ISO/IEC 27017:2015
ISO/IEC 27017:2015 Code of practice for information security controls for cloud services.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Both
| Code | Title |
|---|---|
| 10.1.1 | Policy on the use of cryptographic controls (cloud) |
| 10.1.2 | Key management (cloud) |
| 12.1.2 | Change management (cloud) |
| 12.1.3 | Capacity management (cloud) |
| 12.3.1 | Information backup (cloud) |
| 12.4.1 | Event logging (cloud) |
| 12.4.3 | Administrator and operator logs (cloud) |
| 12.6.1 | Management of technical vulnerabilities (cloud) |
| 13.1.3 | Segregation in networks (cloud) |
| 13.2.2 | Agreements on information transfer (cloud) |
| 14.1.1 | Information security requirements analysis (cloud apps) |
| 15.1.1 | Information security policy for supplier relationships (cloud) |
| 15.1.2 | Addressing security within supplier agreements (cloud) |
| 16.1.1 | Responsibilities and procedures (cloud incidents) |
| 16.1.2 | Reporting information security events (cloud) |
| 18.1.1 | Identification of applicable legislation (cloud) |
| 5.1.1 | Leadership and commitment (general) |
| 6.1.1 | Information security roles and responsibilities (cloud guidance) |
| 6.1.3 | Compliance Obligations |
| 7.2.2 | Information security awareness, education and training (cloud) |
| 8.1.1 | Operational planning and control, general |
| 8.1.2 | Eliminating hazards and reducing OH&S risks |
| 8.2.2 | Asset Management |
| 9.1.2 | Access to networks and network services (cloud) |
| 9.2.1 | Internal audit (general) |
| 9.2.3 | Management of privileged access rights (cloud) |
| 9.2.4 | Management of secret authentication information (cloud) |
| 9.4.1 | Information access restriction (cloud) |
| CLD.12.1.5 | Administrator's operational security |
| CLD.12.4.5 | Monitoring of cloud services |
| CLD.6.3.1 | Shared roles and responsibilities within a cloud computing environment |
| CLD.9.5.2 | Virtual machine hardening |
Cloud Service Provider
| Code | Title |
|---|---|
| 11.2.7 | Secure disposal or reuse of equipment (cloud) |
| 9.4.4 | Use of privileged utility programs (cloud) |
| CLD.13.1.4 | Alignment of security management for virtual and physical networks |
| CLD.8.1.5 | Removal of cloud service customer assets |
| CLD.9.5.1 | Segregation in virtual computing environments |
Frequently Asked Questions
What is ISO/IEC 27017:2015?
ISO/IEC 27017:2015 is a compliance framework from International with 2 domains and 37 controls. ISO/IEC 27017:2015 Code of practice for information security controls for cloud services. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27017:2015 have?
ISO/IEC 27017:2015 has 37 controls organised across 2 domains. The largest domains are Both (32 controls), Cloud Service Provider (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27017:2015 map to?
ISO/IEC 27017:2015 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with ISO/IEC 27017:2015 compliance?
Start your ISO/IEC 27017:2015 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27017:2015 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required