ISO/IEC 27017
ISO/IEC 27017:2026 / ITU-T X.1631 — Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
[second edition]
Abstract
"ISO/IEC 27017 provides guidance for implementing information security controls in cloud services. It builds on ISO/IEC 27002 by adding cloud-specific guidance and additional controls for both cloud service customers and cloud service providers.
The standard helps organizations address security risks that arise from the shared nature of cloud computing. It clarifies how information security controls can be applied across customer and provider environments, including situations where responsibilities, infrastructure and operational activities are divided between multiple parties.
ISO/IEC 27017 applies to all cloud deployment models, including public, private and hybrid cloud environments. Its controls should be selected and applied according to the organization’s risk assessment and any relevant legal, regulatory, contractual or cloud-specific security requirements.”
[Source: ISO/IEC 27017:2026]
Introduction
This standard provides guidance on the information security aspects of cloud computing to assist with the implementation of cloud-specific information security controls.
Scope
The standard provides additional information security controls implementation advice, supplementing the guidance in ISO/IEC 27002 and other ISO27k standards in the context of cloud computing services.
Structure
The standard advises both Cloud Service Customers and Cloud Service Providers, the complementary security guidance for each audience being laid out side-by-side in clauses 5 to 8 mirroring the structure of ISO/IEC 27002:
Clause 4 sets the scene with general guidance and concepts;
Clause 5 covers organizational controls for cloud services [controls such as policy that don't fit neatly into the people, physical or technological domains];
Clause 6 covers people controls for cloud services;
Clause 7 covers physical controls for cloud services;
Clause 8 covers technological controls for cloud services;
Annex A maps the first edition of the standard to the second;
Annex B concerns cloud service [security] monitoring.
There are 4 cloud-specific information security controls adding to the 93 in ISO/IEC 27002:
5.38 - Shared roles and reponsibilities within a cloud computing environment [managing the security aspects as part of commercial relationship management]
5.39 - Agreement on the roles and responsibilities of the cloud service partner [meaning both 'sides'!]
8.35 - Segregation in virtual computing environments [keeping tenants isolated from each other and protecting the CSP's platform and internal services from tenants]
8.36 - Detection and prevention of unauthorized use of cloud services [primarily a CSC concern]
Status
The first edition was published in 2015. Having been developed jointly by ISO/IEC and ITU-T, the standard was dual-numbered ISO/IEC 27017 and ITU-T X.1631 with identical content.
Work on a second edition started in 2022 as a collaboration between ISO/IEC SC 27 and SC 38, ITU-T SG17 and the Cloud Security Alliance, reconsidering and reorganising the controls as per ISO/IEC 27002:2022.
The second edition was published in August 2026, more than a decade after the first.
Commentary
In my opinion, ISO/IEC 27017 still takes an unrealistically simplistic view of cloud service provider and customer relationships as individual one-to-one interactions. In reality, cloud services are often provided by multiple suppliers to multiple clients in different organisations, and nothing remains static for long. In practice, inter-organisational business relationships often extend through complex cloud supply chains or supply networks, with multiple parties involved in collaborating to assemble, deliver and manage cloud services (e.g. network, data centre, physical servers, virtual servers, operating systems, database management systems and other layered software, applications, and all the associated services). Consequently, there are numerous supplier-customer relationship risks to manage, such as organisational interdependence, contracting and subcontracting, complexity, dynamics and compliance. There are risk visibility and trust issues, resourcing challenges, commercial angles, technological challenges and more to contend with. Cloud-related information risks are, well, cloudy!
Risk treatments for cloud and other information risks may include risk sharing, avoidance and acceptance - not just risk mitigation using security controls. Neither this standard nor ISO/IEC 27002 pay much attention to risk treatments other than mitigation using security controls - a persistent systematic bias throughout ISO27k.
Particularly for small or immature organisations, cloud services providing email, file storage and office apps etc. may be treated as mere commodities, procured without adequate consideration of information risk, security, privacy etc. However, some cloud services may be critical for core business, and cloud generally increases the organisation’s attack surface and vulnerabilities. [This issue may be more relevant to ISO/IEC 27005 and ISO/IEC 27036.]
Cloud services proved their value for resilience and flexible working through COVID. There are general principles and lessons here that can help organisations be better prepared to cope with future widespread/global challenges such as further pandemics, wars, Internet connectivity issues etc. The challenge is to draw them out, considering and embedding them where appropriate.
ISO does not intend to develop a formal requirements specification standard against which to certify the security of Cloud Service Providers specifically. CSPs can, however, be certified against ISO/IEC 27001, ISO/IEC 27701 and other standards in the usual way, while there are non-ISO cloud security assessment and certification, classification, benchmarking or assurance schemes such as CSA STAR.
