ISO/IEC 27017 is an international standard that provides guidelines for information security controls in cloud services. It focuses on risk management, ensuring confidentiality, integrity and availability of data, and defining the roles and responsibilities of cloud providers and customers. It adapts controls from the ISO/IEC 27002 standard to the specific requirements of the cloud environment, supporting compliance with legal regulations and industry standards.
What is ISO/IEC 27017?
ISO/IEC 27017 is an international standard that provides guidelines for information security controls for cloud services, based on the ISO/IEC 27002 standard. It was published in 2015 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). This standard defines additional safeguards specific to the cloud environment, complementing the controls contained in ISO/IEC 27002.
ISO/IEC 27017 is a response to the growing importance of cloud services and the associated challenges in information security. Cloud services bring numerous advantages, including ease of resource adaptation to current needs, high adaptability and the ability to optimize expenses. However, the cloud model also introduces new challenges and potential risks related to sharing infrastructure among multiple users, the use of virtualization, and the remote nature of access to data and systems.
The ISO/IEC 27017 standard provides comprehensive guidelines that help manage this risk and ensure information security in the cloud environment.
The ISO/IEC 27017 standard is part of the ISO/IEC 27000 family of standards, related to information security management systems (ISMS). This family includes, among others, the popular ISO/IEC 27001 standard (requirements for ISMS) and ISO/IEC 27002 (code of practice for information security). ISO/IEC 27017 extends and complements the controls from ISO/IEC 27002, adapting them to the specifics of cloud services.
Implementation of the ISO/IEC 27017 standard allows cloud service providers to demonstrate commitment to ensuring information security to their customers and compliance with good practices and industry standards. For customers, choosing a provider that meets ISO/IEC 27017 requirements gives greater assurance that their data will be adequately protected in the cloud environment.
📚 Read the complete guide: Cloud Security / AWS: Bezpieczeństwo chmury publicznej - AWS, Azure, best practices
What is the purpose of ISO/IEC 27017?
The main purpose of the ISO/IEC 27017 standard is to ensure information security in cloud services, from both the provider’s and customer’s perspective. The standard provides guidelines that help in:
-
Identifying and managing risk associated with cloud services
-
Ensuring confidentiality, integrity and availability of information processed in the cloud
-
Defining the roles and responsibilities of the provider and customer in terms of information security
-
Ensuring compliance with legal and regulatory requirements regarding data protection
The ISO/IEC 27017 standard aims to provide consistent and harmonized guidelines for the cloud services industry, promoting best practices in information security. By implementing the controls and safeguards described in the standard, cloud service providers can more effectively protect their customers’ data, manage risk and build trust in the market.
For customers, the ISO/IEC 27017 standard is a valuable source of information about cloud security issues and the expectations they should have of providers. Knowledge of the standard’s requirements allows customers to make more informed choices of providers and better understand the division of responsibilities in terms of information security.
Furthermore, the ISO/IEC 27017 standard supports compliance with regulations and laws concerning data protection, such as GDPR (General Data Protection Regulation) in the European Union. Implementation of the controls described in the standard helps cloud service providers meet legal requirements and avoid potential consequences associated with regulatory violations.
In summary, the main purpose of the ISO/IEC 27017 standard is to establish clear and consistent guidelines for ensuring information security in cloud services, benefiting both providers and customers. The standard promotes good practices, helps in risk management and supports regulatory compliance, contributing to the development of trust and security in the cloud industry.
Who developed ISO/IEC 27017?
The ISO/IEC 27017 standard was developed by subcommittee SC 27 “IT Security Techniques” of the ISO/IEC JTC 1 “Information Technology” joint technical committee. Subcommittee SC 27 comprises experts from different countries, representing both standardization organizations and the IT industry.
The process of creating the ISO/IEC 27017 standard was the result of cooperation and consensus among experts from around the world. Specialists in information security, representatives of cloud service providers, customers and other interested parties participated in the development of the standard. This diversity of perspectives allowed key issues and challenges related to information security in the cloud to be incorporated into the standard.
Work on the ISO/IEC 27017 standard began in 2011, and its publication took place in 2015. The ISO/IEC procedures were used in the standard creation process, which ensure transparency, openness and consensus. The draft standard underwent public consultations, during which comments and suggestions were collected from a wide range of stakeholders.
It is worth emphasizing that the ISO/IEC 27017 standard is the result of many years of experience and expert knowledge in the field of information security. It is based on proven practices and standards, such as ISO/IEC 27001 and ISO/IEC 27002, adapting them to the specifics of cloud services. Thanks to this, the standard provides comprehensive and practical guidelines that reflect the current challenges and needs of the cloud industry.
The involvement of leading experts from around the world and a consensus-based process mean that the ISO/IEC 27017 standard enjoys great recognition and trust in the market. It constitutes a valuable reference point for both cloud service providers and their customers, helping to build a secure and sustainable cloud ecosystem.
Who is ISO/IEC 27017 aimed at?
The ISO/IEC 27017 standard is aimed at a wide range of recipients involved in the cloud services ecosystem. The main groups to which the standard is addressed are:
-
Cloud Service Providers (CSPs) who want to ensure information security for their customers
-
Cloud Service Customers (CSCs) who want to ensure that their data is adequately protected
-
Auditors and regulatory bodies assessing the security of cloud services
For cloud service providers, the ISO/IEC 27017 standard is a comprehensive source of guidelines for implementing security controls and risk management in the cloud environment. Implementation of the standard allows providers to demonstrate commitment to ensuring information security, increase customer trust and gain competitive advantage in the market. The standard also helps providers meet legal and regulatory requirements regarding data protection.
