Compliance · Cloud extension
ISO 27001, translated for how cloud actually works.
ISO/IEC 27017 extends ISO 27002 with guidance built for cloud — the shared responsibility split, virtual machine hardening, tenant isolation, and the controls that only exist because someone else runs your infrastructure. It's implemented alongside an ISO 27001 ISMS.
27002+
Extends
Shared
Responsibility model
Both sides
Provider & customer
It fills the gap ISO 27001 leaves open: who does what when your infrastructure isn't yours.
27017 makes the split explicit — which controls the provider owns, which you own, and which are shared. Undocumented boundaries are where cloud breaches live.
Guidance covering virtual machine hardening, tenant isolation, administrative operations, monitoring, and the safe return or deletion of assets when you leave a provider.
The standard speaks to both cloud service providers and cloud customers. Which role you're in changes what you have to prove.
Organizations whose security posture depends on a provider they don't control.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We document exactly which controls you own versus your provider, per service — eliminating the assumed-covered gaps that fail audits.
We extend your ISMS policies to address multi-tenancy, provisioning, identity delegation, and administrative access.
We harden cloud configurations, network boundaries, key management, and logging against 27017 guidance.
We evaluate your provider's posture and certifications, and capture what you can legitimately inherit from them.
We prove assets can be returned or destroyed on exit — a control teams routinely forget until an auditor asks.
We produce the cloud control mapping and evidence that plugs into your 27001 audit.
Inventory cloud services and the responsibility split for each.
Measure current cloud controls against 27017 guidance.
Close configuration, identity, and monitoring gaps.
Document control ownership and collect proof.
Fold the results into your ISO 27001 certification or surveillance audit.
Not on its own — 27017 is guidance that extends ISO 27002, so it's assessed alongside an ISO 27001 ISMS. Certification bodies can include 27017 in the scope of your 27001 certification, which is how most organizations demonstrate it.
27017 is about cloud security controls broadly — isolation, hardening, shared responsibility. 27018 is specifically about protecting personally identifiable information in public clouds. They're complementary and often implemented together.
They handle their half. Providers publish shared responsibility models precisely because configuration, identity, data, and access remain yours. Nearly every headline cloud breach is a customer-side misconfiguration, not a provider failure.
A meaningful amount of physical and infrastructure control coverage, if you document it properly. We map what's genuinely inheritable from your provider's certifications and make sure the rest is demonstrably yours.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.