ISO/IEC 27017 (cloud security) updated
- Aug 19
- 1 min read
After more than a decade, the first edition of ISO/IEC 27017 and ITU-T recommendation X.1631 has been updated.
The standard advises both Cloud Service Customers and Cloud Service Providers, providing complementary security guidance side-by-side in tables.
Clauses 5 through 8 in the new second edition adopt the structure of ISO/IEC 27002:2022:
Clause 4 sets the scene with general guidance and concepts;
Clause 5 covers organizational controls for cloud services;
Clause 6 covers people controls for cloud services;
Clause 7 covers physical controls for cloud services;
Clause 8 covers technological controls for cloud services;
Annex A maps the first edition of the standard to the second;
Annex B concerns cloud service [security] monitoring.
There are 4 cloud-specific information security controls adding to the 93 in ISO/IEC 27002:
5.38 - Shared roles and reponsibilities within a cloud computing environment
5.39 - Agreement on the roles and responsibilities of the cloud service partner
8.35 - Segregation in virtual computing environments
8.36 - Detection and prevention of unauthorized use of cloud services
Read more about '27017 here on this website and get the official low-down at ISO.org