For customers using cloud services, knowledge of the ISO/IEC 27017 standard is extremely valuable. It allows for better understanding of cloud security issues and the expectations they should have of providers. Customers can use the standard’s requirements as criteria when choosing a cloud service provider, ensuring that their data will be adequately protected. Additionally, the standard helps customers understand the division of roles and responsibilities in terms of information security between them and the provider.
Auditors and regulatory bodies are also important recipients of the ISO/IEC 27017 standard. The standard provides them with uniform criteria for assessing the security of cloud services and compliance with legal and regulatory requirements. Auditors can use the standard’s requirements as a basis for conducting audits and assessing the information security management system of cloud service providers. Regulatory bodies, on the other hand, can refer to the standard when creating regulations and guidelines concerning cloud security.
It is also worth mentioning that the ISO/IEC 27017 standard can be useful for other interested parties, such as:
-
System integrators and consultants, helping organizations implement cloud services
-
Insurers, assessing the risk associated with cloud services
-
Academic and research environments, interested in the development of cloud security standards
In summary, the ISO/IEC 27017 standard is aimed at all entities involved in the cloud services ecosystem, providing them with valuable guidelines and tools to ensure information security. Its universal character makes it useful for both providers and customers, auditors and regulatory bodies, contributing to building trust and promoting good practices in the cloud industry.
What standard is ISO/IEC 27017 based on?
ISO/IEC 27017 is based on the ISO/IEC 27002 standard, which provides general guidelines for information security controls. ISO/IEC 27002 is part of the ISO/IEC 27000 family of standards, related to information security management systems (ISMS). ISO/IEC 27017 extends and complements the controls from ISO/IEC 27002, adapting them to the specifics of cloud services.
The ISO/IEC 27002 standard contains a collection of best practices and guidelines concerning information security, divided into 14 security areas. These include, among others, information security policy, organization of information security, asset management, access control, cryptography, physical and environmental security, operations security, communications security, system acquisition, development and maintenance, supplier relationships, information security incident management, business continuity management and compliance.
ISO/IEC 27017 is based on the structure and controls defined in ISO/IEC 27002, adapting them to the context of cloud services. This standard extends the existing guidelines with additional protection mechanisms, taking into account the unique features of the cloud environment, such as shared infrastructure, virtualization, remote access and the distribution of responsibilities between the service provider and service recipient.
The connection between ISO/IEC 27017 and ISO/IEC 27002 has several key advantages:
-
Consistency and compatibility: Thanks to being based on ISO/IEC 27002, the ISO/IEC 27017 standard maintains consistency with general principles and information security controls. This facilitates integration with existing information security management systems based on ISO/IEC 27001 and ISO/IEC 27002.
-
Extension and adaptation: ISO/IEC 27017 extends the controls from ISO/IEC 27002, adding guidelines specific to cloud services. This allows for consideration of unique challenges and threats related to data processing in the cloud, while maintaining compliance with general information security principles.
-
Comprehensiveness and practicality: Thanks to the combination of general controls from ISO/IEC 27002 and additional cloud-specific guidelines, ISO/IEC 27017 provides comprehensive and practical guidance for ensuring information security in cloud services. The standard covers a wide range of security aspects, from technical to organizational and legal issues.
-
Facilitation of implementation: Organizations that have already implemented or plan to implement an information security management system based on ISO/IEC 27001 and ISO/IEC 27002 can more easily adapt to the requirements of ISO/IEC 27017. Knowledge of the structure and controls from ISO/IEC 27002 facilitates understanding and implementation of additional cloud-specific safeguards.
In summary, ISO/IEC 27017 is based on the solid foundations of the ISO/IEC 27002 standard, extending and adapting its controls to the specifics of cloud services. This approach ensures consistency, compatibility and comprehensiveness in information security management in the cloud environment, while taking into account the unique challenges and threats associated with this technology.
What additional safeguards does ISO/IEC 27017 introduce compared to ISO/IEC 27002?
The ISO/IEC 27017 standard introduces 7 additional safeguards, specific to cloud services, which are not included in ISO/IEC 27002. These safeguards are intended to take into account the unique challenges and threats associated with data processing in the cloud environment. Here is a detailed discussion of these additional safeguards:
-
Division of roles and responsibilities in the cloud environment: ISO/IEC 27017 requires clear definition and documentation of the division of roles and responsibilities in terms of information security between the cloud service provider and the customer. The standard emphasizes the importance of precisely defining the scope of responsibility of each party, which allows avoiding misunderstandings and gaps in security.
-
Removal and return of customer assets after contract termination: The standard introduces requirements for secure removal and return of data and other customer assets after termination of the contract with the cloud service provider. The provider must ensure that all customer data is permanently deleted from cloud systems, and any physical data media is securely destroyed or returned to the customer.
-
Protection and separation of customer virtual environment: ISO/IEC 27017 emphasizes ensuring appropriate separation and protection of the customer’s virtual environment in the cloud. The cloud service provider must implement mechanisms that guarantee that one customer’s data and resources will not be accessible to other customers, even in the case of sharing physical infrastructure.
-
Requirements for virtual machine security: The standard introduces detailed requirements for securing virtual machines in the cloud environment. These include, among others, access control, encryption, integrity monitoring, regular updates and vulnerability management. The cloud service provider must ensure that virtual machines are appropriately configured and protected against unauthorized access and manipulation.
-
Operational security of cloud environment administration: ISO/IEC 27017 draws attention to operational security related to cloud environment administration. The cloud service provider must implement appropriate procedures and control mechanisms to ensure that administrative activities are performed in a secure manner and in compliance with the security policy. This includes, among others, administrative access control, monitoring and logging of administrator activities, and regular reviews of permissions.
