ISO 27017
Definition
ISO 27017
ISO 27017 is the cloud security standard that adds cloud-specific guidance to the general security controls, and it addresses providers and customers together. It exists to settle who owns which control, which is the question outsourcing keeps raising in practice.
Almost every other standard speaks to one party. This one speaks to both — deliberately.
That design choice makes it unusually useful in outsourcing, where the recurring failure is not a missing control but a control each side assumed the other operated.
It is guidance layered on top of the general security controls rather than a standalone management system, which shapes how a provider can be certified against it.
Key takeaways
- ISO 27017 addresses cloud service providers and cloud service customers in the same document.
- It adds cloud-specific guidance to existing controls and introduces seven genuinely new ones.
- The new controls cover the handover points where outsourced arrangements usually fail.
- Certification is normally audited alongside ISO 27001 rather than on its own.
How it works
ISO 27017 sits on top of the general information security controls. Microsoft records that it provides guidance on 37 controls in ISO/IEC 27002, and it also features seven new controls that are not duplicated elsewhere.
Those seven are the reason the standard matters to anyone buying outsourced cloud work. They are the handover points.
They cover shared roles and responsibilities; removal and return of customer assets when a contract ends; and separating one customer’s virtual environment from another’s.
They also reach virtual machine hardening; procedures for administrative operations; letting customers monitor their own activity; and aligning virtual with physical network security.
Read that list as a contract checklist — and it becomes obvious what it is for. Every item is a place where a buyer and a provider can each assume the other is responsible.
Microsoft also notes the standard is unique in providing guidance for both cloud service providers and cloud service customers, giving customers practical information on what to expect from a provider.
| New control area | The outsourcing question it answers |
|---|---|
| Shared roles and responsibilities | Who operates which control |
| Return of assets on termination | What happens to your data when you leave |
| Virtual environment separation | Whether another tenant can reach you |
| Virtual machine hardening | Who patches what, and when |
| Administrative operations | Which provider staff hold privileged access |
| Customer monitoring | Whether you can see your own logs |
| Virtual and physical network alignment | Whether the two security models agree |
The termination row deserves particular attention. Exit provisions are written when a relationship starts — and read when it ends badly.
The shared-responsibility idea is not unique to this standard. AWS describes its own Shared Responsibility Model in the same terms, splitting infrastructure duties from those the customer retains.
Examples
Cloud responsibility disputes follow a predictable pattern, and the standard reads almost like a catalogue of them. Each of these came up in a real contract negotiation rather than a webinar.
A company assumes its provider patches the operating systems on its virtual machines. The provider assumes the customer does, and the hardening control is where that argument gets settled.
A buyer ending a contract asks for its data back and finds no agreed format or deadline. Return of assets on termination exists precisely because data center outsourcing exits are rarely graceful.
A regulated client requires log access so its own team can monitor activity. Without the customer monitoring control, it depends on the provider volunteering evidence.
A security team asks how many provider administrators can reach its environment. The answer sits in administrative operations, and it is frequently larger than expected.
Related terms
Cloud security standards, the services around them and the general security regime are habitually conflated. The terms below carry one sense apiece, with the nearest rival explicitly excluded.
- ISO 27001: the certifiable management system that ISO 27017 is normally audited alongside.
- Cybersecurity outsourcing: buying security operations as a service rather than adopting a standard.
- Data center outsourcing: the infrastructure arrangement these cloud controls govern.
- Web security: protection of web-facing assets, narrower than cloud service security.
- ISO certification: the audit mechanism common to ISO management standards.
- Compliance outsourcing: buying regulatory capability, not cloud controls.
- Security operations outsourcing: delegating detection and response, which these controls assume somebody performs.
FAQ
Is ISO 27017 a certification?
It is guidance rather than a standalone management system, and providers are normally audited against it as part of an ISO 27001 certification rather than separately.
How is it different from ISO 27001?
ISO 27001 specifies the management system. ISO 27017 adds cloud-specific control guidance on top and speaks to customers as well as providers.
What makes it useful in outsourcing?
Its seven new controls all sit at handover points between buyer and provider, which is exactly where outsourced cloud arrangements tend to fail.
Does it cover data privacy?
Only incidentally. Personal data in public clouds is the subject of ISO 27018, which addresses providers acting as processors.
Which edition is current?
A second edition has replaced the original 2015 code of practice, aligning the cloud guidance with the 2022 revision of the underlying controls.
Should I ask a provider for it specifically?
Ask if you buy cloud-delivered services. The seven control areas make a better contract checklist than most procurement templates.
Compare source partners in the Outsource Accelerator hubs directory and confirm which side of the shared model owns each control.







Independent




