Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026); German version EN ISO/IEC 27017:2026

Standard [PRE-ORDER]

DIN EN ISO/IEC 27017:2026-11

Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026); German version EN ISO/IEC 27017:2026

German title
Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre - Informationssicherheitsmaßnahmen auf der Grundlage von ISO/IEC 27002 für Cloud-Dienste (ISO/IEC 27017:2026); Deutsche Fassung EN ISO/IEC 27017:2026
Publication date
2026-11
Accessibility
Original language
German
Pages
61

from 155.30 EUR VAT included

from 145.14 EUR VAT excluded

Format and language options

PDF download
  • 155.30 EUR

  • 188.20 EUR

  • 194.10 EUR

Shipment (3-5 working days)
  • 199.00 EUR

  • 248.60 EUR

Monitor with the Standards Ticker

This option is only available after login.
1

preorderable

Easily subscribe: Save time and money now!

You can also subscribe to this document - together with other important standards in your industry. This makes your work easier and pays for itself after a short time.

Sparschwein_data
Subscription advantages
Sparschwein Vorteil 1_data

Important standards for your industry, regularly updated

Sparschwein Vorteil 2_data

Much cheaper than buying individually

Sparschwein Vorteil 3_data

Useful functions: Filters, version comparison and more

Publication date
2026-11
Original language
German
Pages
61
Loading recommended items...

Quick delivery via download or delivery service

Buy securely with a credit card or pay upon receipt of invoice

All transactions are encrypted

About this product

Effectively implementing information security for cloud services

DIN EN ISO/IEC 27017 describes information security controls for cloud services based on ISO/IEC 27002:2022. It supports cloud service providers (CSPs) and cloud service customers (CSCs) in systematically managing information security risks in cloud environments and implementing appropriate security controls. The standard supplements existing information security standards with cloud-specific requirements and recommendations.

What is DIN EN ISO/IEC 27017 about?

The standard provides additional guidance on the controls set out in ISO/IEC 27002:2022 and supplements them with specific requirements for cloud computing. It focuses on the secure use and provision of cloud services, the allocation of responsibilities between cloud customers and cloud providers, and the protection of information in cloud environments. The standard also describes cloud-specific controls relating to identity management, access rights, supplier relationships, configuration management, virtualization, monitoring, and information security incidents.

The new structure is based on a taxonomy of organizational, people, physical, and technological controls and consistently follows the current structure of ISO/IEC 27002.

Topics covered

  • Information security for cloud services
  • Roles and responsibilities of CSCs and CSPs
  • Cloud governance and supplier relationships
  • Identity and access management
  • Secure authentication and rights management
  • Incident management and information security incidents
  • Business continuity and cloud SLAs
  • Network security and configuration management
  • Segregation of virtual cloud environments
  • Monitoring of cloud services and prevention of unauthorized use
  • Privacy and protection of personal data
  • Cryptography, data backup, and data deletion

Practical relevance

Cloud services are now a central component of modern IT and business processes. DIN EN ISO/IEC 27017 helps organizations systematically implement information security in cloud environments and take the specific characteristics of cloud models into account in risk assessments, governance, and security controls.

Particularly relevant are the requirements concerning the allocation of responsibilities between CSPs and CSCs, the segregation of virtual environments, identity management, and the monitoring of cloud services. In this way, the standard helps effectively reduce security risks in multi-cloud, hybrid-cloud, and public-cloud environments.

Changes compared with DIN EN ISO/IEC 27017:2021-11

The 2026 edition has been comprehensively revised. The key changes include:

  • Alignment of the title and scope with current cloud and security requirements
  • Restructuring of the document based on a consistent control taxonomy
  • Consolidation of individual controls and removal of content that is no longer relevant
  • Introduction of new cloud-specific controls, including:
    • CLD – Distributed roles and responsibilities in a cloud computing environment
    • CLD – Agreement on the roles and responsibilities of the cloud service partner
    • CLD – Segregation in virtual computing environments
    • CLD – Detection and prevention of unauthorized use of cloud services
  • Alignment with the current ISO/IEC 27002:2022

Target audience

  • Information security officers
  • ISMS managers
  • Cloud architects
  • Cloud service providers (CSPs)
  • Cloud service customers (CSCs)
  • IT security and cybersecurity professionals
  • Auditors and certification bodies
  • Data protection and compliance managers
  • Organizations with cloud and ISO/IEC 27001 projects

Conclusion

DIN EN ISO/IEC 27017 provides authoritative guidance on information security for cloud services. With its cloud-specific security controls and clear allocation of responsibilities between cloud providers and cloud users, it supports the secure use of modern cloud environments and supplements the requirements of ISO/IEC 27002 with practical cloud security controls.

Content

ICS

03.100.70, 35.030
Replacement amendments

This document replaces DIN EN ISO/IEC 27017:2021-11 .

Cooperation at DIN

Also available in
Loading recommended items...