-
Monitoring of cloud services by the customer: The standard emphasizes the customer’s right to monitor cloud services in terms of security and compliance with the contract. The cloud service provider should provide the customer with appropriate tools and mechanisms that enable monitoring and control over their data and resources in the cloud. This may include access to logs, security reports or the ability to conduct audits.
-
Adaptation of security management for virtual and physical networks: ISO/IEC 27017 draws attention to the need to adapt security management to the specifics of virtual and physical networks in the cloud environment. The cloud service provider must ensure appropriate mechanisms for network segmentation, access control and monitoring to protect customer data and resources from unauthorized access and attacks.
The introduction of these additional safeguards in the ISO/IEC 27017 standard is intended to take into account the specific challenges and threats associated with cloud services. Thanks to these safeguards, cloud service providers can ensure their customers a higher level of security and data protection, and customers gain greater transparency and control over their resources in the cloud.
It is worth emphasizing that the additional safeguards introduced by ISO/IEC 27017 do not replace, but complement the controls from ISO/IEC 27002. The ISO/IEC 27017 standard should be used in conjunction with ISO/IEC 27002, which allows for a comprehensive approach to information security management in cloud services.
What areas do ISO/IEC 27017 guidelines cover?
The ISO/IEC 27017 standard guidelines cover 18 areas of information security, analogous to the structure of ISO/IEC 27002. These areas represent key aspects of information security management in cloud services. Here is a detailed discussion of each of these areas:
-
Information security policy: This area concerns the establishment, implementation and maintenance of an information security policy that defines the organization’s approach to managing information security in cloud services. The policy should be adapted to the specifics of the cloud and take into account the division of roles and responsibilities between the provider and the customer.
-
Organization of information security: In this area, the standard focuses on establishing an information security management structure in the organization, including defining roles, responsibilities and authorities. It is important to take into account the specifics of cloud services and ensure appropriate coordination between the provider and the customer.
-
Human resource security: This area includes guidelines for ensuring that employees, contractors and external users understand their responsibilities and are appropriately trained in information security. In the context of the cloud, it is important to include specific requirements regarding access and training for cloud service provider personnel.
-
Asset management: In this area, the standard focuses on identification, inventory and appropriate protection of information assets in the cloud. This includes both customer and cloud service provider assets. It is important to define asset ownership and ensure their protection throughout the lifecycle.
-
Access control: This area concerns managing user access to information and systems in the cloud. The standard requires implementation of appropriate authentication, authorization and access control mechanisms, adapted to the specifics of cloud services. Regular review and updating of access rights is also important.
-
Cryptography: In this area, the standard focuses on the proper use of cryptography to protect the confidentiality, integrity and availability of information in the cloud. This includes selection of appropriate cryptographic algorithms and tools, key management and ensuring compliance with legal and regulatory requirements.
-
Physical and environmental security: This area concerns the physical protection of cloud infrastructure and ensuring appropriate environmental conditions. The standard requires implementation of physical access controls, monitoring and protection against environmental threats such as fire, flooding or power failures.
-
Operations security: In this area, the standard focuses on ensuring security of operations in the cloud, including change management, monitoring, event logging and incident response. It is important to establish appropriate procedures and control mechanisms, adapted to the specifics of cloud services.
-
Communications security: This area concerns the protection of information transmitted over networks in the cloud. The standard requires implementation of appropriate security mechanisms, such as encryption, authentication and integrity control, to ensure confidentiality and integrity of data during transmission.
-
System acquisition, development and maintenance: In this area, the standard focuses on ensuring security during acquisition, development and maintenance of cloud systems. This includes incorporating security requirements in the system lifecycle, security testing, vulnerability management and secure programming practices.
-
Supplier relationships: This area concerns managing information security in relationships with cloud service providers. The standard requires establishment of appropriate contracts and agreements that define security requirements, service levels and the division of roles and responsibilities. Regular monitoring and review of provider activities is also important.
-
Information security incident management: In this area, the standard focuses on establishing an effective information security incident management process in the cloud. This includes identification, reporting, assessment, response and learning from incidents. Cooperation between the provider and the customer in incident handling is important.
-
Business continuity management: This area concerns ensuring business continuity of cloud services and the ability to restore availability and access to information after disruptions. The standard requires development and testing of business continuity plans, taking into account the specifics of the cloud and the division of roles and responsibilities between the provider and the customer.
-
Compliance: In this area, the standard focuses on ensuring compliance of cloud services with legal, regulatory and contractual requirements. This includes identification of relevant requirements, implementation of control mechanisms and regular compliance reviews and audits.
For each of these areas, the ISO/IEC 27017 standard provides additional guidelines, specific to the cloud environment. These guidelines take into account unique challenges and threats associated with cloud services, such as multi-tenancy, virtualization, remote access or the division of responsibilities between the provider and the customer.
It is worth emphasizing that the ISO/IEC 27017 standard guidelines do not replace, but complement and extend the controls from ISO/IEC 27002. Organizations implementing ISO/IEC 27017 should use it in conjunction with ISO/IEC 27002 to ensure a comprehensive approach to information security management in cloud services.
In summary, the ISO/IEC 27017 standard guidelines cover a wide range of information security areas, adapted to the specifics of cloud services. Implementation of these guidelines allows organizations to effectively manage risk, protect data and ensure compliance with legal and regulatory requirements in the cloud environment.
What is the structure of ISO/IEC 27017?
