ISO/IEC 27017 Cloud Services Information Security
Sets out who is responsible for what between cloud provider and cloud customer, and the security controls that follow. Certified as an extension of ISO/IEC 27001.
This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →
What this certification proves
Most cloud incidents are not break-ins. They come from «we each thought the other one was doing it» — a storage bucket left public, a backup nobody was taking, an administrator account never removed. When that happens, provider and customer point at each other.
ISO/IEC 27017 targets exactly that gap. For every control it requires you to state which part is the provider's job and which part is the customer's. It then adds seven controls that exist only in cloud — isolating your resources from other tenants sharing the same hardware, monitoring privileged administrator activity, and confirming that your data was genuinely deleted when the contract ended.
⚠️ This standard is not certified on its own. It is audited as an extension of ISO/IEC 27001.
Who this is for
- Cloud service providers (CSPs)
- Organisations running their systems on cloud (CSCs)
- Organisations that must demonstrate «our cloud is secure too» to customers
🌱 How this relates to ESG
S SocialMaps onto the S (Social) pillar. Information security and data protection are classified as social by every major ESG framework — the same reasoning as ISO/IEC 27001.
- Korea's K-ESG guideline, S domain «information protection» — security framework and incident count
- SASB and MSCI place «Data Security» in the Social pillar, not governance
- Customer due diligence after cloud migration — answers the question «you moved to cloud, so how is security handled now?»
- Public-sector cloud programmes accept it as evidence of a security management framework
- ⚠️ If you also handle personal data, look at ISO/IEC 27018 or 27701 alongside this
What certification gives you
- Makes clear where your responsibility ends, so nobody argues after an incidentSee the 8-step process →
- Addresses risks that exist only in cloud — tenant isolation, administrator activityRequest audit duration and fees →
- Establishes a procedure to confirm your data was really deleted when a contract endsCheck a certified organisation →
- Audited on top of ISO/IEC 27001, so the additional burden is modestSee ISO/IEC 27001 →
- If personal data is involved, take 27018 at the same timeSee ISO/IEC 27018 →
How the requirements are structured
This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.
| Clause | Title | In plain terms |
|---|---|---|
| Basis | ISO/IEC 27001 + 27002 | An information security management system and the general control set underpin this. 27017 is not certified separately. |
| CLD.6.3.1 | Shared roles and responsibilities | Document, control by control, what the provider does and what the customer does. |
| CLD.8.1.5 | Return and removal of assets | When the contract ends, customer data is returned and confirmed deleted. |
| CLD.9.5.1 | Segregation in virtual environments | Keep your resources isolated from other tenants sharing the same hardware. |
| CLD.9.5.2 | Virtual machine hardening | Turn off unnecessary services and ports, and change insecure defaults. |
| CLD.12.1.5 | Administrator operational security | Privileged administrator work follows a documented procedure and leaves records. |
| CLD.12.4.5 | Monitoring of cloud services | Give the customer the ability to see the state of their own resources. |
| CLD.13.1.4 | Virtual and physical network security | Keep virtual network configuration consistent with physical network security policy. |
※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.
Before you apply, please check
Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.
- 🔴 Do you hold ISO/IEC 27001, or are you preparing it in parallel? 27017 cannot be certified alone
- Is there a responsibility matrix naming «provider / customer» for each control?
- Is there an inventory of cloud services in use, including SaaS adopted by individual teams?
- Are administrator accounts attributed to named people, with multi-factor authentication enabled?
- Is there a record of checking that no storage is publicly exposed? This is the leading cause of cloud incidents
- Are logs generated and retained — who did what, and when?
- Do contracts include data return and deletion on termination?
- Are backups taken, and have you actually restored from one?
- Have you carried out at least one internal audit yourselves? (required before the audit)
You can apply for ISO/IEC 27017 certification here
Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.
Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317
※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.
Which audit division handles this
Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →
