ISO 27017
Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Acquisition (cloud-extended)
Security requirements for cloud-deployed applications shall be specified before development or acquisition.
- Security requirements documents
- Threat models
- Cloud reference architecture
- Architecture reviews
- Requirements set post-launch
- No cloud-specific threats
- Reference architecture absent
Cloud-specific
Procedures for administrator operations in cloud environments shall be defined and documented.
- Admin runbooks
- Change management records
- Privileged access logs
- Approval workflows
- Runbooks missing
- Bypass of change control for cloud
- No segregation between dev and prod admin
Customer shall have capability to monitor relevant aspects of cloud service operation.
- Provider log export config
- Customer SIEM ingestion
- Monitoring rights in contract
- Dashboard screenshots
- No log export
- Contract silent on monitoring
- SIEM coverage incomplete
Network security policies shall apply consistently to virtual and physical networks in cloud environments.
- Unified network policy
- SDN configurations
- Firewall rule reviews
- Microsegmentation diagrams
- Separate policies
- No microsegmentation
- Rule sprawl
Cloud service customer and provider responsibilities for information security shall be allocated, agreed and documented.
- Shared responsibility matrix
- Customer agreement
- Provider SLA
- RACI for cloud workloads
- No documented matrix
- Customer assumes provider covers everything
- SLA silent on security
Customer assets in the cloud service shall be removed, returned or securely deleted upon termination as specified in the agreement.
- Exit clause in contract
- Deletion certificates
- Return of data records
- Verification reports
- No deletion certificates
- Backup copies retained
- Verification missing
Customer environments shall be segregated from other customers and the provider in a multi-tenant cloud.
- Tenancy architecture diagram
- Isolation control tests
- Penetration test reports
- Hypervisor configs
- Shared keys across tenants
- No isolation testing
- Provider attestation accepted at face value
Virtual machines in cloud environments shall be hardened to meet business needs.
- VM hardening baselines
- Golden image inventory
- Drift reports
- CIS benchmark scans
- No golden image
- Manual hardening
- No drift detection
Compliance (cloud-extended)
Legal, regulatory and contractual requirements applicable to cloud data and location shall be identified.
- Data residency register
- Regulatory mapping
- Region selection rationale
- DPA register
- No residency register
- Region defaults accepted
- DPAs missing
ISO 27017: Cloud Governance
Shared responsibility model definition. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Cloud security policy and strategy. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Cloud risk assessment. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Regulatory compliance for cloud services. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
Cloud security roles and responsibilities. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.
- Shared responsibility matrix
- Cloud security policy
- Cloud risk register
- Regulatory mapping
- Shared responsibility unclear per service
- Cloud risks not in enterprise register
- Regulatory mapping stale
ISO 27017: Cloud Infrastructure Security
Virtual network segmentation. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Container and serverless security. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Cloud workload protection. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Image and template hardening. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
Cloud configuration management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.
- VPC design diagram
- Container security baseline
- Hardened image catalogue
- CSPM report
- Default VPC still in use
- Containers run as root
- CSPM misconfigurations unresolved
ISO 27017: Cloud Operations & Monitoring
Cloud security monitoring and logging. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Incident response in cloud. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Cloud vulnerability management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Cloud change management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
Service level agreement management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.
- Cloud SIEM configuration
- Incident response runbook
- Vulnerability scan output
- SLA performance report
- Cloud logs not centralized
- Incident playbooks not cloud-specific
- SLAs not measured
ISO 27017: Data Protection in Cloud
Data classification for cloud. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Encryption of cloud-stored data. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Data residency and sovereignty. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Data backup and recovery in cloud. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
Secure data deletion in cloud. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.
- Data classification policy
- Encryption configuration baseline
- Residency map
- Secure deletion attestation
- Encryption not enforced on all storage classes
- Residency assumptions undocumented
- Deletion attestations missing
ISO 27017: Identity & Access in Cloud
Cloud identity management. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Multi-factor authentication for cloud. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Privileged access in cloud environments. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Federation and single sign-on. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
API security and access tokens. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.
- IAM policy
- MFA enforcement report
- Federation configuration
- API token inventory
- MFA bypass on legacy auth
- Long-lived tokens
- Privileged roles not just-in-time
Incident (cloud-extended)
Incident response procedures shall address cloud-specific incidents and provider coordination.
- Cloud IR playbook
- Provider escalation contacts
- Joint exercise records
- Forensic evidence procedures
- No provider contacts
- No joint exercises
- Forensics limited by provider
Physical (cloud-extended)
Customer data on shared cloud media shall be addressed via provider procedures for secure disposal or reuse.
- Provider disposal attestations
- Crypto-erase configuration
- Media handling policy
- Contract clauses
- No attestation
- Reliance on crypto-erase only
- Policy excludes cloud
Supplier (cloud-extended)
Security requirements for cloud providers shall be defined and reflected in contracts.
- Provider security requirements
- Contract clauses
- Provider attestations
- Risk assessments
- No security annex
- Attestations stale
- No annual review
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27017 framework page.