International Standard
ISO/IEC 27017:2026
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Reference number
ISO/IEC 27017:2026
Edition 2
2026-07

Preview this standard in our Online Browsing Platform (OBP)

ISO/IEC 27017:2026
82878
Published (Edition 2, 2026)

ISO/IEC 27017:2026

ISO/IEC 27017:2026
82878
Language
Format
CHF 196

What is ISO/IEC 27017?

ISO/IEC 27017 provides guidance for implementing information security controls in cloud services. It builds on ISO/IEC 27002 by adding cloud-specific guidance and additional controls for both cloud service customers and cloud service providers.

The standard helps organizations address security risks that arise from the shared nature of cloud computing. It clarifies how information security controls can be applied across customer and provider environments, including situations where responsibilities, infrastructure and operational activities are divided between multiple parties.

ISO/IEC 27017 applies to all cloud deployment models, including public, private and hybrid cloud environments. Its controls should be selected and applied according to the organization’s risk assessment and any relevant legal, regulatory, contractual or cloud-specific security requirements.

Why is ISO/IEC 27017 important?

Cloud services can create uncertainty about who is responsible for protecting information, managing infrastructure, responding to incidents and maintaining security controls. Without clear responsibilities and consistent safeguards, gaps can develop between the expectations of cloud customers and the practices of cloud providers.

ISO/IEC 27017 provides a common security framework for cloud service relationships. It helps customers and providers define responsibilities, manage cloud-specific risks and implement controls in a consistent and transparent way.

By aligning cloud security practices with ISO/IEC 27002, the standard also helps organizations integrate cloud services into their wider information security management approach. This can support stronger governance, clearer supplier relationships and more informed cloud risk decisions.

Benefits

  • Stronger information security for cloud services
  • Clearer security responsibilities between cloud customers and providers
  • More consistent implementation of cloud-specific security controls
  • Improved management of legal, regulatory and contractual security requirements
  • Better alignment with ISO/IEC 27002 information security controls
  • Greater trust and transparency across cloud service relationships

 

FAQ

ISO/IEC 27017 is based on ISO/IEC 27002. It provides additional implementation guidance for controls that are relevant to cloud services and introduces additional controls addressing cloud-specific security risks and responsibilities.

No. The standard applies to all cloud deployment models, including public, private and hybrid cloud environments. In private cloud environments, some controls may need to be adapted to reflect the relationships and responsibilities between internal departments.

General information

  •  : Published
     : 2026-07
    : International Standard published [60.60]
  •  : 2
     : 39
  • ISO/IEC JTC 1/SC 27
    35.030  03.100.70 
  • RSS updates

Got a question?

Check out our Help and Support