General Information

Abstract

This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
additional guidance for relevant controls specified in ISO/IEC 27002:2022;
additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE            This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.

Status
Published
Public Enquiry End Date
27-Apr-2025
Publication Date
16-Sep-2026
Technical Committee
ITC - Information technology
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
13-Aug-2026
Due Date
18-Oct-2026
Completion Date
17-Sep-2026

Buy Documents

Standard

SIST EN ISO/IEC 27017:2026

English language (49 pages)
Preview
Preview
e-Library read for
1 day

Overview

SIST EN ISO/IEC 27017:2026 is an international standard that provides specialized guidance for implementing information security controls in cloud services, building on the foundation of ISO/IEC 27002:2022. Developed by the Slovenian Institute for Standardization (SIST) and aligned with the latest international best practices, this document addresses the unique information security, cybersecurity, and privacy protection challenges inherent in cloud environments. It offers additional controls and tailored guidance for both cloud service customers (CSCs) and cloud service providers (CSPs), serving as a horizontal standard that supports consistent security approaches across all cloud service delivery models, including private clouds.

The focus of ISO/IEC 27017:2026 is to mitigate risks related to the provision and use of cloud services by clarifying roles, responsibilities, and control measures in cloud relationships. This standard is applicable across industries leveraging cloud technology and strives to foster trust and security in cloud-based solutions.

Key Topics

The standard covers a comprehensive range of topics and cloud-specific issues, including:

  • Cloud-specific information security controls: Additional requirements beyond ISO/IEC 27002, tailored for cloud service use and provisioning.
  • Shared responsibility models: Guidance on clarifying and dividing roles and responsibilities between CSCs and CSPs.
  • Supplier relationships: Information security management throughout the cloud supply chain, including multi-tier CSP arrangements.
  • Organizational controls: Policies, asset management, segregation of duties, access rights management, compliance, and privacy of personally identifiable information (PII).
  • People controls: Personnel screening, confidentiality agreements, information security training, and remote work considerations.
  • Physical controls: Data center access control, equipment protection, physical security monitoring, and secure disposal of hardware.
  • Technological controls: Data deletion and masking, malware protection, configuration management, secure authentication, privileged access management, logging and monitoring, encryption, and software development lifecycle management.

Applications

ISO/IEC 27017:2026 is relevant for any organization that provides or utilizes cloud services, regardless of industry or cloud deployment type (public, private, hybrid, or community):

  • Cloud service providers (CSPs): Implement the controls to ensure robust security within their cloud platforms, increasing customer confidence and reducing operational risk.
  • Cloud service customers (CSCs): Use the guidance to assess CSP capabilities, specify security requirements in contracts, and maintain their own compliance and risk posture when adopting cloud technologies.
  • Regulated industries: Simplifies alignment with statutory and regulatory requirements concerning data protection and privacy in the cloud.
  • Auditors and assessors: Provides benchmarks for evaluating the effectiveness of implemented information security controls in cloud environments.
  • Security managers and IT departments: Supports risk assessment and continuous improvement of cloud security strategies in line with internationally recognized best practices.

By using this standard, organizations can better define, implement, and monitor effective cloud security, reduce vulnerabilities, and respond efficiently to incidents or changes in the cloud threat landscape.

Related Standards

ISO/IEC 27017:2026 is part of a broader family of standards on information security and cloud computing. Key related standards include:

  • ISO/IEC 27002:2022: Foundations for information security controls applied in ISO/IEC 27017.
  • ISO/IEC 27001: Requirements for establishing, implementing, maintaining, and improving an information security management system (ISMS).
  • ISO/IEC 27036 (Parts 1-4): Focused guidance on securing supplier and service relationships, especially relevant for cloud supply chains.
  • ISO/IEC 22123-1: Defines cloud computing terminology and concepts.
  • ISO/IEC 27018: Code of practice for protection of personally identifiable information (PII) in public cloud environments.

Integration of ISO/IEC 27017:2026 with these standards ensures a robust, holistic approach to information security, cybersecurity, and privacy protection in modern cloud computing landscapes.

Relations

Effective Date
01-Oct-2026

Buy Documents

Standard

SIST EN ISO/IEC 27017:2026

English language (49 pages)
Preview
Preview
e-Library read for
1 day

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

SIST EN ISO/IEC 27017:2026 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)". This standard covers: This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides: additional guidance for relevant controls specified in ISO/IEC 27002:2022; additional controls with guidance that specifically relate to cloud services. This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs). This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. NOTE            This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.

