Standard [PRE-ORDER]
Product information on this site:
Quick delivery via download or delivery service
All transactions are encrypted
DIN EN ISO/IEC 27017 describes information security controls for cloud services based on ISO/IEC 27002:2022. It supports cloud service providers (CSPs) and cloud service customers (CSCs) in systematically managing information security risks in cloud environments and implementing appropriate security controls. The standard supplements existing information security standards with cloud-specific requirements and recommendations.
The standard provides additional guidance on the controls set out in ISO/IEC 27002:2022 and supplements them with specific requirements for cloud computing. It focuses on the secure use and provision of cloud services, the allocation of responsibilities between cloud customers and cloud providers, and the protection of information in cloud environments. The standard also describes cloud-specific controls relating to identity management, access rights, supplier relationships, configuration management, virtualization, monitoring, and information security incidents.
The new structure is based on a taxonomy of organizational, people, physical, and technological controls and consistently follows the current structure of ISO/IEC 27002.
Cloud services are now a central component of modern IT and business processes. DIN EN ISO/IEC 27017 helps organizations systematically implement information security in cloud environments and take the specific characteristics of cloud models into account in risk assessments, governance, and security controls.
Particularly relevant are the requirements concerning the allocation of responsibilities between CSPs and CSCs, the segregation of virtual environments, identity management, and the monitoring of cloud services. In this way, the standard helps effectively reduce security risks in multi-cloud, hybrid-cloud, and public-cloud environments.
The 2026 edition has been comprehensively revised. The key changes include:
DIN EN ISO/IEC 27017 provides authoritative guidance on information security for cloud services. With its cloud-specific security controls and clear allocation of responsibilities between cloud providers and cloud users, it supports the secure use of modern cloud environments and supplements the requirements of ISO/IEC 27002 with practical cloud security controls.
This document replaces DIN EN ISO/IEC 27017:2021-11 .