Skip to main content
Back

EVS-EN ISO/IEC 27017:2026

Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)

General information

Valid from 17.08.2026
Base Documents
ISO/IEC 27017:2026; EN ISO/IEC 27017:2026
Directives or regulations
None

Standard history

Status
Date
Type
Name

ISO/IEC 27017 provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This standard provides:

— additional guidance for relevant controls specified in ISO/IEC 27002:2022,
— additional controls with guidance that specifically relate to cloud services.

ISO/IEC 27017 provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).

This standard is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. ISO/IEC 27017 applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organisation’s internal departments.

ISO/IEC 27017:2026 text has been approved in Europe as EN ISO/IEC 27017:2026 without any changes.

Required fields are indicated with *

*
*
*
PDF
27.28 € incl tax
Paper
27.28 € incl tax
Browse standard from 2.48 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

EVS-EN ISO/IEC 27701:2025

Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance (ISO/IEC 27701:2025)
Newest version Valid from 15.12.2025
Main

EVS-EN ISO/IEC 42001:2026

Information technology - Artificial intelligence - Management system (ISO/IEC 42001:2023)
Newest version Valid from 01.04.2026
Main

EVS-EN ISO/IEC 23894:2024

Information technology - Artificial intelligence - Guidance on risk management (ISO/IEC 23894:2023)
Newest version Valid from 01.03.2024
Main + amendment

EVS-EN ISO/IEC 27001:2023+A1:2024

Information security, cybersecurity and privacy protection - Information security management systems - Requirements (ISO/IEC 27001:2022 + ISO/IEC 27001:2022/Amd 1:2024)
Newest version Valid from 16.12.2024