The ISO/IEC 27017 Cloud Service Information Security Management System is an international standard addressing information security in cloud environments. Built upon the robust foundation of ISO/IEC 27001 (information security management framework) and ISO/IEC 27002 (best-practice controls), this standard specifically assesses and certifies CSPs' information security risks and controls.
Its core mission is to equip CSPs with a holistic information security management system to address diverse risks inherent in cloud services. It encompasses CSP security policies, operational management, and the protection of customer data and applications, ensuring the confidentiality, integrity, and availability of customer data throughout service delivery.
Key Coverage Areas
The ISO/IEC 27017 standard addresses the following critical domains: