Skip to main content
Category: Cloud Security & Providers

ISO/IEC 27017

Also known as: ISO/IEC 27017:2015, ISO/IEC 27017 Code of Practice for Information Security Controls for Cloud Services
Simply put

ISO/IEC 27017 is an international standard that provides guidance on information security controls for organizations that provide or use cloud services. It is intended to help cloud providers and their customers reduce security risks in cloud-based environments. It offers recommended practices rather than a certifiable control set on its own.

Formal definition

ISO/IEC 27017 is a jointly published ISO and IEC standard that gives guidance for implementing information security controls applicable to the provision and use of cloud services. It builds on ISO/IEC 27002 by supplementing existing controls with cloud-specific implementation guidance and adding controls addressed to both cloud service providers and cloud service customers. It functions as a code of practice and reference for selecting cloud-relevant information security controls; readers should verify the applicable revision (for example, the 2015 edition versus later revisions) against the current authoritative ISO/IEC text, and should note that this standard is distinct from and not a substitute for U.S. federal frameworks such as FedRAMP, FISMA, NIST SP 800-53, or DoD RMF requirements.

Why it matters

Cloud adoption introduces a shared-responsibility model in which security obligations are divided between the cloud service provider and the cloud service customer, and gaps between the two are a persistent source of risk. ISO/IEC 27017 matters because it addresses this divide directly: it supplements the general controls of ISO/IEC 27002 with cloud-specific implementation guidance and adds controls explicitly directed at both providers and customers. For organizations that either deliver or consume cloud services, this helps clarify who is expected to implement which safeguards, reducing the ambiguity that often leads to misconfigured or unowned controls.

For defense and public sector readers, the standard is best understood as a code of practice rather than an independently certifiable control set, and it should not be treated as equivalent to or a substitute for U.S. federal authorities. ISO/IEC 27017 does not confer a FedRAMP authorization, satisfy FISMA obligations, or map one-to-one to NIST SP 800-53 or DoD RMF requirements. An organization that aligns with ISO/IEC 27017 may still need to complete separate assessment and authorization processes to operate a system handling U.S. government data. Conflating international conformance with federal authorization is a common and consequential mistake.

Because the standard has been published in a 2015 edition and may be subject to later revision, readers should verify the applicable version against the current authoritative ISO/IEC text before relying on specific guidance. Using ISO/IEC 27017 as a reference point can strengthen cloud security posture and improve provider-customer alignment, but conformance alone should not be equated with meeting any particular contractual, statutory, or agency-specific compliance requirement.

Who it's relevant to

Cloud Service Providers
Providers can use ISO/IEC 27017 as a reference for implementing and communicating cloud-specific information security controls, including guidance directed specifically at the provider side of the shared-responsibility model. Providers serving U.S. government customers should note that alignment with this standard is distinct from, and does not by itself satisfy, FedRAMP, FISMA, or DoD RMF authorization requirements.
Cloud Service Customers
Customers consuming cloud services can use the standard to identify the security controls that remain their responsibility and to evaluate how a provider addresses cloud-specific risks. This is particularly useful for clarifying the boundaries of the shared-responsibility model, though customers with federal obligations must confirm requirements against the applicable U.S. framework rather than relying on ISO/IEC 27017 alone.
Compliance Officers and Security Managers
Those responsible for governing cloud security programs can reference ISO/IEC 27017 when selecting controls and defining provider-customer responsibilities. They should treat it as a code of practice rather than a certifiable standalone control set, verify the applicable revision against the authoritative ISO/IEC text, and avoid equating conformance with federal authorization or with security itself.
Auditors and Assessors
Assessors evaluating cloud environments may use ISO/IEC 27017 as a benchmark for cloud-specific control implementation and for confirming that responsibilities are appropriately allocated between provider and customer. Assessors working in defense and public sector contexts should distinguish an evaluation against this standard from the separate assessment and authorization processes required under U.S. federal frameworks.

Inside ISO/IEC 27017

Cloud-Specific Control Guidance
ISO/IEC 27017 is a code of practice issued jointly by ISO and IEC that provides implementation guidance for information security controls applicable to the provision and use of cloud services. It supplements the controls found in ISO/IEC 27002 rather than establishing a wholly independent control set.
Supplementary and Cloud-Specific Controls
The standard offers additional implementation guidance for existing ISO/IEC 27002 controls in a cloud context and introduces a set of controls specific to cloud services. Practitioners should confirm the exact controls and their numbering against the current published text, as this guidance may be revised across editions.
Shared Responsibility Perspective
ISO/IEC 27017 generally addresses guidance from the perspectives of both cloud service providers and cloud service customers, helping clarify how security responsibilities may be allocated between the parties in a cloud arrangement.
Relationship to the ISO/IEC 27000 Family
The document is intended to be used in conjunction with an ISO/IEC 27001 information security management system and the ISO/IEC 27002 code of practice. It does not, on its own, define certifiable management system requirements.
Non-Regulatory, Voluntary Standard
As an international consensus standard, ISO/IEC 27017 is voluntary guidance rather than a U.S. federal regulation or authorization program. It is not issued by NIST, CISA, the FedRAMP PMO, or the DoD CIO, and adoption is typically driven by organizational or contractual choice.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27017.

