ISO/IEC 27018
ISO/IEC 27018 is an international standard that provides guidance for protecting personal information (referred to as personally identifiable information, or PII) when it is handled in public cloud services. It establishes commonly accepted control objectives, controls, and guidelines that a cloud service provider can implement when it processes such personal data on behalf of its customers. Because it is guidance rather than a binding law or a defense-specific requirement, readers should confirm how it maps to their own regulatory obligations.
ISO/IEC 27018 is a jointly published ISO and IEC standard that establishes commonly accepted control objectives, controls, and guidelines for implementing measures to protect personally identifiable information (PII) in public cloud computing environments, specifically addressing the cloud service provider acting as a PII processor. The standard is structured as a code of practice built upon the broader ISO/IEC 27002 information security controls, extending and supplementing them with cloud- and PII-specific guidance. Multiple revisions exist (the evidence references 2014, 2019, and 2025 editions), so practitioners should verify which revision applies to a given implementation or certification. As an international guidance standard, ISO/IEC 27018 is distinct from and does not by itself satisfy U.S. federal, defense, or CUI-handling requirements such as those under FISMA, FedRAMP, the RMF, or DFARS/CMMC; any such mapping must be confirmed against the applicable authoritative sources.
Why it matters
For organizations that entrust personal data to public cloud services, ISO/IEC 27018 offers a widely recognized reference point for evaluating how a cloud service provider protects personally identifiable information (PII) when acting as a PII processor. Because it establishes commonly accepted control objectives, controls, and guidelines specific to the public cloud context, it gives customers and providers a shared vocabulary for setting expectations around cloud PII handling, and it is frequently cited by major cloud providers as part of their broader compliance posture. This matters for compliance officers and security managers who need to assess third-party cloud services against a consistent, internationally published baseline rather than relying solely on vendor assertions.
Who it's relevant to
Inside ISO/IEC 27018
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27018.