This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides: additional guidance for relevant controls specified in ISO/IEC 27002:2022; additional controls with guidance that specifically relate to cloud services. This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs). This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. NOTE            This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.

SIST EN ISO/IEC 27017:2026 is classified under the following ICS (International Classification for Standards) categories: 03.100.70 - Management systems; 35.030 - IT Security; 35.210 - Cloud computing. The ICS classification helps identify the subject area and facilitates finding related standards.

SIST EN ISO/IEC 27017:2026 has the following relationships with other standards: It is inter standard links to SIST EN ISO/IEC 27017:2021. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

SIST EN ISO/IEC 27017:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-oktober-2026
Nadomešča:
SIST EN ISO/IEC 27017:2021
Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Nadzor
informacijske varnosti, ki temelji na ISO/IEC 27002 za storitve v oblaku (ISO/IEC
27017:2026)
Information security, cybersecurity and privacy protection - Information security controls
based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)
Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre -
Informationssicherheitsmaßnahmen auf der Grundlage von ISO/IEC 27002 für Cloud-
Dienste (ISO/IEC 27017:2026)
Sécurité de l'information, cybersécurité et protection de la vie privée - Contrôles de
sécurité de l'information fondés sur l'ISO/IEC 27002 pour les services du nuage
(ISO/IEC 27017:2026)
Ta slovenski standard je istoveten z: EN ISO/IEC 27017:2026
ICS:
03.100.70 Sistemi vodenja Management systems
35.030 Informacijska varnost IT Security
35.210 Računalništvo v oblaku Cloud computing
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 27017

NORME EUROPÉENNE
EUROPÄISCHE NORM
August 2026
ICS 35.030; 03.100.70
Supersedes EN ISO/IEC 27017:2021
English version
Information security, cybersecurity and privacy protection
- Information security controls based on ISO/IEC 27002
for cloud services (ISO/IEC 27017:2026)
Sécurité de l'information, cybersécurité et protection Informationssicherheit, Cybersicherheit und Schutz
de la vie privée - Contrôles de sécurité de l'information der Privatsphäre -
fondés sur l'ISO/IEC 27002 pour les services du nuage Informationssicherheitsmaßnahmen auf der Grundlage
(ISO/IEC 27017:2026) von ISO/IEC 27002 für Cloud-Dienste (ISO/IEC
27017:2026)
This European Standard was approved by CEN on 2 July 2026.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. EN ISO/IEC 27017:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
This document (EN ISO/IEC 27017:2026) has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology" in collaboration with Technical Committee CEN-CENELEC/ JTC 13
“Cybersecurity and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by February 2027, and conflicting national standards
shall be withdrawn at the latest by February 2027.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
This document supersedes EN ISO/IEC 27017:2021.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN and CENELEC
websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 27017:2026 has been approved by CEN-CENELEC as EN ISO/IEC 27017:2026
without any modification.
International
Standard
ISO/IEC 27017
Second edition
Information security, cybersecurity
2026-07
and privacy protection —
Information security controls based
on ISO/IEC 27002 for cloud services
Sécurité de l'information, cybersécurité et protection de la vie
privée — Contrôles de sécurité de l'information fondés sur l'ISO/
IEC 27002 pour les services du nuage
Horizontal document
Reference number
ISO/IEC 27017:2026(en) © ISO/IEC 2026

