Home/Frameworks/ISO 27017
Cloud Security
Cloud Security

ISO 27017

Cloud security, proven. ISO 27017 extends ISO 27001 with controls written specifically for the cloud — addressing the shared-responsibility, multi-tenancy, and virtualisation risks that general standards don't fully cover.

The standard

What ISO 27017 is.

ISO/IEC 27017:2015 is a code of practice for cloud security, building on the ISO 27002 controls with cloud-specific guidance for both providers and customers.

It clarifies the division of security responsibility between cloud provider and customer, and adds controls for issues unique to cloud — virtual machine hardening, administrative-operation segregation, and the return or removal of assets when a service ends.

It is implemented as an extension to an ISO 27001 ISMS and certified alongside it, making it a natural add-on for cloud-native businesses.

Who it's for

Is this you?

Cloud service providers

Demonstrates cloud-specific security maturity to enterprise buyers.

Cloud-native SaaS

Companies whose entire delivery runs on public-cloud infrastructure.

Heavy cloud consumers

Organisations needing assurance over the cloud services they depend on.

How we deliver

From kickoff to done,
in five stages.

Delivered through our specialist network, typically alongside ISO 27001. Because it extends your existing ISMS, the incremental work is focused on the cloud-specific controls rather than a full separate programme.

01

Scope & kickoff

We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.

02

Gap diagnostic

A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.

03

Build

We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.

04

Operate

The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.

05

Audit support

We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.

Questions

Frequently asked.

No — it's an extension to ISO 27001 and is certified together with it. If you already hold ISO 27001, adding ISO 27017 is a focused piece of additional work rather than a fresh engagement.

For a cloud-native business, often yes. It signals to enterprise buyers that you've addressed the security risks specific to cloud, which a general ISO 27001 certificate doesn't explicitly evidence.

Explore more

Other frameworks.

Ready when you are

Let's get you
ISO 27017 ready.

Book a free advisory session and we'll map your fastest credible route to compliance.

Book a free advisory session