ISO 27017 explained: proof your cloud is actually secure
Your data lives in someone else's data centre now. That is not a confession, it is just Tuesday. But it creates a very specific problem when a customer's security team asks how you keep it safe: the honest answer involves you, your cloud provider, and a fuzzy line between the two that nobody has ever written down. ISO 27017 is the standard that makes you write it down.
It is the code of practice for information security in cloud services. The 2026 second edition was realigned to ISO 27002:2022, which is the same control set that sits behind ISO 27001. So rather than inventing a whole new rulebook, 27017 layers cloud-specific guidance on the controls you may already know, and adds four controls built purely for the cloud.
ISO 27001 says you have controls. ISO 27017 says you know exactly which of them your cloud provider runs, which you run, and where the evidence lives. That second sentence is the one enterprise buyers actually want to hear.
The four controls that are new
Most of 27017 is cloud guidance on familiar controls. The genuinely new part is four cloud-specific controls, and they are refreshingly practical:
- Shared roles and responsibilities (5.38 and 5.39 CLD): write down who does what, for every service and every partner in the chain.
- Segregation in virtual computing environments (8.35 CLD): keep your tenancy, and your own environments, properly walled off from each other.
- Detection and prevention of unauthorized cloud use (8.36 CLD): catch both misuse of your sanctioned services and the shadow IT nobody told you about.
The idea that runs through all of it: shared responsibility
The cloud provider secures the platform. You secure what you put on it and how you configure it. The trouble is that the exact split changes with every service and every provider, and 'we assumed AWS handled that' is how breaches happen. 27017 asks you to record, for each control, whether it is operated by you (the cloud service customer), your provider (the cloud service provider), or shared. That record is the shared-responsibility matrix, and it is the artifact an auditor reaches for first.
Why this is the framework that rewards good tooling
Here is the happy part. Because 27017's controls are the ISO 27002:2022 set, the continuous cloud-posture scans you already run against AWS, Azure and GCP map straight onto them. Encryption, logging, segregation, least-privilege access: those are checks a scanner performs thousands of times a day. In Compliance One, that evidence flows into the matching 27017 controls automatically, you set CSC, CSP or Shared on each control inline or in a dedicated matrix with export, and the cloud policies and standards come pre-filled. The framework where most teams have the least evidence becomes the one where the platform does the most of the work.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.