The ISO/IEC 27017 standard consists of the following main parts:
-
Scope of the standard: This part defines the scope and objectives of the ISO/IEC 27017 standard. It explains that the standard provides guidelines for information security controls for cloud services, based on the ISO/IEC 27002 standard.
-
Normative references: This part lists the normative documents to which the ISO/IEC 27017 standard refers, such as ISO/IEC 27000 (vocabulary and definitions) and ISO/IEC 27002 (code of practice for information security).
-
Terms and definitions: This part contains terms and definitions used in the ISO/IEC 27017 standard. This includes both terms defined in ISO/IEC 27000 and additional terms specific to cloud services.
-
Concepts specific to the cloud sector: In this part, the standard introduces key concepts and principles related to information security in cloud services. It discusses the specifics of the cloud, service models (IaaS, PaaS, SaaS) and the division of roles and responsibilities between the provider and the customer.
-
Information security policies: This part of the standard provides guidelines for establishing, implementing and maintaining an information security policy in the context of cloud services. It emphasizes the importance of adapting the policy to the specifics of the cloud and taking into account the division of roles and responsibilities between the provider and the customer.
-
Organization of information security: In this part, the standard focuses on establishing an information security management structure in the organization, taking into account the specifics of cloud services. It discusses roles, responsibilities and authorities and emphasizes the importance of coordination between the provider and the customer.
-
Human resource security: This part of the standard provides guidelines for ensuring that employees, contractors and external users understand their responsibilities and are appropriately trained in information security in the context of the cloud.
-
Asset management: In this part, the standard focuses on identification, inventory and appropriate protection of information assets in the cloud, both on the customer and cloud service provider side.
-
Access control: This part of the standard provides guidelines for managing user access to information and systems in the cloud, taking into account specific requirements and access control mechanisms in the cloud environment.
-
Cryptography: In this part, the standard focuses on the proper use of cryptography to protect the confidentiality, integrity and availability of information in the cloud, including the selection of appropriate cryptographic algorithms and tools.
-
Physical and environmental security: This part of the standard provides guidelines for the physical protection of cloud infrastructure and ensuring appropriate environmental conditions.
-
Operations security: In this part, the standard focuses on ensuring security of operations in the cloud, including change management, monitoring, event logging and incident response.
-
Communications security: This part of the standard provides guidelines for protecting information transmitted over networks in the cloud, including encryption, authentication and integrity control.
-
System acquisition, development and maintenance: In this part, the standard focuses on ensuring security during acquisition, development and maintenance of cloud systems, taking into account specific security requirements in the system lifecycle.
-
Supplier relationships: This part of the standard provides guidelines for managing information security in relationships with cloud service providers, including establishing appropriate contracts and agreements and monitoring provider activities.
-
Information security incident management: In this part, the standard focuses on establishing an effective information security incident management process in the cloud, taking into account cooperation between the provider and the customer.
-
Information security aspects in business continuity management: This part of the standard provides guidelines for ensuring business continuity of cloud services and the ability to restore availability and access to information after disruptions.
-
Compliance: In this part, the standard focuses on ensuring compliance of cloud services with legal, regulatory and contractual requirements, including identification of relevant requirements and implementation of control mechanisms.
Additionally, the standard contains two annexes:
- Annex A - Extended safeguards for cloud services: This annex contains additional safeguards specific to cloud services that complement the controls from ISO/IEC 27002. This includes, among others, division of roles and responsibilities, removal and return of customer assets, protection of customer virtual environment or monitoring of cloud services by the customer.
- Annex B - References to information security risk in the context of cloud processing: This annex provides additional information and guidelines concerning information security risk management in cloud services. It discusses specific risk factors associated with the cloud and approaches to their assessment and handling.
The structure of the ISO/IEC 27017 standard is consistent with other standards from the ISO/IEC 27000 family, which facilitates its integration with existing information security management systems. Individual parts of the standard provide detailed guidelines for different areas of information security, adapted to the specifics of cloud services.
It is worth emphasizing that the ISO/IEC 27017 standard should be used in conjunction with ISO/IEC 27002, which provides general guidelines for information security controls. ISO/IEC 27017 extends and complements these controls with specific requirements for the cloud environment.
In summary, the structure of the ISO/IEC 27017 standard is logical, comprehensive and adapted to the needs of information security management in cloud services. It provides practical guidelines for organizations, helping them effectively implement and maintain information security in the cloud.
Is ISO/IEC 27017 mandatory for cloud service providers?
The ISO/IEC 27017 standard is not legally mandatory, however its implementation is highly recommended for cloud service providers. Implementation of the standard allows demonstration of commitment to ensuring customer information security and compliance with good practices and industry standards.
Although the ISO/IEC 27017 standard does not have legal force, there are situations in which its implementation may be required or expected:
-
Customer requirements: Some customers, especially large organizations or government institutions, may require cloud service providers to comply with the ISO/IEC 27017 standard as a condition of cooperation. Meeting the standard’s requirements may be perceived as a guarantee of an appropriate level of information security.
-
Sector regulations: In some industries, such as finance, healthcare or the public sector, there may be specific regulations or guidelines that require cloud service providers to apply certain security standards, including ISO/IEC 27017.
-
Legal requirements: Although the ISO/IEC 27017 standard itself is not legally mandatory, some of its elements may be required by regulations concerning personal data protection, such as GDPR (General Data Protection Regulation) in the European Union. Implementation of the standard can help meet these legal requirements.
-
Industry good practices: Implementation of ISO/IEC 27017 is recognized as good practice in the cloud services industry. Providers who comply with the standard’s requirements are perceived as more credible and responsible, which can translate into competitive advantage in the market.
