ISO/IEC 27017
ISO/IEC 27017 is an international standard that provides guidance on information security controls for organizations that provide or use cloud services. It is intended to help cloud providers and their customers reduce security risks in cloud-based environments. It offers recommended practices rather than a certifiable control set on its own.
ISO/IEC 27017 is a jointly published ISO and IEC standard that gives guidance for implementing information security controls applicable to the provision and use of cloud services. It builds on ISO/IEC 27002 by supplementing existing controls with cloud-specific implementation guidance and adding controls addressed to both cloud service providers and cloud service customers. It functions as a code of practice and reference for selecting cloud-relevant information security controls; readers should verify the applicable revision (for example, the 2015 edition versus later revisions) against the current authoritative ISO/IEC text, and should note that this standard is distinct from and not a substitute for U.S. federal frameworks such as FedRAMP, FISMA, NIST SP 800-53, or DoD RMF requirements.
Why it matters
Cloud adoption introduces a shared-responsibility model in which security obligations are divided between the cloud service provider and the cloud service customer, and gaps between the two are a persistent source of risk. ISO/IEC 27017 matters because it addresses this divide directly: it supplements the general controls of ISO/IEC 27002 with cloud-specific implementation guidance and adds controls explicitly directed at both providers and customers. For organizations that either deliver or consume cloud services, this helps clarify who is expected to implement which safeguards, reducing the ambiguity that often leads to misconfigured or unowned controls.
For defense and public sector readers, the standard is best understood as a code of practice rather than an independently certifiable control set, and it should not be treated as equivalent to or a substitute for U.S. federal authorities. ISO/IEC 27017 does not confer a FedRAMP authorization, satisfy FISMA obligations, or map one-to-one to NIST SP 800-53 or DoD RMF requirements. An organization that aligns with ISO/IEC 27017 may still need to complete separate assessment and authorization processes to operate a system handling U.S. government data. Conflating international conformance with federal authorization is a common and consequential mistake.
Because the standard has been published in a 2015 edition and may be subject to later revision, readers should verify the applicable version against the current authoritative ISO/IEC text before relying on specific guidance. Using ISO/IEC 27017 as a reference point can strengthen cloud security posture and improve provider-customer alignment, but conformance alone should not be equated with meeting any particular contractual, statutory, or agency-specific compliance requirement.
Who it's relevant to
Inside ISO/IEC 27017
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27017.