It answers the cloud question
'How is your cloud secured?' has no certificate of its own until 27017. It is the recognised, auditable way to demonstrate cloud-specific controls.
Prove your cloud is actually secure.
ISO/IEC 27017 is the code of practice for information security in cloud services. The 2026 second edition is realigned to ISO/IEC 27002:2022: it layers cloud-specific implementation guidance on the whole control set and adds four standalone cloud controls, all built around the shared-responsibility model between you as the cloud service customer (CSC) and your provider (CSP). It is certified as an extension to ISO 27001 — and it is the framework where continuous cloud-posture monitoring does most of the work for you.
The standard
ISO/IEC 27017:2026 — Cloud services information security controls
Who needs it
Any organisation that runs on the cloud and whose customers ask 'how do you secure your cloud?' — SaaS vendors, anyone on AWS/Azure/GCP, and organisations already holding ISO 27001 who want a cloud-specific credential to match. It is increasingly named directly in enterprise security questionnaires.
1000s
cloud checks, auto-mapped
The basics
An extension of ISO 27002:2022, not a separate control set: cloud-specific guidance on the existing controls, plus four cloud controls — shared roles & responsibilities (5.38/5.39 CLD), segregation in virtual computing environments (8.35 CLD), and detection & prevention of unauthorized cloud use (8.36 CLD).
Built on shared responsibility: for every control you record who operates it — CSC (you), CSP (your provider), or Shared — in a responsibility matrix, which is exactly what an auditor reviews.
Certified alongside ISO 27001 by an accredited body, so a 27017 statement sits on top of your existing ISMS certificate rather than starting a new one.
Why it matters
'How is your cloud secured?' has no certificate of its own until 27017. It is the recognised, auditable way to demonstrate cloud-specific controls.
The base controls are the ISO 27002:2022 set, so 27017 maps one-to-one to 27001 — if you hold 27001 you are most of the way there.
Because the controls are the 27002:2022 set, continuous cloud-posture scans of your AWS/Azure/GCP accounts satisfy the technical controls automatically.
Record CSC / CSP / Shared for every control across each cloud service — your shared-responsibility matrix.
Segregation in virtual environments, encryption and key management, logging, and least-privilege cloud IAM.
Threat detection, anomalous-activity monitoring, and control of unsanctioned cloud services (shadow IT).
Cloud service selection, supplier agreements, and secure return & deletion of data at exit.
Cloud security is a moving target split across you and your providers: who encrypts what, who logs what, who owns segregation, what happens to your data at exit. Working out the shared-responsibility split for every control, then evidencing it and keeping it current as your cloud estate changes, is where cloud-security programmes stall.
Do it once, reuse it everywhere. Evidence you collect for ISO 27017is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps ISO 27017 to your environment in a 30-minute walkthrough — and how much of it we handle for you.