top of page

ISO/IEC 27017 (cloud security) updated

  • Aug 19
  • 1 min read

After more than a decade, the first edition of ISO/IEC 27017 and ITU-T recommendation X.1631 has been updated.


The standard advises both Cloud Service Customers and Cloud Service Providers, providing complementary security guidance side-by-side in tables.

Clauses 5 through 8 in the new second edition adopt the structure of ISO/IEC 27002:2022:

  • Clause 4 sets the scene with general guidance and concepts;

  • Clause 5 covers organizational controls for cloud services;

  • Clause 6 covers people controls for cloud services;

  • Clause 7 covers physical controls for cloud services;

  • Clause 8 covers technological controls for cloud services;

  • Annex A maps the first edition of the standard to the second;

  • Annex B concerns cloud service [security] monitoring.


There are 4 cloud-specific information security controls adding to the 93 in ISO/IEC 27002:

  • 5.38 - Shared roles and reponsibilities within a cloud computing environment

  • 5.39 - Agreement on the roles and responsibilities of the cloud service partner

  • 8.35 - Segregation in virtual computing environments

  • 8.36 - Detection and prevention of unauthorized use of cloud services


Read more about '27017 here on this website and get the official low-down at ISO.org

 
 

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page