• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » ISO 27017

ISO 27017

Definition

ISO 27017

ISO 27017 is the cloud security standard that adds cloud-specific guidance to the general security controls, and it addresses providers and customers together. It exists to settle who owns which control, which is the question outsourcing keeps raising in practice.

Almost every other standard speaks to one party. This one speaks to both — deliberately.

That design choice makes it unusually useful in outsourcing, where the recurring failure is not a missing control but a control each side assumed the other operated.

It is guidance layered on top of the general security controls rather than a standalone management system, which shapes how a provider can be certified against it.

Key takeaways

  • ISO 27017 addresses cloud service providers and cloud service customers in the same document.
  • It adds cloud-specific guidance to existing controls and introduces seven genuinely new ones.
  • The new controls cover the handover points where outsourced arrangements usually fail.
  • Certification is normally audited alongside ISO 27001 rather than on its own.

How it works

ISO 27017 sits on top of the general information security controls. Microsoft records that it provides guidance on 37 controls in ISO/IEC 27002, and it also features seven new controls that are not duplicated elsewhere.

Those seven are the reason the standard matters to anyone buying outsourced cloud work. They are the handover points.

They cover shared roles and responsibilities; removal and return of customer assets when a contract ends; and separating one customer’s virtual environment from another’s.

They also reach virtual machine hardening; procedures for administrative operations; letting customers monitor their own activity; and aligning virtual with physical network security.

Read that list as a contract checklist — and it becomes obvious what it is for. Every item is a place where a buyer and a provider can each assume the other is responsible.

Microsoft also notes the standard is unique in providing guidance for both cloud service providers and cloud service customers, giving customers practical information on what to expect from a provider.

New control areaThe outsourcing question it answers
Shared roles and responsibilitiesWho operates which control
Return of assets on terminationWhat happens to your data when you leave
Virtual environment separationWhether another tenant can reach you
Virtual machine hardeningWho patches what, and when
Administrative operationsWhich provider staff hold privileged access
Customer monitoringWhether you can see your own logs
Virtual and physical network alignmentWhether the two security models agree

The termination row deserves particular attention. Exit provisions are written when a relationship starts — and read when it ends badly.

The shared-responsibility idea is not unique to this standard. AWS describes its own Shared Responsibility Model in the same terms, splitting infrastructure duties from those the customer retains.

Examples

Cloud responsibility disputes follow a predictable pattern, and the standard reads almost like a catalogue of them. Each of these came up in a real contract negotiation rather than a webinar.

A company assumes its provider patches the operating systems on its virtual machines. The provider assumes the customer does, and the hardening control is where that argument gets settled.

A buyer ending a contract asks for its data back and finds no agreed format or deadline. Return of assets on termination exists precisely because data center outsourcing exits are rarely graceful.

A regulated client requires log access so its own team can monitor activity. Without the customer monitoring control, it depends on the provider volunteering evidence.

A security team asks how many provider administrators can reach its environment. The answer sits in administrative operations, and it is frequently larger than expected.

Related terms

Cloud security standards, the services around them and the general security regime are habitually conflated. The terms below carry one sense apiece, with the nearest rival explicitly excluded.

FAQ

Is ISO 27017 a certification?

It is guidance rather than a standalone management system, and providers are normally audited against it as part of an ISO 27001 certification rather than separately.

How is it different from ISO 27001?

ISO 27001 specifies the management system. ISO 27017 adds cloud-specific control guidance on top and speaks to customers as well as providers.

What makes it useful in outsourcing?

Its seven new controls all sit at handover points between buyer and provider, which is exactly where outsourced cloud arrangements tend to fail.

Does it cover data privacy?

Only incidentally. Personal data in public clouds is the subject of ISO 27018, which addresses providers acting as processors.

Which edition is current?

A second edition has replaced the original 2015 code of practice, aligning the cloud guidance with the 2022 revision of the underlying controls.

Should I ask a provider for it specifically?

Ask if you buy cloud-delivered services. The seven control areas make a better contract checklist than most procurement templates.

Compare source partners in the Outsource Accelerator hubs directory and confirm which side of the shared model owns each control.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image