It is also worth noting that some organizations may require cloud service providers to be certified for compliance with the ISO/IEC 27017 standard by an independent certification body. Certification is formal confirmation that the provider’s information security management system meets the standard’s requirements and is regularly audited.
In summary, although the ISO/IEC 27017 standard is not legally mandatory, its implementation is highly recommended for cloud service providers. Meeting the standard’s requirements may be expected by customers, regulators or result from industry good practices. Implementation of ISO/IEC 27017 allows providers to demonstrate commitment to ensuring information security, build customer trust and gain competitive advantage in the market.
What benefits does implementing ISO/IEC 27017 bring to cloud service providers?
Implementation of the ISO/IEC 27017 standard brings cloud service providers numerous benefits, contributing to improved information security, increased customer trust and gaining competitive advantage in the market. Here is a detailed discussion of the key benefits:
-
Increased customer trust: Implementation of ISO/IEC 27017 allows cloud service providers to demonstrate commitment to ensuring the information security of their customers. By meeting the standard’s requirements, providers show that they treat customer data protection as a priority and apply industry best practices. This builds customer trust and gives them confidence that their information is adequately protected.
-
Reduction of information security risk: The ISO/IEC 27017 standard provides comprehensive guidelines for managing information security risk in cloud services. Implementation of the controls and safeguards described in the standard allows providers to identify, assess and effectively mitigate risk associated with data processing in the cloud. This reduces the likelihood of security incidents, data breaches or other negative consequences.
-
Improvement of company image and reputation: Cloud service providers who implement ISO/IEC 27017 gain better reputation in the market. Compliance with a recognized international information security standard demonstrates professionalism, responsibility and care for customer interests. This can attract new customers who are looking for credible and secure cloud solutions.
-
Increased competitive advantage: In the face of growing competition in the cloud services market, implementation of ISO/IEC 27017 can give providers significant advantage over competitors. Customers often prefer providers who can demonstrate compliance with recognized security standards. Having an ISO/IEC 27017 certificate can be a deciding factor when choosing a provider, especially in the case of large, demanding customers.
-
Meeting customer requirements and sector regulations: Implementation of ISO/IEC 27017 helps cloud service providers meet specific security requirements set by customers or sector regulations. Some customers, especially large organizations or government institutions, may require provider compliance with the standard as a condition of cooperation. Similarly, in some industries, such as finance or healthcare, there are specific regulations concerning information security that can be met through implementation of ISO/IEC 27017.
-
Optimization of information security processes: The ISO/IEC 27017 standard provides structured guidelines and best practices for managing information security in the cloud. Implementation of the standard allows providers to optimize security processes, streamline operations and more effectively use resources. Thanks to the standard approach, providers can avoid duplication of efforts and focus on key security aspects.
-
Possibility of obtaining compliance certificate: Cloud service providers who implement ISO/IEC 27017 can apply for a compliance certificate with the standard, issued by independent certification bodies. The certificate is formal confirmation that the provider’s information security management system meets the standard’s requirements and is regularly audited. Having a certificate strengthens the provider’s credibility and can be a significant asset in customer relations and in tenders.
-
Continuous improvement of information security: Implementation of ISO/IEC 27017 is not a one-time action, but the beginning of a continuous process of improving information security. The standard requires regular reviews, audits and corrective actions, which allows providers to constantly monitor and improve their security management system. Thanks to this, providers can adapt to changing threats and maintain a high level of customer data protection.
In summary, implementation of the ISO/IEC 27017 standard brings cloud service providers many measurable benefits. It increases customer trust, reduces information security risk, improves company image and reputation, increases competitive advantage, helps meet customer requirements and sector regulations, optimizes security processes, provides the possibility of obtaining a compliance certificate and supports continuous improvement of information security. All this translates into a better market position for the provider and greater customer satisfaction.
What benefits does knowledge of ISO/IEC 27017 bring to cloud service customers?
Knowledge of the ISO/IEC 27017 standard brings customers using cloud services many significant benefits. It allows them to better understand information security issues in the cloud, make more informed provider choices and more effectively protect their data. Here is a detailed discussion of the key benefits:
-
Better understanding of cloud security issues: The ISO/IEC 27017 standard provides comprehensive guidelines for information security in cloud services. Knowledge of the standard allows customers to better understand specific threats, risks and challenges associated with data processing in the cloud. Customers gain knowledge about key security areas, such as access management, encryption, data protection or business continuity, which helps them make informed decisions about using cloud services.
-
More informed choice of cloud service provider: Knowledge of ISO/IEC 27017 requirements allows customers to make more informed choices of cloud service providers. Customers can use the standard’s requirements as criteria for evaluating and comparing different providers. By choosing a provider who declares compliance with ISO/IEC 27017 or has a compliance certificate, customers gain greater confidence that their data will be adequately protected according to industry best practices.
-
Clear definition of roles and responsibilities: The ISO/IEC 27017 standard places great emphasis on clearly defining roles and responsibilities in terms of information security between the cloud service provider and the customer. Knowledge of the standard allows customers to better understand the division of tasks and responsibilities, which is particularly important in the shared responsibility model characteristic of the cloud. Customers know which security aspects the provider is responsible for and which they themselves are responsible for, which allows for more effective data protection.
-
Increased trust in the provider: By choosing a cloud service provider who complies with ISO/IEC 27017 requirements, customers gain greater trust in their security practices. Compliance with a recognized international standard demonstrates the provider’s commitment to protecting customer data and using proven control mechanisms. This increases customer confidence that their information is adequately secured and that the provider treats security as a priority.
