Skip to content

ISO 27017

What is ISO 27017?

An international standard that provides guidelines for information security controls applicable to the provision and use of cloud services. ISO 27017 extends ISO 27002 with cloud-specific guidance.

Cloud

Each of these is named in at least one of the same controls as iso 27017. The number is how many controls name both.

What the standards actually require on iso 27017

Requirements naming iso 27017 across 6 standards, quoted from the control text.

ISMAP (Japan)3 controls

ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency
ISO 27017:201541 controls

Requirement defined in ISO 27017:2015, clause 12.3 (Backup). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-27017-2015::12.3 · Backup

GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails)...

GAMP5-CrossMapping-NIST-ISO · Crosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL

Ghana CSA crosswalk to international standards. NIST CSF 2.0 (February 2024): mapping GOVERN (CSA Ghana engagement + Cybersecurity Plan) + IDENTIFY (CII designation + asset + risk + supplier) + PROTECT (access controls + segmentation + encryption + training) +...

GhCSA-Crosswalk-NIST-ISO-27001-Sectoral · Crosswalk to NIST CSF 2.0, ISO 27001, ISO 22301 and Sector Standards
HKMA TM-G-11 control

HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;

HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline

Questions people ask about iso 27017

What is ISO 27017?
An international standard that provides guidelines for information security controls applicable to the provision and use of cloud services. ISO 27017 extends ISO 27002 with cloud-specific guidance.
Why is ISO 27017 important for compliance?
ISO 27017 is a key concept in Cloud. Understanding iso 27017 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address ISO 27017?
ISO 27017 appears in the requirement text of ISMAP (Japan), ISO 27017:2015, IRS Publication 1075, GAMP 5 - Good Automated Manufacturing Practice, Ghana Cybersecurity Act. Across these standards we have identified 49 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about ISO 27017?
Explore our compliance framework pages to see how iso 27017 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how ISO 27017 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.