Skip to main content
Back
NEW

EVS-EN ISO/IEC 27017:2026

Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)

General information

Valid from 17.08.2026
Base Documents
ISO/IEC 27017:2026; EN ISO/IEC 27017:2026
Directives or regulations
None

Standard history

Status
Date
Type
Name

ISO/IEC 27017 provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This standard provides:

— additional guidance for relevant controls specified in ISO/IEC 27002:2022,
— additional controls with guidance that specifically relate to cloud services.

ISO/IEC 27017 provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).

This standard is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services. ISO/IEC 27017 applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organisation’s internal departments.

ISO/IEC 27017:2026 text has been approved in Europe as EN ISO/IEC 27017:2026 without any changes.

Required fields are indicated with *

*
*
*
PDF
27.28 € incl tax
Paper
27.28 € incl tax
Browse standard from 2.48 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

EVS-ISO/IEC 27033-2:2013

Information technology -- Security techniques -- Network security -- Part 2: Guidelines for the design and implementation of network security
Newest version Valid from 05.08.2013
Main

EVS-ISO/IEC 27033-3:2013

Information technology - Security techniques - Network security - Part 3: Reference networking scenarios - Threats, design techniques and control issues
Newest version Valid from 06.05.2013
Main

EVS-EN ISO/IEC 12792:2025

Information technology - Artificial intelligence (AI) - Transparency taxonomy of AI systems (ISO/IEC 12792:2025)
Newest version Valid from 01.12.2025
Main

EVS-ISO/IEC 27035-2:2024

Information technology — Information security incident management — Part 2: Guidelines to plan and prepare for incident response (ISO/IEC 27035-2:2023, identical)
Newest version Valid from 15.08.2024