Skip to content

Evidence request lists

ISO 27017

Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Acquisition (cloud-extended)

14.1.1
Information security requirements analysis (cloud apps)

Security requirements for cloud-deployed applications shall be specified before development or acquisition.

Artefacts an auditor will ask for
  • Security requirements documents
  • Threat models
  • Cloud reference architecture
  • Architecture reviews
Where this commonly fails
  • Requirements set post-launch
  • No cloud-specific threats
  • Reference architecture absent

Cloud-specific

CLD.12.1.5
Administrator's operational security

Procedures for administrator operations in cloud environments shall be defined and documented.

Artefacts an auditor will ask for
  • Admin runbooks
  • Change management records
  • Privileged access logs
  • Approval workflows
Where this commonly fails
  • Runbooks missing
  • Bypass of change control for cloud
  • No segregation between dev and prod admin
CLD.12.4.5
Monitoring of cloud services

Customer shall have capability to monitor relevant aspects of cloud service operation.

Artefacts an auditor will ask for
  • Provider log export config
  • Customer SIEM ingestion
  • Monitoring rights in contract
  • Dashboard screenshots
Where this commonly fails
  • No log export
  • Contract silent on monitoring
  • SIEM coverage incomplete
CLD.13.1.4
Alignment of security management for virtual and physical networks

Network security policies shall apply consistently to virtual and physical networks in cloud environments.

Artefacts an auditor will ask for
  • Unified network policy
  • SDN configurations
  • Firewall rule reviews
  • Microsegmentation diagrams
Where this commonly fails
  • Separate policies
  • No microsegmentation
  • Rule sprawl
CLD.6.3.1
Shared roles and responsibilities within a cloud computing environment

Cloud service customer and provider responsibilities for information security shall be allocated, agreed and documented.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Customer agreement
  • Provider SLA
  • RACI for cloud workloads
Where this commonly fails
  • No documented matrix
  • Customer assumes provider covers everything
  • SLA silent on security
CLD.8.1.5
Removal of cloud service customer assets

Customer assets in the cloud service shall be removed, returned or securely deleted upon termination as specified in the agreement.

Artefacts an auditor will ask for
  • Exit clause in contract
  • Deletion certificates
  • Return of data records
  • Verification reports
Where this commonly fails
  • No deletion certificates
  • Backup copies retained
  • Verification missing
CLD.9.5.1
Segregation in virtual computing environments

Customer environments shall be segregated from other customers and the provider in a multi-tenant cloud.

Artefacts an auditor will ask for
  • Tenancy architecture diagram
  • Isolation control tests
  • Penetration test reports
  • Hypervisor configs
Where this commonly fails
  • Shared keys across tenants
  • No isolation testing
  • Provider attestation accepted at face value
CLD.9.5.2
Virtual machine hardening

Virtual machines in cloud environments shall be hardened to meet business needs.

Artefacts an auditor will ask for
  • VM hardening baselines
  • Golden image inventory
  • Drift reports
  • CIS benchmark scans
Where this commonly fails
  • No golden image
  • Manual hardening
  • No drift detection

Compliance (cloud-extended)

18.1.1
Identification of applicable legislation (cloud)

Legal, regulatory and contractual requirements applicable to cloud data and location shall be identified.

Artefacts an auditor will ask for
  • Data residency register
  • Regulatory mapping
  • Region selection rationale
  • DPA register
Where this commonly fails
  • No residency register
  • Region defaults accepted
  • DPAs missing

ISO 27017: Cloud Governance

ISO27017-01
Shared responsibility model definition

Shared responsibility model definition. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27017-02
Cloud security policy and strategy

Cloud security policy and strategy. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27017-03
Cloud risk assessment

Cloud risk assessment. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27017-04
Regulatory compliance for cloud services

Regulatory compliance for cloud services. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27017-05
Cloud security roles and responsibilities

Cloud security roles and responsibilities. Control from ISO 27017 framework, domain: ISO 27017: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale

ISO 27017: Cloud Infrastructure Security

ISO27017-16
Virtual network segmentation

Virtual network segmentation. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27017-17
Container and serverless security

Container and serverless security. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27017-18
Cloud workload protection

Cloud workload protection. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27017-19
Image and template hardening

Image and template hardening. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27017-20
Cloud configuration management

Cloud configuration management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved

ISO 27017: Cloud Operations & Monitoring

ISO27017-21
Cloud security monitoring and logging

Cloud security monitoring and logging. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27017-22
Incident response in cloud

Incident response in cloud. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27017-23
Cloud vulnerability management

Cloud vulnerability management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27017-24
Cloud change management

Cloud change management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27017-25
Service level agreement management

Service level agreement management. Control from ISO 27017 framework, domain: ISO 27017: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured

ISO 27017: Data Protection in Cloud

ISO27017-11
Data classification for cloud

Data classification for cloud. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27017-12
Encryption of cloud-stored data

Encryption of cloud-stored data. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27017-13
Data residency and sovereignty

Data residency and sovereignty. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27017-14
Data backup and recovery in cloud

Data backup and recovery in cloud. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27017-15
Secure data deletion in cloud

Secure data deletion in cloud. Control from ISO 27017 framework, domain: ISO 27017: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing

ISO 27017: Identity & Access in Cloud

ISO27017-06
Cloud identity management

Cloud identity management. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27017-07
Multi-factor authentication for cloud

Multi-factor authentication for cloud. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27017-08
Privileged access in cloud environments

Privileged access in cloud environments. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27017-09
Federation and single sign-on

Federation and single sign-on. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27017-10
API security and access tokens

API security and access tokens. Control from ISO 27017 framework, domain: ISO 27017: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time

Incident (cloud-extended)

16.1.1
Responsibilities and procedures (cloud incidents)

Incident response procedures shall address cloud-specific incidents and provider coordination.

Artefacts an auditor will ask for
  • Cloud IR playbook
  • Provider escalation contacts
  • Joint exercise records
  • Forensic evidence procedures
Where this commonly fails
  • No provider contacts
  • No joint exercises
  • Forensics limited by provider

Physical (cloud-extended)

11.2.7
Secure disposal or reuse of equipment (cloud)

Customer data on shared cloud media shall be addressed via provider procedures for secure disposal or reuse.

Artefacts an auditor will ask for
  • Provider disposal attestations
  • Crypto-erase configuration
  • Media handling policy
  • Contract clauses
Where this commonly fails
  • No attestation
  • Reliance on crypto-erase only
  • Policy excludes cloud

Supplier (cloud-extended)

15.1.1
Information security policy for supplier relationships (cloud)

Security requirements for cloud providers shall be defined and reflected in contracts.

Artefacts an auditor will ask for
  • Provider security requirements
  • Contract clauses
  • Provider attestations
  • Risk assessments
Where this commonly fails
  • No security annex
  • Attestations stale
  • No annual review
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27017 framework page.