ISO/IEC 27017:2026(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 27017:2026(en)
Contents Page
Foreword .vi
Introduction .vii
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
3.1 Terms and definitions .1
3.2 Abbreviated terms .2
4 Guidance for using this document . . 2
4.1 Relation between this document and ISO/IEC 27002:2022 .2
4.2 Structure of this document .3
4.3 Cloud computing specific concepts .3
4.3.1 Supplier relationships in cloud services .3
4.3.2 Relationships between CSCs and CSPs.3
4.3.3 Managing information security risks in cloud services .4
5 Cloud service specific guidance related to organizational controls . 5
5.1 Policies for information security . .5
5.2 Information security roles and responsibilities .6
5.3 Segregation of duties.6
5.4 Management responsibilities .6
5.5 Contact with authorities .6
5.6 Contact with special interest groups . .6
5.7 Threat intelligence .7
5.8 Information security in project management .7
5.9 Inventory of information and other associated assets .7
5.10 Acceptable use of information and other associated assets .7
5.11 Return of assets .8
5.12 Classification of information .8
5.13 Labelling of information .8
5.14 Information transfer .8
5.15 Access control .8
5.16 Identity management .8
5.17 Authentication information .9
5.18 Access rights .9
5.19 Information security in supplier relationships .9
5.20 Addressing information security within supplier agreements .10
5.21 Managing information security in the ICT supply chain .10
5.22 Monitoring, review and change management of supplier services .11
5.23 Information security for use of cloud services .11
5.24 Information security incident management planning and preparation .11
5.25 Assessment and decision on information security events .11
5.26 Response to information security incidents . 12
5.27 Learning from information security incidents . 12
5.28 Collection of evidence . . 12
5.29 Information security during disruption . 12
5.30 ICT readiness for business continuity . 12
5.31 Legal, statutory, regulatory and contractual requirements . 13
5.32 Intellectual property rights .14
5.33 Protection of records .14
5.34 Privacy and protection of PII .14
5.35 Independent review of information security .14
5.36 Compliance with policies, rules and standards for information security . 15
5.37 Documented operating procedures . 15
5.38 CLD - Shared roles and responsibilities within a cloud computing environment . 15

© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 27017:2026(en)
5.39 CLD - Agreement on the roles and responsibilities of the cloud service partner .16
6 Cloud service specific guidance related to people controls . 17
6.1 Screening .17
6.2 Terms and conditions of employment .18
6.3 Information security awareness, education and training .18
6.4 Disciplinary process .18
6.5 Responsibilities after termination or change of employment.18
6.6 Confidentiality or non-disclosure agreements .18
6.7 Remote working .18
6.8 Information security event reporting.19
7 Cloud service specific guidance related to physical controls . 19
7.1 Physical security perimeters .19
7.2 Physical entry .19
7.3 Securing offices, rooms and facilities .19
7.4 Physical security monitoring . .19
7.5 Protecting against physical and environmental threats .19
7.6 Working in secure areas .19
7.7 Clear desk and clear screen .19
7.8 Equipment siting and protection .19
7.9 Security of assets off-premises . 20
7.10 Storage media . 20
7.11 Supporting utilities . 20
7.12 Cabling security . 20
7.13 Equipment maintenance . 20
7.14 Secure disposal or re-use of equipment . 20
8 Cloud service specific guidance related to technological controls .20
8.1 User endpoint devices . 20
8.2 Privileged access rights .21
8.3 Information access restriction .21
8.4 Access to source code .21
8.5 Secure authentication .21
8.6 Capacity management . 22
8.7 Protection against malware . 22
8.8 Management of technical vulnerabilities . 22
8.9 Configuration management . 23
8.10 Information deletion . 23
8.11 Data masking .24
8.12 Data leakage prevention .24
8.13 Information backup.24
8.14 Redundancy of information processing facilities . 25
8.15 Logging . 25
8.16 Monitoring activities . 26
8.17 Clock synchronization . 26
8.18 Use of privileged utility programs .27
8.19 Installation of software on operational systems .27
8.20 Network security .27
8.21 Security of network services .27
8.22 Segregation of networks . 28
8.23 Web filtering . 28
8.24 Use of cryptography . 28
8.25 Secure development life cycle . 28
8.26 Application security requirements . 29
8.27 Secure system architecture and engineering principles . 29
8.28 Secure coding. 29
8.29 Security testing in development and acceptance . 29
8.30 Outsourced development . 29
8.31 Separation of development, test and production environments. 29

© ISO/IEC 2026 – All rights reserved
iv
ISO/IEC 27017:2026(en)
8.32 Change management . 29
8.33 Test information . 30
8.34 Protection of information systems during audit and testing . 30
8.35 CLD - Segregation in virtual computing environments . 30
8.36 CLD - Detection and prevention of unauthorized use of cloud services .31
Annex A (Informative) Correspondence between this document and the first edition (ISO/IEC
27017:2015) .33
Annex B (informative) Monitoring of cloud services .38
Bibliography .39

