Overview
EN ISO/IEC 27017:2021 (identical to ISO/IEC 27017:2015 / ITU‑T X.1631) is a code of practice for cloud security that provides guidelines for information security controls specific to cloud services. Built on ISO/IEC 27002, this standard adds cloud‑sector implementation guidance and cloud‑specific controls. It addresses both cloud service providers (CSPs) and cloud service customers, clarifying responsibilities and practical measures for secure cloud operation and use.
Key topics
The standard supplements ISO/IEC 27002 with cloud‑focused guidance across typical information security domains, including:
- Information security policies - management direction and cloud policy considerations.
- Organization of information security - roles, supplier relationships and governance for cloud ecosystems.
- Human resource security - hiring, ongoing duties and termination in cloud contexts.
- Asset management - classification and handling of cloud data and media.
- Access control - tenant isolation, privileged access, user lifecycle and remote access for cloud platforms.
- Cryptography - guidance on protecting data in transit and at rest within cloud deployments.
- Risk management for cloud services - assessing shared responsibility, third‑party suppliers and service models.
- Operational controls and supplier relationships - SLAs, monitoring, logging, incident response and subcontractor management.
These topics reflect the document’s table of contents and emphasize implementation guidance rather than prescriptive requirements.
Applications
EN ISO/IEC 27017 is used to:
- Design and validate cloud security architectures (IaaS, PaaS, SaaS).
- Inform security clauses in contracts and SLAs between cloud customers and providers.
- Guide vendor risk assessments and due diligence for cloud suppliers.
- Align cloud operations with information security management systems (ISMS) and compliance programs.
- Shape operational controls such as access provisioning, logging, encryption and incident handling for cloud services.
Practical benefits include clearer shared‑responsibility definitions, improved supplier governance, and consistent implementation of cloud controls aligned with ISO best practice.
Who should use it
- Cloud service providers and platform operators
- Cloud service customers and enterprise IT/security teams
- Security architects, compliance officers and auditors
- Procurement and legal teams drafting cloud contracts
Related standards
- ISO/IEC 27002 - controls and guidance on which 27017 builds.
- ISO/IEC 27001 - for establishing an ISMS aligning with controls.
- ITU‑T X.1631 - identical Recommendation to ISO/IEC 27017.
Adopting EN ISO/IEC 27017 supports cohesive cloud security practices and helps organizations demonstrate alignment with international cloud computing security guidance.