Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
ISO 27017
ISO/IEC 27017 providing security controls and guidance for cloud services.
ISO/IEC 27017 is an international standard published jointly by ISO and IEC that provides information security controls and implementation guidance for cloud services. Building on ISO/IEC 27002, it offers cloud-specific guidance for both cloud service providers and cloud service customers, adding a set of controls that address the shared and distinctive risks of cloud computing such as separation of tenants, virtual environments and the allocation of responsibilities between provider and customer.
ISO/IEC 27017 is a code of practice rather than a certifiable management-system standard, so it is not independently certifiable; organisations typically demonstrate its adoption within an ISO/IEC 27001 certification. The current edition is ISO/IEC 27017:2015.
Define and document the division of security responsibilities between cloud service providers and cloud service customers.
Apply additional cloud guidance covering areas such as virtual machine hardening, administrator operations and segregation in shared environments.
Follow the role-specific implementation guidance provided for both providers and customers of cloud services.
Integrate the cloud controls with the broader information security controls of ISO/IEC 27002 and 27001.
Read more
Anove scans your stack against ISO 27017 and 260+ other frameworks in minutes.