Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

ISO 27017: the cloud controls ISO 27001 does not spell out.

ISO 27017 cloud security certification exists to close a specific gap. ISO 27001:2022 tells you to manage supplier risk and control access; it does not tell you who is responsible for hypervisor hardening, what happens to your data when you terminate a cloud contract, or how a customer and a provider divide the work of monitoring.

ISO 27017 is a code of practice that extends ISO 27002 with cloud-specific guidance: additional implementation advice on existing controls plus seven controls that exist only in the cloud context. Crucially, it is written for both sides: cloud service customers and cloud service providers each get their own guidance, and the point of the standard is making the boundary between them explicit.

It is not a standalone certification. It is audited as an extension of an ISO 27001:2022 management system, so the sensible route is to build or extend the ISMS with cloud scope from the start. Where personal data is involved, ISO 27018 is the companion standard; the technical half is cloud security testing.

Why you need it

01 / 06

Why ISO 27017 is worth the extension.

01

Shared responsibility is where audits find gaps.

Both parties assume the other handles logging, key management, backup or vulnerability scanning for a given layer. ISO 27017 requires the split to be documented control by control, which is the single most useful thing it produces.

02

Standard controls do not describe cloud operations.

Virtual machine hardening, administrative operations in a shared environment, segregation between tenants, and alignment of customer and provider virtual networks are cloud-specific concerns that ISO 27002 addresses only in general terms.

03

Customers are asking for cloud-specific assurance.

For a SaaS or cloud-hosted product, "we are ISO 27001 certified" increasingly draws the follow-up question of what that covers in the cloud. ISO 27017 answers it with a recognised scope rather than a bespoke explanation.

04

Exit is planned before you need it.

The standard requires attention to asset return and removal on contract termination: what happens to your data, in what format, on what timeline, and with what proof of deletion. Most cloud contracts are signed without anyone asking.

Instrument

02 / 06

Where cloud controls overlap what you already do.

ISO 27017 sits on top of an ISO 27001:2022 management system. Toggle what you are asked for; the overlap is work you only do once.

What we deliver

03 / 06

What we deliver.

01

Cloud security readiness assessment

Your current cloud controls measured against ISO 27017 guidance and the seven cloud-specific controls, across every provider and service model you use. Delivered as a gap register with the shared-responsibility position stated for each item.

02

Cloud scope definition

Which cloud services, environments, regions and data are covered, and whether you are being assessed as a cloud service customer, a provider, or, as is increasingly common, both, because you consume infrastructure and sell a service built on it.

03

Shared responsibility mapping

A control-by-control matrix of what your provider does, what you do, and what neither of you currently does. The third column is the deliverable; it is almost never empty, and it is what an auditor will look for.

04

Cloud control implementation

Virtual machine and image hardening, tenant segregation, encryption and key management with clear ownership, administrative operations control, cloud monitoring aligned between customer and provider, and the asset return and removal process for contract exit.

05

Cloud security policy set

Policies and procedures written for cloud operations rather than adapted from a data-centre template: provider selection and assessment, configuration standards, change management in infrastructure-as-code, and multi-cloud governance.

06

Training and audit preparation

Role-specific training for the engineers who operate the environment and the people who will be interviewed, then internal audit against the extended scope and support through the certification body's assessment.

How we run it

04 / 06

Six stages, on top of the ISMS.

  1. 01

    Assess cloud security readiness

    Current controls against ISO 27017, per provider and per service model, with evidence sampled from the environment rather than from documentation. Existing ISO 27001:2022 coverage is credited so the gap is genuinely incremental.

    Weeks 1-3
  2. 02

    Define cloud security scope

    Services, environments and data in scope, and your role in each relationship. This decides which half of the standard's guidance applies to you and how the certificate will read.

    Weeks 3-4
  3. 03

    Implement cloud-specific controls

    The seven cloud controls and the cloud-extended guidance on existing ones (segregation, hardening, administrative operations, monitoring alignment, key management and asset return) implemented in the live environment.

    Months 1-4
  4. 04

    Develop cloud security policies

    The policy and procedure set, integrated into the existing ISMS documentation rather than maintained separately, so that one management system covers both.

    Months 2-4
  5. 05

    Employee training

    Cloud responsibilities made concrete for the people who hold them, and audit rehearsal for those who will be interviewed. Auditors ask engineers directly what they are responsible for.

    Month 4
  6. 06

    Internal audit and certification

    Internal audit against the extended scope, corrective action, and the certification body's assessment of ISO 27017 alongside your ISO 27001:2022 audit.

    Months 5-7

Key benefits

05 / 06

What changes after.

The responsibility boundary is written down

A control-by-control matrix showing who does what between you and each provider, which resolves the gaps that both parties currently assume the other covers.

Cloud assurance without a bespoke explanation

A recognised standard covering the cloud half of your estate, so customer reviews stop turning into architecture conversations.

Exit is a plan, not a crisis

Data return and deletion terms, formats and timelines established while you still have a working relationship with the provider.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Standards

  • ISO/IEC 27017
  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • ISO/IEC 27018

Cloud posture evidence

  • Prowler
  • ScoutSuite
  • Steampipe
  • CIS Benchmarks

Provider assurance

  • CSA CAIQ
  • CSA STAR registry
  • Provider audit reports and scope review

Control operation

  • Infrastructure-as-code policy checks
  • Key management inventory
  • Shared responsibility matrix

Validation

  • Trivy
  • kube-bench
  • Cloud configuration drift review

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about ISO 27017.

Can we certify to ISO 27017 on its own?
No. ISO 27017 is a code of practice, not a management system standard, so it is assessed as an extension of scope on an ISO 27001:2022 certification. If you are not already certified, the sensible route is a single programme that builds the ISMS with cloud scope included from the start, which is considerably cheaper than certifying and then extending.
Does it apply to us if we only consume cloud services?
Yes, and that is the more common case. The standard gives separate guidance for cloud service customers and cloud service providers. As a customer your obligations centre on provider selection and assessment, understanding and documenting the shared responsibility split, configuring and hardening what you control, managing your own keys and access, and planning exit. Many organisations are both, because they consume infrastructure and sell a service on top of it.
How is this different from ISO 27018?
ISO 27017 covers cloud security generally; ISO 27018 covers the protection of personally identifiable information processed in the cloud specifically. They are complementary and are frequently certified together: 27017 for the security of the environment, 27018 for the privacy obligations attaching to the personal data in it. If you process personal data in the cloud, you almost certainly want both.
What are the extra controls, in practice?
Beyond additional cloud guidance on existing ISO 27002 controls, the standard adds seven cloud-specific ones: shared roles and responsibilities, removal and return of assets on contract termination, protection and segregation in the virtual environment, virtual machine hardening, administrative operations and procedures, customer monitoring of cloud activity, and alignment of virtual and physical network security. The shared-responsibility control is the one that changes the most in practice.
How long does the extension take if we are already certified?
Typically three to five months, and much of it is documentation and mapping rather than new engineering, because most of the technical controls are already in place. The work is concentrated in the shared-responsibility matrix, the cloud policy set, and getting evidence collection working for cloud configuration. It is normally scheduled to be audited alongside a surveillance or recertification visit.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.