ISO 27017: Cloud Security Controls Guide
ISO/IEC 27017 provides guidelines for information security controls applicable to the provision and use of cloud services. It extends ISO 27002 with cloud-specific implementation guidance and introduces seven additional controls unique to cloud computing.
What ISO 27017 Covers
The standard addresses security from both perspectives: cloud service providers (CSPs) and cloud service customers (CSCs). For each ISO 27002 control, ISO 27017 adds cloud-specific implementation guidance, clarifying responsibilities for each party.
Seven additional controls address cloud-specific concerns: shared roles and responsibilities, asset removal after contract termination, virtual environment segregation, virtual machine hardening, administrator operational security, cloud network monitoring, and alignment of security management across virtual and physical networks.
Who Needs ISO 27017
Cloud service providers seeking to differentiate on security should consider ISO 27017. It is particularly valuable for IaaS, PaaS, and SaaS providers that need to demonstrate cloud-specific security measures beyond what ISO 27001 alone covers.
Cloud customers in regulated industries also benefit, as ISO 27017 provides a framework for evaluating and managing cloud-related risks. Financial institutions and government agencies increasingly expect their cloud providers to hold ISO 27017 certification.
Certification Process
ISO 27017 is not a standalone certification. Organizations certify by extending their ISO 27001 scope to include ISO 27017 controls. This means you must have or be pursuing ISO 27001 certification first.
- Prerequisite — Establish an ISO 27001-certified ISMS
- Cloud risk assessment — Identify cloud-specific threats and vulnerabilities
- Control gap analysis — Map existing controls to ISO 27017 requirements
- Implement additional controls — Address the seven cloud-specific controls
- Extend audit scope — Include ISO 27017 in your next ISO 27001 audit cycle
Cost Considerations
For organizations already ISO 27001 certified, the incremental cost of adding ISO 27017 is modest. Primary expenses include additional consulting for cloud-specific gap analysis, documentation updates, and slightly expanded audit scope. Expect $15,000 to $30,000 in incremental costs for a mid-size cloud provider.
The Seven Cloud-Specific Controls Explained
ISO 27017 introduces seven controls not present in ISO 27002 that address the unique risk surface of cloud computing environments.
Shared roles and responsibilities in a cloud computing environment — Arguably the most important addition. Both CSP and CSC must clearly document their respective security responsibilities for each cloud service. Ambiguity here is a common source of security failures and audit findings.
Removal and return of cloud service customer assets — Defines procedures for returning or securely deleting customer assets (data, configurations, credentials) when a cloud service agreement ends. Cloud customers need assurance their data is not retained after offboarding.
Protection and separation of the customer's virtual environment — CSPs must demonstrate that virtualization infrastructure prevents one customer's workloads from accessing another's data. Segregation controls, hypervisor hardening, and network isolation all apply here.
Virtual machine hardening — Establishes requirements for securing VM images and containers, preventing the deployment of unnecessarily privileged or unpatched virtual instances.
Administrator operations security in cloud computing — Addresses how CSP administrators access and operate customer environments, including logging, separation of duties, and restrictions on privileged access to customer data.
Monitoring of cloud services — Both CSPs and CSCs must implement monitoring appropriate to the services and data involved. Shared responsibility means shared visibility requirements.
Alignment of security management for virtual and physical networks — Security requirements that apply to physical network infrastructure must extend consistently to virtual networks and software-defined networking.
Who Should Pursue ISO 27017
SaaS providers selling to regulated industries (financial services, healthcare, government) find ISO 27017 certification valuable because customers increasingly require cloud-specific security assurance beyond what ISO 27001 alone provides.
IaaS and PaaS providers — Any company offering cloud infrastructure services faces customer due diligence that probes cloud security specifically. ISO 27017 provides a structured, audited answer to those questions.
Enterprises with significant cloud footprints — Large organizations that rely heavily on third-party cloud providers use ISO 27017 as the evaluation framework for their cloud supplier reviews, even if they are not themselves seeking certification.
Costs and Timeline
| Component | Low Estimate | High Estimate |
|---|---|---|
| Cloud-specific gap analysis | $5,000 | $15,000 |
| Policy and documentation updates | $3,000 | $10,000 |
| Expanded certification audit scope | $5,000 | $20,000 |
| Compliance automation (incremental) | $0 | $5,000 |
| Total incremental cost (from ISO 27001) | $15,000 | $50,000 |
Timeline: 2 to 6 months for organizations with an active ISO 27001 ISMS.
How ISO 27017 Relates to Other Cloud Frameworks
ISO 27017 vs. ISO 27018 — ISO 27017 focuses on cloud security controls for both providers and customers. ISO 27018 focuses specifically on privacy protection for PII in public clouds. The two are complementary and frequently pursued together.
ISO 27017 vs. CSA STAR — CSA STAR uses the Cloud Controls Matrix (CCM), which overlaps approximately 60% with ISO 27017. Organizations with CSA STAR certification can leverage that work toward ISO 27017, though the ISO framework is more widely demanded in enterprise procurement.
ISO 27017 vs. FedRAMP — FedRAMP is the U.S. government's cloud authorization framework based on NIST 800-53. ISO 27017 and FedRAMP are parallel rather than sequential — you would pursue FedRAMP for U.S. federal contracts and ISO 27017 for international enterprise credibility.
How Automation Helps
Cloud-specific evidence collection is exactly where automation earns its keep. Collecting and maintaining evidence for virtual network configurations, access logs for privileged CSP administrators, and VM image hardening states is impractical manually at any scale.
LowerPlane integrates with AWS, Azure, and GCP to automate collection of cloud configuration evidence mapped to ISO 27017 controls. As part of its 50-plus framework library, it allows organizations already pursuing ISO 27001 to extend their evidence program to ISO 27017 without duplicating work. Starts at $4,000/year with a free tier; rated 9.4/10 by AuditXYZ. See Best Compliance Automation Platforms.
Frequently Asked Questions
Can I get ISO 27017 certified without ISO 27001? No. ISO 27017 is certified as an extension to ISO 27001. You must hold or be pursuing ISO 27001 certification before your certification body can assess ISO 27017 compliance.
Do cloud customers need ISO 27017 certification, or only providers? The standard addresses both roles. Providers are more commonly the ones seeking certification, but cloud-heavy enterprises sometimes pursue ISO 27017 as a framework for structuring their cloud security governance, even without formal certification.
How does ISO 27017 handle multi-cloud environments? The standard's principles apply regardless of the number of cloud providers. Multi-cloud environments add complexity to the shared responsibility mapping requirement — you need a documented security responsibilities matrix for each provider.
Is ISO 27017 required for GDPR compliance? No, but it helps. ISO 27017 addresses cloud security controls that support several GDPR processor obligations, particularly around data segregation, sub-processor management, and secure deletion. Combining ISO 27017 with ISO 27018 provides a more complete privacy-plus-security posture for GDPR purposes.