that defines terminology used in cloud computing. This…
BS ISO/IEC 5140:2024
ДействующийInformation technology. Cloud computing. Concepts for multi-cloud and the use of multiple cloud services
1 Scope This document specifies foundational concepts for multiple cloud services including multi-cloud, hybrid cloud, inter-cloud and federated cloud.