-
Facilitation of meeting own legal and regulatory requirements: Customers using cloud services often must meet various legal and regulatory requirements concerning data protection, such as GDPR in the European Union. Knowledge of the ISO/IEC 27017 standard helps customers understand how the standard’s requirements support regulatory compliance. By choosing a provider who complies with ISO/IEC 27017, customers gain confidence that the control mechanisms and safeguards implemented by them contribute to meeting their own legal obligations.
-
Ability to audit and monitor the provider: The ISO/IEC 27017 standard provides for the possibility of audit and monitoring of the cloud service provider by the customer. Knowledge of the standard’s requirements allows customers to more effectively enforce their rights in terms of security control. Customers can demand that the provider provide audit results, compliance reports or other evidence confirming compliance with the standard’s requirements, which gives them greater transparency and control over the security of their data.
-
Support in negotiations and contract signing: Knowledge of the ISO/IEC 27017 standard can be useful for customers during negotiations and signing contracts with cloud service providers. Customers can refer to the standard’s requirements when defining expectations regarding information security, service levels or provider commitments. Contracts based on ISO/IEC 27017 standards give customers greater confidence that their interests are adequately protected.
-
Continuous improvement of information security: The ISO/IEC 27017 standard promotes an approach based on continuous improvement of information security. Knowledge of the standard’s requirements allows customers to better understand how the cloud service provider should monitor, review and improve their security management system. Customers can expect regular updates, reports and information from the provider about improvement activities, which gives them confidence that their data is constantly protected according to the latest standards.
In summary, knowledge of the ISO/IEC 27017 standard gives customers using cloud services many significant benefits. It allows for better understanding of cloud security issues, more informed provider choice, clear definition of roles and responsibilities, increased trust in the provider, facilitation of meeting own legal and regulatory requirements, ability to audit and monitor the provider, support in negotiations and contract signing, and ensuring continuous improvement of information security. All this translates into more effective protection of customer data and greater trust in cloud services.
Is ISO/IEC 27017 compatible with other ISO 27000 family standards?
Yes, the ISO/IEC 27017 standard is fully compatible with other standards from the ISO/IEC 27000 family, which includes standards concerning information security management systems (ISMS). This compatibility results from the fact that ISO/IEC 27017 is an extension and complement of general guidelines contained in other standards from this family, in particular in ISO/IEC 27001 and ISO/IEC 27002.
Here is a discussion of the compatibility of ISO/IEC 27017 with key standards from the ISO/IEC 27000 family:
-
ISO/IEC 27001 - Information security management systems - Requirements: ISO/IEC 27001 defines requirements for establishing, implementing, maintaining and continuously improving an ISMS in an organization. ISO/IEC 27017 is fully compliant with ISO/IEC 27001 and can be integrated with an existing ISMS based on this standard. Implementation of ISO/IEC 27017 allows for extending the scope of the ISMS with specific requirements concerning information security in cloud services.
-
ISO/IEC 27002 - Code of practice for information security controls: ISO/IEC 27002 provides guidelines and general principles for initiating, implementing, maintaining and improving information security management in an organization. ISO/IEC 27017 is directly related to ISO/IEC 27002 and is based on its structure and controls. ISO/IEC 27017 extends and complements the guidelines from ISO/IEC 27002 with specific requirements for cloud services, ensuring consistency and compatibility between these standards.
-
ISO/IEC 27018 - Code of practice for protection of personally identifiable information in public clouds acting as PII processors: ISO/IEC 27018 provides additional guidelines for cloud service providers who process personal data on behalf of their customers. ISO/IEC 27017 is compatible with ISO/IEC 27018 and can be used together with this standard. Both standards complement each other, ensuring a comprehensive approach to personal data protection in the cloud.
-
Other standards from the ISO/IEC 27000 family: ISO/IEC 27017 is also compatible with other standards from the ISO/IEC 27000 family, such as ISO/IEC 27005 (information security risk management), ISO/IEC 27031 (business continuity assurance) or ISO/IEC 27035 (information security incident management). Implementation of ISO/IEC 27017 can be integrated with existing management systems based on these standards, ensuring a consistent and comprehensive approach to information security.
Compatibility of ISO/IEC 27017 with other standards from the ISO/IEC 27000 family has many advantages:
-
Facilitates integration and implementation: Organizations that already apply other standards from the ISO/IEC 27000 family can more easily implement ISO/IEC 27017, using existing structures, processes and documentation. Integration of ISO/IEC 27017 with an existing ISMS is smooth and does not require fundamental changes.
-
Ensures consistency and comprehensiveness: Thanks to compatibility with other standards, ISO/IEC 27017 ensures a consistent and comprehensive approach to information security management. Organizations can benefit from synergies between different standards, avoiding duplication of efforts and ensuring that all key security aspects are taken into account.
-
Facilitates communication and cooperation: Compatibility of ISO/IEC 27017 with other standards facilitates communication and cooperation between different stakeholders, such as cloud service providers, customers, auditors or regulatory bodies. Common understanding and reference to recognized standards helps build trust and understanding.
-
Supports continuous improvement: The ISO/IEC 27000 family of standards is based on the PDCA (Plan-Do-Check-Act) model, which promotes continuous improvement. Compatibility of ISO/IEC 27017 with other standards allows organizations to consistently apply this approach, enabling constant monitoring, review and improvement of the information security management system.
In summary, the ISO/IEC 27017 standard is fully compatible with other standards from the ISO/IEC 27000 family, in particular with ISO/IEC 27001 and ISO/IEC 27002. This compatibility facilitates integration and implementation, ensures consistency and comprehensiveness, facilitates communication and cooperation, and supports continuous improvement. Organizations applying ISO/IEC 27017 can benefit from synergies with other standards, obtaining a comprehensive and effective approach to information security management in cloud services.