© ISO/IEC 2026 – All rights reserved
v
ISO/IEC 27017:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection, in collaboration with ITU-T
(as Rec. ITU-T X.1631), and in collaboration with the European Committee for Standardization (CEN)
Technical Committee CEN/CLC/JTC 13, Cybersecurity and Data Protection, in accordance with the Agreement
on technical cooperation between ISO and CEN (Vienna Agreement).
This second edition cancels and replaces the first edition (ISO/IEC 27017:2015 | Rec. ITU-T X.1631:2015),
which has been technically revised.
The main changes are as follows:
— the title and the scope have been modified;
— the structure of the document has been changed, presenting the controls using a simple taxonomy and
associated attributes;
— some controls have been merged, some have been removed and several new controls have been
introduced.
This document has been given the status of a horizontal document in accordance with the ISO/IEC Directives,
Part 1.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
vi
ISO/IEC 27017:2026(en)
Introduction
The guidance contained within this document is aligned with and complements the guidance given in
ISO/IEC 27002.
Specifically, this document provides guidance supporting the implementation of information security
controls for cloud service customers (CSCs) and cloud service providers (CSPs). Some guidance is intended
for CSCs who implement the controls and other guidance is for CSPs to support the implementation of those
controls. The determination of the appropriate information security controls and the extent of the utilization
of the guidance provided depends on the results of the relevant risk assessment and the existence of any
legal, regulatory, contractual, or other cloud-computing specific information security requirements.

© ISO/IEC 2026 – All rights reserved
vii
International Standard ISO/IEC 27017:2026(en)
Information security, cybersecurity and privacy protection —
Information security controls based on ISO/IEC 27002 for
cloud services
1 Scope
This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to
the provision and use of cloud services. This document provides:
— additional guidance for relevant controls specified in ISO/IEC 27002:2022;
— additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service
providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common
understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying
this document to the private cloud, the controls and guidance of this document are applicable, although adjustments
can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 22123-1, Information technology — Cloud computing — Part 1: Vocabulary
ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection — Information security
controls
3 Terms, definitions and abbreviated terms
3.1 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 27002, ISO/IEC 22123-1 and
the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1.1
capability
ability to perform a specific activity
[SOURCE: ISO 19440:2020, 3.5]
© ISO/IEC 2026 – All rights reserved
ISO/IEC 27017:2026(en)
3.2 Abbreviated terms
API application programming interface
CSC cloud service customer
CSN cloud service partner
CSP cloud service provider
CSU cloud service user
IaaS infrastructure as a service
ICT information and communication technology
PaaS platform as a service
PII personally identifiable information
RTO recovery time objective
RPO recovery point objective
SaaS software as a service
SLA service level agreement
4 Guidance for using this document
4.1 Relation between this document and ISO/IEC 27002:2022
This document provides:
— additional guidance for relevant controls specified in ISO/IEC 27002:2022;
— additional controls with guidance that specifically relate to cloud services.
This document refers to the attributes, controls, purposes, guidance and other information from
ISO/IEC 27002:2022, Clauses 5 to 8. Owing to the general applicability of ISO/IEC 27002:2022, many of the
controls, guidance and other information apply to both the general and cloud computing contexts of an
organization. For example, ISO/IEC 27002:2022, 5.3, “Segregation of duties” provides a control that can be
applied whether the organization is acting as a CSP or not. Additionally, a CSC can derive requirements for
segregation of duties in the cloud computing environment from the same control, e.g. a CSC segregating the
CSCs' cloud service administrators from other CSUs.
This document also provides attributes, controls, purposes, guidance and other information that are specific
to cloud services and are intended to mitigate the risks that accompany the technical and operational
features of cloud services (see 5.38, 5.39, 8.35 and 8.36). Annex A provides the mappings between the set of
1)
controls of this document and the previous edition (ISO/IEC 27017:2015 ).
The CSCs and the CSPs can refer to ISO/IEC 27002:2022 and this document to identify guidance on general
and cloud service specific controls as necessary. This process can be done by performing an information
security risk assessment and risk treatment in the organizational and business context where cloud services
are used or provided (see 4.3.3).
1) Cancelled and replaced by this document (ISO/IEC 27017:2026).

