Compliance · Cloud extension

ISO/IEC 27017 — cloud-specific information security controls

ISO 27001, translated for how cloud actually works.

ISO/IEC 27017 extends ISO 27002 with guidance built for cloud — the shared responsibility split, virtual machine hardening, tenant isolation, and the controls that only exist because someone else runs your infrastructure. It's implemented alongside an ISO 27001 ISMS.

27002+

Extends

Shared

Responsibility model

Both sides

Provider & customer

What ISO 27017 adds

It fills the gap ISO 27001 leaves open: who does what when your infrastructure isn't yours.

Shared responsibility

27017 makes the split explicit — which controls the provider owns, which you own, and which are shared. Undocumented boundaries are where cloud breaches live.

Cloud-specific controls

Guidance covering virtual machine hardening, tenant isolation, administrative operations, monitoring, and the safe return or deletion of assets when you leave a provider.

Two audiences

The standard speaks to both cloud service providers and cloud customers. Which role you're in changes what you have to prove.

Who needs ISO 27017

Organizations whose security posture depends on a provider they don't control.

  • SaaS providers building on AWS, Azure, or GCP
  • Cloud service providers demonstrating tenant isolation
  • Regulated organizations moving workloads off-premises
  • ISO 27001-certified companies asked to prove cloud maturity

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Responsibility mapping

We document exactly which controls you own versus your provider, per service — eliminating the assumed-covered gaps that fail audits.

Cloud policy uplift

We extend your ISMS policies to address multi-tenancy, provisioning, identity delegation, and administrative access.

Configuration hardening

We harden cloud configurations, network boundaries, key management, and logging against 27017 guidance.

Provider assurance

We evaluate your provider's posture and certifications, and capture what you can legitimately inherit from them.

Exit & deletion

We prove assets can be returned or destroyed on exit — a control teams routinely forget until an auditor asks.

Audit evidence

We produce the cloud control mapping and evidence that plugs into your 27001 audit.

How the engagement runs

1

Map services

Inventory cloud services and the responsibility split for each.

2

Assess

Measure current cloud controls against 27017 guidance.

3

Harden

Close configuration, identity, and monitoring gaps.

4

Evidence

Document control ownership and collect proof.

5

Audit

Fold the results into your ISO 27001 certification or surveillance audit.

Frequently asked questions

Can we certify to ISO 27017 by itself?

Not on its own — 27017 is guidance that extends ISO 27002, so it's assessed alongside an ISO 27001 ISMS. Certification bodies can include 27017 in the scope of your 27001 certification, which is how most organizations demonstrate it.

How is ISO 27017 different from ISO 27018?

27017 is about cloud security controls broadly — isolation, hardening, shared responsibility. 27018 is specifically about protecting personally identifiable information in public clouds. They're complementary and often implemented together.

Doesn't our cloud provider handle this?

They handle their half. Providers publish shared responsibility models precisely because configuration, identity, data, and access remain yours. Nearly every headline cloud breach is a customer-side misconfiguration, not a provider failure.

What can we inherit from AWS or Azure?

A meaningful amount of physical and infrastructure control coverage, if you document it properly. We map what's genuinely inheritable from your provider's certifications and make sure the rest is demonstrably yours.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

ISO 27017 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.