Can you obtain a certificate of compliance with ISO/IEC 27017?
Yes, it is possible to obtain a certificate of compliance with the ISO/IEC 27017 standard. Certification is a process in which an independent, accredited certification body conducts an audit of an organization’s information security management system (ISMS) for compliance with the requirements of the ISO/IEC 27017 standard. Obtaining a certificate confirms that the organization’s ISMS is compliant with the standard’s requirements and is effectively implemented.
Certification of compliance with ISO/IEC 27017 is particularly important for cloud service providers who want to demonstrate to their customers and other stakeholders that they apply best practices in information security. The certificate is recognized worldwide and constitutes credible confirmation that the provider meets international security standards.
The certification process for compliance with ISO/IEC 27017 includes the following steps:
-
Implementation of ISMS compliant with standard requirements: The organization must establish, implement, maintain and continuously improve an ISMS that meets the requirements of ISO/IEC 27017. This includes developing policies, procedures, control mechanisms and documentation in accordance with the standard’s guidelines.
-
Selection of accredited certification body: The organization selects an independent certification body that is accredited to conduct compliance audits with ISO/IEC 27017. Accreditation is confirmation that the body has appropriate competence, independence and recognition. The choice of body may be based on factors such as experience, reputation, scope of accreditation or service costs.
-
Documentation review and preliminary audit (optional): Before the actual certification audit, the organization may decide to have its ISMS documentation reviewed by the certification body. This review allows for preliminary assessment of documentation compliance with standard requirements and identification of any gaps. The organization may also use an optional preliminary audit, which simulates the course of the certification audit and helps identify areas requiring improvement.
-
Certification audit: The key stage of the certification process is the certification audit conducted by the certification body. The audit includes review of documentation, interviews with personnel, observations and tests to verify that the ISMS is compliant with ISO/IEC 27017 requirements and is effectively implemented. Auditors assess, among others, policies, procedures, control mechanisms, risk management, monitoring and continuous improvement of the ISMS. The audit can be conducted on-site or remotely, depending on agreements between the organization and the certification body.
-
Audit report and corrective actions: After completion of the certification audit, the certification body prepares a report that contains the audit results, including any non-conformities or areas requiring improvement. Non-conformities are classified as minor or major, depending on their impact on ISMS effectiveness. The organization has the opportunity to implement corrective actions to eliminate non-conformities before the certificate is issued. These actions must be documented and verified by the certification body.
-
Certificate issuance: If the audit results are positive and all non-conformities have been eliminated, the certification body issues a certificate of compliance with ISO/IEC 27017. The certificate is typically valid for three years, subject to conducting annual surveillance audits to verify continued compliance.
-
Surveillance audits and recertification: During the certificate’s validity period, the certification body conducts annual surveillance audits to ensure that the organization’s ISMS still meets ISO/IEC 27017 requirements and is effectively maintained. After three years, the organization must undergo the recertification process to renew the certificate for another three years.
Obtaining a certificate of compliance with ISO/IEC 27017 brings organizations many benefits:
-
Increases customer and other stakeholder trust, demonstrating commitment to information security.
-
Confirms that the organization’s ISMS meets international standards and good practices.
-
Facilitates meeting legal and regulatory requirements concerning data protection.
-
Distinguishes the organization from the competition and may be required in tenders and contracts.
-
Supports continuous improvement of ISMS through regular audits and reviews.
It is worth noting that certification of compliance with ISO/IEC 27017 is not mandatory, but constitutes a voluntary commitment of the organization to meet the standard’s requirements. The decision to apply for certification depends on individual needs, customer requirements and the organization’s business strategy.
In summary, obtaining a certificate of compliance with the ISO/IEC 27017 standard is possible and constitutes valuable confirmation that the organization’s ISMS meets international information security standards in cloud services. The certification process includes implementation of ISMS compliant with standard requirements, selection of an accredited certification body, certification audit, corrective actions and regular surveillance audits. Certification brings organizations many benefits, such as increased customer trust, meeting legal and regulatory requirements, and standing out from the competition.
What does the ISO/IEC 27017 certification process look like?
The certification process for compliance with the ISO/IEC 27017 standard includes several key stages that are designed to verify that the organization’s information security management system (ISMS) meets the standard’s requirements and is effectively implemented. Here is a detailed discussion of the individual steps of the certification process:
-
Implementation of ISMS compliant with standard requirements: The first step is to establish, implement, maintain and continuously improve an ISMS that meets the requirements of ISO/IEC 27017. The organization must develop policies, procedures, control mechanisms and documentation in accordance with the standard’s guidelines. This includes, among others, conducting risk assessment, defining the scope of the ISMS, establishing roles and responsibilities, implementing technical and organizational safeguards, and providing personnel training.
-
Selection of accredited certification body: The organization selects an independent certification body that is accredited to conduct compliance audits with ISO/IEC 27017. Accreditation is confirmation that the body has appropriate competence, independence and recognition. The choice of body may be based on factors such as experience, reputation, scope of accreditation or service costs.
-
Documentation review and preliminary audit (optional): Before the actual certification audit, the organization may decide to have its ISMS documentation reviewed by the certification body. This review allows for preliminary assessment of documentation compliance with standard requirements and identification of any gaps. The organization may also use an optional preliminary audit, which simulates the course of the certification audit and helps identify areas requiring improvement.
