FRAMEWORK · CLOUD SECURITY
ISO 27017, Cloud Security Controls
The international standard extending ISO 27001 with cloud-specific security controls and guidance for cloud service providers and cloud service customers. Senior practitioner implementation for UK organisations operating cloud infrastructure or providing cloud services.
Goldline delivers ISO 27017 implementation as an extension to existing ISO 27001 programmes or as a parallel cloud security workstream. ISO 27001 Senior Lead Implementer (PECB) credentialed delivery.
WHERE THIS FRAMEWORK FITS
Where this framework fits at Goldline
Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. ISO 27017 is not a service Goldline delivers as a standalone product.
ISO 27017 is an ISO 27001 extension providing cloud-service-specific implementation guidance. Organisations approaching ISO 27017 typically implement ISO 27001 first, then layer the cloud-specific extension. Goldline's ISO 27001 Sprint delivers the foundational management system on which ISO 27017 is built.
For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.
Book the Free Diagnostic- Cyber Essentials Certified
- JOSCAR Registered
- Companies House 10901798
What is ISO 27017?
ISO 27017:2015 provides cloud-specific implementation guidance for information security controls from ISO 27002, and introduces additional controls that apply specifically to cloud computing environments. It addresses both cloud service providers (CSPs) who deliver cloud infrastructure and platforms, and cloud service customers (CSCs) who consume those services.
The standard is structured around the shared responsibility model inherent in cloud computing. Security responsibilities are divided between CSP and CSC depending on the service model (IaaS, PaaS, or SaaS). ISO 27017 clarifies which controls sit with each party and provides implementation guidance for both roles.
For organisations already holding ISO 27001 certification, ISO 27017 is implemented as an extension to the existing ISMS, adding cloud-specific controls and guidance rather than requiring a separate management system.
What ISO 27017 covers
Shared responsibility
Clarifying the division of security responsibilities between cloud service provider and cloud service customer across IaaS, PaaS, and SaaS service models. Security boundary definition for each cloud service in scope.
Asset management in cloud
Identification and classification of assets in cloud environments. Cloud-specific asset inventory covering virtual machines, storage, databases, and managed services. Ownership assignment for cloud assets.
Access control
Cloud-specific access control guidance including privileged access to cloud management interfaces, administrator account management, and identity federation across cloud providers and on-premise environments.
Virtual machine security
Security of virtual machine images, hardening of VM configurations, isolation between virtual machines, and management of VM lifecycle including secure decommissioning.
Monitoring and logging
Cloud-specific monitoring requirements including cloud activity logging, audit trail preservation, and monitoring of cloud administrative functions. Integration with SIEM environments.
Supply chain and multi-cloud
Managing security across cloud provider supply chains. Vendor assessment for cloud services, contractual security requirements, and governance of multi-cloud and hybrid cloud architectures.
Why UK organisations adopt ISO 27017
- Cloud infrastructure is now standard across UK regulated mid-market and enterprise. ISO 27017 provides the governance framework specific to cloud security risks not fully addressed by ISO 27001 alone.
- Enterprise procurement increasingly includes cloud security questions that ISO 27001 alone does not address. ISO 27017 demonstrates structured cloud security governance.
- UK financial services regulators (FCA, PRA) and public sector procurement frameworks expect cloud security governance calibrated to the specific risks of cloud deployment models.
- ISO 27017 and ISO 27001 share governance infrastructure. For ISO 27001-certified organisations, ISO 27017 extension compresses implementation effort significantly.
- Cloud service providers delivering services to ISO 27001-certified customers often face requests to demonstrate their own ISO 27017 alignment as part of supplier security assurance.
ISO 27017 vs ISO 27001 vs CSA STAR
| ISO 27017 | ISO 27001 | CSA STAR | |
|---|---|---|---|
| Type | International standard (cloud extension) | International standard (ISMS) | Cloud-specific assurance programme |
| Scope | Cloud service providers and customers | Information security across the organisation | Cloud service providers |
| Certification | Accredited certification body, extension to ISO 27001 | Accredited certification body | Self-assessment (Level 1) or third-party (Level 2) |
| Relationship | Cloud-specific control overlay on the ISO 27001 ISMS | Foundational ISMS that ISO 27017 extends with cloud controls | Complementary cloud assurance; commonly paired with ISO 27017 |
METHODOLOGY
How Goldline delivers ISO 27017
The Goldline Method applied to ISO 27017 cloud security implementation. Five phases from scope through certification audit support.
- 01
Phase 1
Cloud scope and shared responsibility mapping
Cloud service inventory across IaaS, PaaS, and SaaS. Shared responsibility boundaries documented per service and provider. CSP and CSC responsibilities clarified. Existing ISO 27001 ISMS scope extended to include cloud-specific controls.
- Cloud asset inventory
- Shared responsibility matrix
- Scope extension
- 02
Phase 2
Gap analysis against ISO 27017 cloud controls
Comprehensive gap analysis against ISO 27017 cloud-specific controls and ISO 27002 guidance as it applies to cloud environments. Existing cloud security configuration, access controls, logging, and monitoring assessed.
- Gap analysis
- Cloud control assessment
- Remediation plan
- 03
Phase 3
Cloud-specific control implementation
Cloud access controls hardened. VM security configurations applied. Cloud activity logging and monitoring established. Virtual network security controls implemented. Cloud-specific policy framework developed covering cloud usage, administrator access, and multi-cloud governance.
- Cloud controls operational
- Logging and monitoring
- Cloud security policies
- 04
Phase 4
Evidence collection and documentation
Evidence of cloud-specific controls collected and mapped to ISO 27017 requirements. Cloud provider security documentation reviewed. Shared responsibility evidence compiled. Technical documentation prepared to certification body submission standard.
- Evidence pack
- Provider documentation
- Technical documentation
- 05
Phase 5
Certification audit support and continuous cloud security
Internal review against ISO 27017 cloud controls. Certification body engagement supported. Post-certification continuous monitoring of cloud controls established. Annual surveillance audit preparation.
- CB submission
- Certification issued
- Continuous monitoring
Frequently asked
Discuss where this framework fits your programme
Whether your organisation is extending an existing ISO 27001 programme with cloud-specific controls, demonstrating cloud security governance to enterprise customers, or operating as a cloud service provider seeking to evidence ISO 27017 alignment, Goldline provides senior practitioner-led delivery calibrated to your cloud estate.
