Skip to main content
Back

EVS-EN ISO/IEC 27017:2026

Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)

General information

Valid from 17.08.2026
Base Documents
ISO/IEC 27017:2026; EN ISO/IEC 27017:2026
Directives or regulations
None

Standard history

Status
Date
Type
Name

ISO/IEC 27017 provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This standard provides:

— additional guidance for relevant controls specified in ISO/IEC 27002:2022,
— additional controls with guidance that specifically relate to cloud services.

ISO/IEC 27017 provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).

This standard is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. ISO/IEC 27017 applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organisation’s internal departments.

ISO/IEC 27017:2026 text has been approved in Europe as EN ISO/IEC 27017:2026 without any changes.

Required fields are indicated with *

*
*
*
*
PDF
27.28 € incl tax
Paper
27.28 € incl tax
Browse standard from 2.48 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

EVS-EN ISO/IEC 27701:2025

Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance (ISO/IEC 27701:2025)
Newest version Valid from 15.12.2025
Main

EVS-EN ISO 9001:2026 en

Quality management systems - Requirements (ISO 9001:2026)
Newest version Valid from 16.09.2026
Main

EVS-EN ISO/IEC 27018:2020

Information technology - Security techniques - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors (ISO/IEC 27018:2019)
Newest version Valid from 15.06.2020
Main

EVS-ISO/IEC 27003:2021

Information technology - Security techniques -- Information security management systems -- Guidance (ISO/IEC 27003:2017, identical)
Newest version Valid from 03.05.2021