ISO 27017 Consultants

ISO 27017 defines Information security controls based on ISO/IEC 27002 for cloud services.

Our ISO 27017 Consultants are knowledgeable in the whole ISO 27000 family of Information Security Standards, and can help you extend your management system to ensure you have the tools to effectively manage risks using a full range of controls.

NOTE: ISO 27017:2026 NOW PUBLISHED!

ISO 27001 & ISO 27017


The most effective implementation of the ISO 27017 Information Security Controls for Cloud Services is by applying them to an extended ISO 27001 Information Security Management System.

ISO 27001:2022 sets out minimum requirements and includes 93 Controls, however many organisations also use the additional guidance from ISO 27002 to extend the controls. ISO 27017 extends some of these controls even further to make them more applicable to cloud services

Cloud Services Customer (CSC) or Cloud Services Provider (CSP)

The ISO 27017 standard is designed to be applicable to both Cloud Services Customers (CSC) and Cloud Services Providers (CSP).

Where additional guidance is provided on Annex A controls, a table is used to denote both CSC and CSP.

Abbreviations in ISO 27017

CSC: cloud service customer

CSN: cloud service partner

CSP: cloud service provider

CSU: cloud service user

IaaS: infrastructure as a service

PaaS: platform as a service

Additional CLD Controls in ISO 27017:2026


Shared roles and responsibilities within a cloud computing environment


Agreement on the roles and responsibilities of the cloud service partner


Segregation in virtual computing environments


Detection and prevention of unauthorised use of cloud services

Cloud Services

Many individuals and organisations use cloud services on a daily basis, and the popularity continues to grow due to the many benefits they bring.

However, this business model is still relatively new and continues to evolve through SaaS, PaaS and IaaS.

ISO 27017 provides explicit guidance on the responsibilities of both the cloud service provider and the cloud customer, bring much needed clarity throughout the cloud models.

ISO 27017 Certification

ISO 27017 Certification is growing in popularity as an extension to the ISO 27001 scope. Many respected certification bodies will include the ISO 27017 Cloud Services Controls within the scope of an ISO 27001 Management System.

Our ISO 27017 Consultants can guide you through the process of defining an appropriate management system scope and attain an independent and impartial audit of these extended controls.

Benefits of ISO 27017

Clear differentiator from competitors,
Protect & Improve your reputation,
Demonstrate commitment to Information Security,
Better management of cloud service risks,
Comprehensive risk management programme,
Established framework ready from growth.

Other Standards

ISO 27001

ISO 27001

The Information Security Management System (ISMS), in conjunction with ISO 27002 which provides more guidance on each Annex A Control.

ISO 27018 Consultants

ISO 27018

ISO 27018 provides specific guidance and controls for Personal Identifiable Information (PII) in Public Clouds.

Why Choose Us for ISO 27017?

Cyber Security Experts

Cloud Industry Knowledge

Over 20 Years Experience

Thought Leadership

Proven Track Record