Does an ISO/IEC 27017 certification satisfy U.S. federal or DoD cloud security requirements such as FedRAMP or the DoD RMF?
No. ISO/IEC 27017 is a voluntary international code of practice for cloud service information security controls, developed under the joint ISO/IEC framework, and it is not a U.S. federal authorization. It does not equate to a FedRAMP authorization issued through the FedRAMP PMO process, nor does it satisfy an Authorization to Operate (ATO) granted by an authorizing official under the DoD RMF. Organizations subject to FISMA, FedRAMP, or DoD requirements must meet those authorities separately, and any mapping between ISO/IEC 27017 controls and federal control baselines should be treated as a crosswalk rather than proof of equivalence. Verify specific requirements against the current authoritative federal guidance.
Is ISO/IEC 27017 a standalone standard that can be certified on its own?
Generally, no. ISO/IEC 27017 provides supplementary cloud-specific guidance that is applied in conjunction with ISO/IEC 27002 and implemented within an information security management system built on ISO/IEC 27001. In most implementations it is not audited in isolation; organizations pursue it as an extension to an existing ISO/IEC 27001-based management system. Treating it as an independent, self-sufficient certification is a common misunderstanding. Confirm the current scope and applicability with the applicable ISO/IEC published text and your certification body.
How does ISO/IEC 27017 divide security responsibilities between a cloud service provider and a cloud service customer?
ISO/IEC 27017 generally addresses cloud-specific roles by offering guidance oriented separately toward the cloud service provider and the cloud service customer, reflecting the shared-responsibility nature of cloud environments. In most implementations, the allocation of specific control responsibilities depends on the service model and the agreement between the parties. The standard provides implementation guidance rather than a binding legal allocation, so the precise division should be documented in contractual terms and verified against the current published text.
How can an organization align ISO/IEC 27017 with an existing ISO/IEC 27001 information security management system?
Because ISO/IEC 27017 is designed to supplement ISO/IEC 27002 within an ISO/IEC 27001-based management system, organizations typically incorporate its cloud-specific guidance into their existing control selection, Statement of Applicability, and risk treatment processes rather than standing up a separate program. The specific integration steps depend on organizational scope and certification body expectations. Confirm the applicable requirements against the current ISO/IEC publications.
Can ISO/IEC 27017 be used as a reference when evaluating a cloud provider during procurement?
Organizations often use ISO/IEC 27017 as a reference point when assessing a cloud provider's cloud-specific security practices, since it provides recognized implementation guidance for cloud environments. However, it is non-binding guidance, and the presence of a related certification does not by itself demonstrate compliance with a customer's own regulatory obligations, including any CUI, FISMA, FedRAMP, or DoD requirements that may apply. Procurement decisions should confirm which controls are actually implemented and by which party, and verify obligations against current authoritative sources.
Does aligning with ISO/IEC 27017 mean a cloud environment is secure and compliant?
Not necessarily. Alignment with ISO/IEC 27017 indicates that cloud-specific guidance has been considered within a management system, but compliance with a standard is not the same as security, and it does not guarantee that all applicable legal, contractual, or agency-specific requirements are met. Effective cloud security also depends on ongoing operation, monitoring, and how responsibilities are actually implemented between provider and customer. Readers should confirm current requirements and scope against the applicable official sources and their own regulatory obligations.

Common misconceptions

ISO/IEC 27017 is a standalone standard you can implement or certify against by itself.
It is generally intended to supplement ISO/IEC 27002 and to be used alongside an ISO/IEC 27001 management system. On its own it provides guidance rather than a complete, independently certifiable set of management system requirements; readers should verify how conformity is demonstrated against current official texts.
Adopting ISO/IEC 27017 satisfies U.S. federal or defense cloud compliance obligations such as FedRAMP, FISMA, or DoD RMF requirements.
ISO/IEC 27017 is a voluntary international standard and is distinct from U.S. authorization programs and control catalogs. It does not automatically satisfy FedRAMP authorization, FISMA obligations for civilian agency systems, or DoD RMF requirements for defense or CUI-handling systems. Applicable federal and contractual requirements must be confirmed separately against current authoritative sources.
The standard places security responsibility for cloud services entirely on the cloud service provider.
ISO/IEC 27017 generally frames guidance for both providers and customers, reflecting a shared allocation of responsibilities. Customers typically retain obligations for portions of the control environment, and the specific division should be established in the cloud arrangement rather than assumed.

Best practices

Use ISO/IEC 27017 in conjunction with your ISO/IEC 27001 management system and ISO/IEC 27002 controls rather than treating it as a standalone framework.
Explicitly document the division of security responsibilities between cloud service provider and cloud service customer, using the standard's dual-perspective guidance as a reference point.
Verify the current edition, control inventory, and control numbering against the official ISO/IEC published text before mapping or implementing, since the guidance may be revised.
Do not assume ISO/IEC 27017 conformance meets U.S. federal or defense requirements; confirm FedRAMP, FISMA, and DoD RMF obligations separately against current authoritative sources.
Treat the standard as voluntary guidance and align its use with your organization's contractual and regulatory obligations, which should be independently validated.
Where systems handle CUI or fall under defense or national security scope, coordinate with the responsible authorizing and compliance stakeholders rather than relying on ISO/IEC 27017 alone.