
ISO/IEC 27017:2026
ISO/IEC 27017:2026 Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
CDN $382.00
This publication was last reviewed and confirmed in 2026.
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Description
This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
- additional guidance for relevant controls specified in ISO/IEC 27002:2022;
- additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Edition
2
Published Date
2026-07-27
Status
PUBLISHED
Pages
39
Format 
Secure PDF
Secure – PDF details
- Save your file locally or view it via a web viewer
- Viewing permissions are restricted exclusively to the purchaser
- Device limits - 3
- Printing – Enabled only to print (1) copy
See more about our Environmental Commitment
Abstract
This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
- additional guidance for relevant controls specified in ISO/IEC 27002:2022;
- additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Previous Editions
Can’t find what you are looking for?
Please contact us at:
Related Documents
-

ISO 27402:2023 Cybersecurity – IoT security and privacy – Device baseline requirements
CDN $195.00 Add to cart -

ISO 27022:2021 Information technology – Guidance on information security management system processes
CDN $353.00 Add to cart -

ISO 20243:2023 Information technology – Open Trusted Technology ProviderTM Standard (O-TTPS) – Part 1: Requirements and recommendations for mitigating maliciously tainted and counterfeit products
CDN $310.00 Add to cart -

ISO 21177:2024 Intelligent transport systems – ITS station security services for secure session establishment and authentication between trusted devices
CDN $443.00 Add to cart







