Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
ISO 27017

ISO 27017: cloud security controls, checked in the cloud itself

Add the cloud-specific controls of ISO/IEC 27017 to your ISO 27001 ISMS, with the shared-responsibility split written down and the technical controls checked automatically in your AWS and Azure accounts.

What is ISO 27017?

ISO/IEC 27017 is the international code of practice for information security controls for cloud services. It takes the controls of ISO/IEC 27002 and adds, for each relevant one, implementation guidance written separately for cloud service providers and for cloud service customers, because responsibility for a control is often split between the two. It then adds cloud-specific controls that ISO 27002 does not have: a documented division of shared roles and responsibilities, the removal and return of a customer's assets when a service ends, segregation between tenants in virtual computing environments, hardening of virtual machines, operational security for administrators, monitoring of cloud services by the customer, and the alignment of security management for virtual and physical networks. ISO 27017 is not a management system standard and is not certified on its own; it is audited as an extension of ISO 27001, with the cloud controls added to the Statement of Applicability, and the certificate records the extension. Providers use it to show how the cloud is secured; customers use it to evidence their side of the shared responsibility.

In one paragraph

ISO/IEC 27017 is the international code of practice for information security controls for cloud services, based on ISO/IEC 27002. It gives cloud-specific implementation guidance for the ISO 27002 controls and adds controls of its own for both cloud service providers and cloud customers, covering shared roles and responsibilities, removal of customer assets, segregation in virtual environments, virtual machine hardening, administrator operations, monitoring and the alignment of virtual and physical network security. It is certified as an extension of an ISO 27001 certificate.

Who it's for

SaaS and cloud service providers whose customers ask how the cloud is secured, and cloud customers in regulated sectors who need to evidence their side of the shared responsibility.

With Viglyn

How Viglyn runs ISO 27017

  • The cloud-specific controls added to your ISO 27001 Statement of Applicability, with the provider and customer responsibilities for each written down as evidence
  • Technical controls checked automatically in AWS and Azure: identity and privileged access, network segregation, virtual machine configuration, logging and monitoring, key management and data removal
  • The shared-responsibility matrix for each cloud provider you use held as a controlled document, and the providers themselves assessed in the vendor module
  • Evidence shared with ISO 27001, SOC 2 and CSA STAR, so the cloud controls are evidenced once
  • The extension audited alongside your ISO 27001 Stage 1 and Stage 2 inside Viglyn, with scoped auditor access
Straight answers

The ISO 27017 questions that decide it

Can we get ISO 27017 without ISO 27001?

No. ISO 27017 is a code of practice, not a management system standard, so it is certified as an extension of an ISO 27001 certificate. If you do not hold ISO 27001 yet, Viglyn runs both from one evidence base and the cloud controls join the Statement of Applicability from the start.

How long does ISO 27017 take?

Weeks on top of an existing ISO 27001 system, because most of the cloud controls are technical and can be checked in your cloud accounts as soon as they are connected. Writing the shared-responsibility split is the part that needs judgement; our practitioners do it with you.

How much does ISO 27017 cost with Viglyn?

ISO 27017 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee for the extended audit is separate and paid by you directly; we take no commission.

FAQ

More ISO 27017 questions

What is the difference between ISO 27017 and ISO 27018?
ISO 27017 is about cloud security controls for providers and customers; ISO 27018 is about protecting personally identifiable information in public clouds, aimed at providers acting as PII processors. Many providers hold both as extensions of ISO 27001, and Viglyn maps both on the same evidence.
Does ISO 27017 replace a SOC 2 report?
No. They serve different buyers: ISO certificates are recognized globally, and in Europe and Asia-Pacific in particular, while SOC 2 reports are what North American enterprises ask for. The underlying cloud controls are the same, which is why Viglyn evidences them once.
What does the shared responsibility model have to do with it?
Everything. Each cloud control is split between the provider and the customer, and ISO 27017 requires the split to be defined and documented. Viglyn holds that matrix per provider and checks the customer side in your accounts automatically.

See ISO 27017 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.