-
Certification audit: The key stage of the certification process is the certification audit conducted by the certification body. The audit includes review of documentation, interviews with personnel, observations and tests to verify that the ISMS is compliant with ISO/IEC 27017 requirements and is effectively implemented. Auditors assess, among others, policies, procedures, control mechanisms, risk management, monitoring and continuous improvement of the ISMS. The audit can be conducted on-site or remotely, depending on agreements between the organization and the certification body.
-
Audit report and corrective actions: After completion of the certification audit, the certification body prepares a report that contains the audit results, including any non-conformities or areas requiring improvement. Non-conformities are classified as minor or major, depending on their impact on ISMS effectiveness. The organization has the opportunity to implement corrective actions to eliminate non-conformities before the certificate is issued. These actions must be documented and verified by the certification body.
-
Certificate issuance: If the audit results are positive and all non-conformities have been eliminated, the certification body issues a certificate of compliance with ISO/IEC 27017. The certificate is typically valid for three years, subject to conducting annual surveillance audits to verify continued compliance. The certificate contains information such as the organization’s name, scope of certification, issue date and expiration date.
-
Surveillance audits: During the certificate’s validity period, the certification body conducts annual surveillance audits to ensure that the organization’s ISMS still meets ISO/IEC 27017 requirements and is effectively maintained. Surveillance audits are less detailed than the certification audit, but include review of key areas of the ISMS, verification of corrective actions from previous audits and assessment of continuous improvement.
-
Recertification: After three years from the certificate issuance, the organization must undergo the recertification process to renew the certificate for another three years. The recertification process is similar to the initial certification audit and includes a full review of the ISMS for compliance with the current version of the ISO/IEC 27017 standard.
It is worth noting that the certification process requires commitment and cooperation on the part of the organization. The organization must provide access to documentation, personnel and systems and actively participate in corrective and improvement actions. Communication and cooperation with the certification body are key to the smooth running of the certification process.
In summary, the certification process for compliance with the ISO/IEC 27017 standard includes implementation of ISMS compliant with standard requirements, selection of an accredited certification body, certification audit, corrective actions, certificate issuance and regular surveillance audits and recertification. This process ensures that the organization’s ISMS meets international information security standards in cloud services and is effectively maintained over time.
How much does ISO/IEC 27017 certification cost?
The cost of certification for compliance with the ISO/IEC 27017 standard can vary depending on many factors, such as the size and complexity of the organization, the scope of the information security management system (ISMS), the chosen certification body and geographical location. Therefore, it is difficult to provide an exact amount that would be universal for all organizations. However, the main cost components and indicative price ranges can be indicated.
Here are the key elements affecting the cost of ISO/IEC 27017 certification:
-
ISMS implementation: Before proceeding to certification, the organization must implement an ISMS compliant with the requirements of the ISO/IEC 27017 standard. Implementation costs include, among others, personnel time, training, external consultations, software and hardware purchases, and infrastructure adjustments. These costs can vary significantly depending on the organization’s initial state and the scope of necessary changes. Indicatively, ISMS implementation can cost from tens to hundreds of thousands of zlotys, depending on the size and complexity of the organization.
-
Certification body fees: The main cost of certification is fees paid to the chosen certification body. These fees include, among others, the certification audit, surveillance audits and certificate issuance. The amount of fees depends on the certification body’s rates, the duration of audits and the number of auditors involved in the process. Indicatively, certification body fees can range from tens to several tens of thousands of zlotys annually, depending on the size of the organization and the scope of the ISMS.
-
Audit costs: In addition to certification body fees, the organization must include costs related to conducting the audits themselves, such as personnel time involved in the audit, providing documentation and systems, and possible travel and accommodation costs for auditors (in the case of on-site audits). These costs are usually lower than certification body fees, but can reach several or tens of thousands of zlotys annually.
-
ISMS maintenance and improvement costs: After obtaining the certificate, the organization must bear costs related to maintaining and continuously improving the ISMS to ensure constant compliance with ISO/IEC 27017 requirements. These costs include, among others, training, reviews and internal audits, documentation updates, and implementation of corrective and preventive actions. ISMS maintenance and improvement costs are usually lower than initial implementation costs, but can reach several or tens of thousands of zlotys annually.
In summary, the cost of certification for compliance with the ISO/IEC 27017 standard consists of ISMS implementation costs, certification body fees, audit costs, and ISMS maintenance and improvement costs. Indicatively, the total cost of certification can range from tens to hundreds of thousands of zlotys, depending on the size and complexity of the organization and the scope of the ISMS. However, exact costs can vary significantly in individual cases.
It is worth remembering that certification is an investment in information security and building customer trust, which can bring measurable business benefits to the organization. Increased competitiveness, meeting legal and regulatory requirements, and improving the company’s image can offset or exceed certification costs in the longer term.
To obtain an exact quotation of ISO/IEC 27017 certification costs, the organization should contact selected certification bodies and present the specifics of their business and the scope of the ISMS. Based on this information, certification bodies will prepare personalized offers, taking into account the organization’s individual circumstances.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- CSPM (Cloud Security Posture Management) — CSPM (Cloud Security Posture Management) is a category of cloud security tools…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- Cloud Environment Security — Cloud environment security refers to the technologies, procedures, policies,…
- Hybrid Cloud — Hybrid cloud is a cloud computing model that combines on-premises…
Learn More
Explore related articles in our knowledge base:
- What is an MDM System? - Definition, Features, Applications, Benefits and Challenges
- Cybersecurity Act: six and a half years of certification in the EU - assessment and perspectives
- High Availability (HA) Solutions - Key Benefits for Business
- How does the public cloud work and what benefits does it offer to companies?
- Hyperconverged Infrastructure (HCI): Solution Overview and Business Benefits
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
