ISO/IEC 27017 Cloud Services Information Security

Sets out who is responsible for what between the cloud provider and the cloud customer, and the controls each side must have. Applied on top of ISO/IEC 27001.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

Who this is for

  • Cloud service providers (CSP)
  • Companies running business systems on the cloud (CSC)
  • Companies asked to prove that their cloud use is secure

What certification gives you

  • Removes the argument over whose responsibility it was after an incident

  • Covers cloud-specific risks such as tenant separation and admin operations

  • Ready to present in cloud adoption reviews and customer due diligence