Back to Frameworks

ISO/IEC 27017:2015

International
2 domains
37 controls

ISO/IEC 27017:2015 Code of practice for information security controls for cloud services.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (2)

Both

32 controls
Controls in the Both domain of ISO/IEC 27017:201532 controls
CodeTitle
10.1.1Policy on the use of cryptographic controls (cloud)
10.1.2Key management (cloud)
12.1.2Change management (cloud)
12.1.3Capacity management (cloud)
12.3.1Information backup (cloud)
12.4.1Event logging (cloud)
12.4.3Administrator and operator logs (cloud)
12.6.1Management of technical vulnerabilities (cloud)
13.1.3Segregation in networks (cloud)
13.2.2Agreements on information transfer (cloud)
14.1.1Information security requirements analysis (cloud apps)
15.1.1Information security policy for supplier relationships (cloud)
15.1.2Addressing security within supplier agreements (cloud)
16.1.1Responsibilities and procedures (cloud incidents)
16.1.2Reporting information security events (cloud)
18.1.1Identification of applicable legislation (cloud)
5.1.1Leadership and commitment (general)
6.1.1Information security roles and responsibilities (cloud guidance)
6.1.3Compliance Obligations
7.2.2Information security awareness, education and training (cloud)
8.1.1Operational planning and control, general
8.1.2Eliminating hazards and reducing OH&S risks
8.2.2Asset Management
9.1.2Access to networks and network services (cloud)
9.2.1Internal audit (general)
9.2.3Management of privileged access rights (cloud)
9.2.4Management of secret authentication information (cloud)
9.4.1Information access restriction (cloud)
CLD.12.1.5Administrator's operational security
CLD.12.4.5Monitoring of cloud services
CLD.6.3.1Shared roles and responsibilities within a cloud computing environment
CLD.9.5.2Virtual machine hardening

Cloud Service Provider

5 controls
Controls in the Cloud Service Provider domain of ISO/IEC 27017:20155 controls
CodeTitle
11.2.7Secure disposal or reuse of equipment (cloud)
9.4.4Use of privileged utility programs (cloud)
CLD.13.1.4Alignment of security management for virtual and physical networks
CLD.8.1.5Removal of cloud service customer assets
CLD.9.5.1Segregation in virtual computing environments

Frequently Asked Questions

What is ISO/IEC 27017:2015?

ISO/IEC 27017:2015 is a compliance framework from International with 2 domains and 37 controls. ISO/IEC 27017:2015 Code of practice for information security controls for cloud services. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISO/IEC 27017:2015 have?

ISO/IEC 27017:2015 has 37 controls organised across 2 domains. The largest domains are Both (32 controls), Cloud Service Provider (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISO/IEC 27017:2015 map to?

ISO/IEC 27017:2015 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with ISO/IEC 27017:2015 compliance?

Start your ISO/IEC 27017:2015 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27017:2015 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required