ISO/IEC 27017 Cloud Services Information Security

Sets out who is responsible for what between cloud provider and cloud customer, and the security controls that follow. Certified as an extension of ISO/IEC 27001.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

Most cloud incidents are not break-ins. They come from «we each thought the other one was doing it» — a storage bucket left public, a backup nobody was taking, an administrator account never removed. When that happens, provider and customer point at each other.

ISO/IEC 27017 targets exactly that gap. For every control it requires you to state which part is the provider's job and which part is the customer's. It then adds seven controls that exist only in cloud — isolating your resources from other tenants sharing the same hardware, monitoring privileged administrator activity, and confirming that your data was genuinely deleted when the contract ended.

⚠️ This standard is not certified on its own. It is audited as an extension of ISO/IEC 27001.

Who this is for

  • Cloud service providers (CSPs)
  • Organisations running their systems on cloud (CSCs)
  • Organisations that must demonstrate «our cloud is secure too» to customers

🌱 How this relates to ESG

S Social

Maps onto the S (Social) pillar. Information security and data protection are classified as social by every major ESG framework — the same reasoning as ISO/IEC 27001.

  • Korea's K-ESG guideline, S domain «information protection» — security framework and incident count
  • SASB and MSCI place «Data Security» in the Social pillar, not governance
  • Customer due diligence after cloud migration — answers the question «you moved to cloud, so how is security handled now?»
  • Public-sector cloud programmes accept it as evidence of a security management framework
  • ⚠️ If you also handle personal data, look at ISO/IEC 27018 or 27701 alongside this

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO/IEC 27017Cloud Services Information SecurityP · 조항 27001 4 – 6PlanSet the cloud scopeand split provider…D · 조항 27002 + CLDDoOperate cloudcontrols such as…C · 조항 27001 9CheckReview cloud logsand monitoring;…A · 조항 27001 10ActRemove causes ofincidents and revise…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
BasisISO/IEC 27001 + 27002An information security management system and the general control set underpin this. 27017 is not certified separately.
CLD.6.3.1Shared roles and responsibilitiesDocument, control by control, what the provider does and what the customer does.
CLD.8.1.5Return and removal of assetsWhen the contract ends, customer data is returned and confirmed deleted.
CLD.9.5.1Segregation in virtual environmentsKeep your resources isolated from other tenants sharing the same hardware.
CLD.9.5.2Virtual machine hardeningTurn off unnecessary services and ports, and change insecure defaults.
CLD.12.1.5Administrator operational securityPrivileged administrator work follows a documented procedure and leaves records.
CLD.12.4.5Monitoring of cloud servicesGive the customer the ability to see the state of their own resources.
CLD.13.1.4Virtual and physical network securityKeep virtual network configuration consistent with physical network security policy.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • 🔴 Do you hold ISO/IEC 27001, or are you preparing it in parallel? 27017 cannot be certified alone
  • Is there a responsibility matrix naming «provider / customer» for each control?
  • Is there an inventory of cloud services in use, including SaaS adopted by individual teams?
  • Are administrator accounts attributed to named people, with multi-factor authentication enabled?
  • Is there a record of checking that no storage is publicly exposed? This is the leading cause of cloud incidents
  • Are logs generated and retained — who did what, and when?
  • Do contracts include data return and deletion on termination?
  • Are backups taken, and have you actually restored from one?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
See the 8-step certification process →

You can apply for ISO/IEC 27017 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →