ISO 27017
About ISO 27017 (Cloud Security Management System)
ISO/IEC 27017 is a code of practice for information security controls based on ISO/IEC 27002, specifically for cloud computing environments. It provides additional guidance for cloud service providers (CSPs) and cloud customers on implementing and maintaining effective cloud-based information security controls.
The standard covers various security controls, including access control, network security, encryption, incident management, and business continuity management. It also includes specific controls related to cloud computing, such as virtualization, multi-tenancy, and data location.
ISO 27017 applies to all types and sizes of organizations, from small businesses to large enterprises, and can be used by CSPs to demonstrate their security capabilities to customers. Cloud customers can also use it to assess CSPs’ security capabilities and ensure that their cloud-based systems and data are adequately protected.
Does your company need it?
ISO 27017 applies to any organization that uses cloud services to store, process, or transmit data.
ISO 27017 is especially relevant for organizations that deal with sensitive information, such as financial data, personal information, and confidential business information. It is also helpful for organizations that rely on cloud services to run their business operations.
Cloud service providers (CSPs) can also benefit from implementing ISO 27017, as it helps them demonstrate their commitment to information security and provide assurance to their customers. Implementing ISO 27017 allows CSPs to differentiate themselves from their competitors and attract customers, prioritizing safety and confidentiality in their cloud services.