© ISO/IEC 2026 – All rights reserved
ISO/IEC 27017:2026(en)
4.2 Structure of this document
This document follows the structure used in ISO/IEC 27002:2022 for the description of controls.
This document adapts the information security controls included in ISO/IEC 27002:2022, Clauses 5 to 8 to
better fit cloud computing. As in ISO/IEC 27002:2022, the categorization of controls given in Clauses 5 to 8 is
referred to as themes and the attributes of each control identified in ISO/IEC 27002:2022 also apply.
When controls specified in ISO/IEC 27002:2022 are applicable to both the CSCs and the CSP without a need
for any additional information, only a reference to ISO/IEC 27002:2022 is provided.
In addition to the controls of ISO/IEC 27002:2022, cloud service extended controls are prefixed with “CLD”
(CLouD service extended controls). When a control specified in ISO/IEC 27002:2022 needs additional
guidance that is specific to cloud services related to the control, it is given as “guidance for cloud services”.
The guidance is provided in one of the following two types:
— Type 1 (shown in Table 1), used when there is separate guidance for the CSC and the CSP;
— Type 2 (shown in Table 2), used when the guidance is the same for both the CSC and the CSP.
Table 1 — Type 1
CSC CSP
CSC guidance CSP guidance
Table 2 — Type 2
CSC CSP
CSC and CSP guidance
4.3 Cloud computing specific concepts
4.3.1 Supplier relationships in cloud services
ISO/IEC 27002:2022, 5.19 to 5.22 provide controls, the purpose of each control, guidance and other
information for managing information security in supplier relationships. The provision and use of cloud
services is similar to a supplier relationship, where the CSC is an acquirer and the CSP is a supplier. Therefore,
ISO/IEC 27002:2022, 5.19 to 5.22 apply to CSCs and CSPs.
CSCs and CSPs can also form a supply chain. For example, a CSP provides a cloud service of infrastructure
capabilities type. On top of this service, another CSP can provide a cloud service of application capabilities
type. In this case, the second CSP is a CSC with respect to the first, and a CSP with respect to the CSC using
its service. In this scenario, the organization has both CSC and CSP roles. Every organization should consider
which controls are applicable to it in its roles as the CSC and the CSP. This example illustrates the case where
this document applies to an organization both as a CSC and as a CSP. Since CSCs and CSPs form a supply
chain through the provision and use of the cloud service, ISO/IEC 27002:2022, 5.21 applies as it covers the
management of information security in the ICT supply chain.
The ISO/IEC 27036 series provides detailed guidance on the information security in supplier relationships
to the acquirer and supplier of products and services. ISO/IEC 27036-4 deals directly with information
security of cloud services in supplier relationships. ISO/IEC 27036-4 is also applicable to CSCs as acquirers
and CSPs as suppliers.
4.3.2 Relationships between CSCs and CSPs
In the cloud computing environment, CSC data are stored, transmitted and processed by a cloud service.
Therefore, a CSC's business processes depend upon the information security of the cloud service. Without
sufficient control over the cloud service, it can be necessary for the CSC to take extra precautions with its
own information security practices.

© ISO/IEC 2026 – All rights reserved
ISO/IEC 27017:2026(en)
Before entering into a supplier relationship, the CSC is expected to select a cloud service, taking into account
the possible gaps between the CSC's information security requirements and the information security
capabilities offered by the service. Once a cloud service is selected, the CSC should manage the use of the
cloud service in such a way as to meet its own information security requirements. In this relationship,
collaborative effort between the CSC and the CSP for the use and provision of the cloud service is necessary
for the CSC to achieve its objectives for information security management. It includes shared roles and
responsibilities between the CSC and the CSP. The CSP should provide the information and technical support
that are necessary to meet the CSC's information security requirements. When the information security
controls provided by the CSP are pre-set and cannot be changed by the CSC, it is possible that the CSC
implements additional controls of its own to mitigate risks. More information on allocation of the shared
roles and responsibilities can be found in 5.38.
It is important to understand that there are different cloud deployment models that are used in cloud
computing environments. Some of the cloud deployment models include:
— private cloud;
— public cloud;
— multi-cloud;
— federated cloud;
— hybrid cloud;
— hybrid multi-cloud;
— inter-cloud.
There are three fundamental approaches that can be taken in these different cloud deployment models.
— The CSC controls and manages the cloud services that are being delivered by each of the CSPs including
their orchestration into a cloud solution (e.g. multi-cloud).
— One CSP combines cloud services from multiple CSPs with varying degrees of orchestration, control and
management activities (e.g. inter-cloud).
— Multiple CSPs form a partnership through out-of-band collaboration and share their resources to
create cloud services (e.g. federated cloud which uses a cloud service federation management system to
orchestrate access to the CSPs resources).
It is important to note that these approaches are not mutually exclusive and it is possible to combine them.
Further explanation of these cloud deployment models can be found in ISO/IEC 5140.
4.3.3 Managing information security risks in cloud services
CSCs and C
...