ISO 27017: cloud security controls, checked in the cloud itself
Add the cloud-specific controls of ISO/IEC 27017 to your ISO 27001 ISMS, with the shared-responsibility split written down and the technical controls checked automatically in your AWS and Azure accounts.
What is ISO 27017?
ISO/IEC 27017 is the international code of practice for information security controls for cloud services. It takes the controls of ISO/IEC 27002 and adds, for each relevant one, implementation guidance written separately for cloud service providers and for cloud service customers, because responsibility for a control is often split between the two. It then adds cloud-specific controls that ISO 27002 does not have: a documented division of shared roles and responsibilities, the removal and return of a customer's assets when a service ends, segregation between tenants in virtual computing environments, hardening of virtual machines, operational security for administrators, monitoring of cloud services by the customer, and the alignment of security management for virtual and physical networks. ISO 27017 is not a management system standard and is not certified on its own; it is audited as an extension of ISO 27001, with the cloud controls added to the Statement of Applicability, and the certificate records the extension. Providers use it to show how the cloud is secured; customers use it to evidence their side of the shared responsibility.
ISO/IEC 27017 is the international code of practice for information security controls for cloud services, based on ISO/IEC 27002. It gives cloud-specific implementation guidance for the ISO 27002 controls and adds controls of its own for both cloud service providers and cloud customers, covering shared roles and responsibilities, removal of customer assets, segregation in virtual environments, virtual machine hardening, administrator operations, monitoring and the alignment of virtual and physical network security. It is certified as an extension of an ISO 27001 certificate.
SaaS and cloud service providers whose customers ask how the cloud is secured, and cloud customers in regulated sectors who need to evidence their side of the shared responsibility.
How Viglyn runs ISO 27017
- The cloud-specific controls added to your ISO 27001 Statement of Applicability, with the provider and customer responsibilities for each written down as evidence
- Technical controls checked automatically in AWS and Azure: identity and privileged access, network segregation, virtual machine configuration, logging and monitoring, key management and data removal
- The shared-responsibility matrix for each cloud provider you use held as a controlled document, and the providers themselves assessed in the vendor module
- Evidence shared with ISO 27001, SOC 2 and CSA STAR, so the cloud controls are evidenced once
- The extension audited alongside your ISO 27001 Stage 1 and Stage 2 inside Viglyn, with scoped auditor access
The ISO 27017 questions that decide it
Can we get ISO 27017 without ISO 27001?
No. ISO 27017 is a code of practice, not a management system standard, so it is certified as an extension of an ISO 27001 certificate. If you do not hold ISO 27001 yet, Viglyn runs both from one evidence base and the cloud controls join the Statement of Applicability from the start.
How long does ISO 27017 take?
Weeks on top of an existing ISO 27001 system, because most of the cloud controls are technical and can be checked in your cloud accounts as soon as they are connected. Writing the shared-responsibility split is the part that needs judgement; our practitioners do it with you.
How much does ISO 27017 cost with Viglyn?
ISO 27017 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee for the extended audit is separate and paid by you directly; we take no commission.
More ISO 27017 questions
What is the difference between ISO 27017 and ISO 27018?
Does ISO 27017 replace a SOC 2 report?
What does the shared responsibility model have to do with it?
See ISO 27017 run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
