Frameworks · Global standards
ISO/IEC 27017:2015
ISO/IEC 27017:2015 gives guidelines for information security controls that apply to providing and using cloud services. It adds implementation guidance for ISO/IEC 27002 controls, plus further controls specific to cloud services. It is written for both cloud service providers and cloud service customers.
Who it applies to
It applies to cloud service providers that add cloud-specific controls to an ISO/IEC 27001 certification. It also helps cloud customers define their provider's obligations and their own responsibilities.
Main requirements
Shared responsibilities
Provider and customer define and agree their roles and responsibilities.
Cloud-specific controls
Controls cover segregation in virtual environments, virtual machine hardening, administrator operations and monitoring of cloud services.
Data
Customer assets are removed and returned when the contract ends, and the location of data is defined.
ISO/IEC 27002 guidance
The standard adds cloud implementation guidance to the existing control set.
How xmodo supports it
- 1
xmodo adds it as an extension pack to ISO/IEC 27001. Your certified ISMS is the base, and only the cloud-specific controls appear as new work.
- 2
Provider and customer responsibilities are recorded for each control. This is the first evidence a certification auditor asks for.
- 3
Requirements map to SOC 2, the DESC CSP Security Standard and BSI C5 for providers that hold several cloud attestations.
Related frameworks
ISO/IEC 27017:2015 shares requirements with the frameworks below. Controls you already run for any of them count towards ISO/IEC 27017:2015 as well.
Frequently asked questions
Can we certify to ISO/IEC 27017 on its own?
No. It is certified as an extension of ISO/IEC 27001, and xmodo sets it up the same way.