Back to Standards
Security & Access ControlGlobal

ISO/IEC 27017: Cloud Security

ISO 27017

Cloud-specific information security controls based on ISO 27001.

Purpose

Extends ISO 27001 with cloud-specific security guidance for providers and customers.

Requirements Overview

Cloud-specific security controls; Shared responsibility model; Virtual machine hardening; Cloud service customer security

Overview

ISO/IEC 27017 represents a critical milestone in cloud security standards, developed in 2015 to address the unique security challenges emerging from cloud computing environments. Prior to this standard, organizations lacked comprehensive guidance for securing multi-tenant, virtualized infrastructure across different cloud service models. The standard was jointly published by the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) to bridge significant gaps in existing information security frameworks. Traditional security models designed for on-premises infrastructure were inadequate for cloud environments, which require fundamentally different approaches to data protection, access management, and infrastructure security. Unlike its predecessor ISO/IEC 27001, ISO 27017 provides 37 cloud-specific controls that directly address the complexities of shared responsibility models in cloud computing. These controls cover critical areas such as virtual machine isolation, hypervisor security, cloud-specific cryptography, and multi-tenant access management. For data center operators, ISO 27017 represents a transformative approach to cloud security. It mandates architectural changes that move beyond traditional perimeter-based security models, requiring sophisticated controls for container-level security, API protection, and automated compliance monitoring. Organizations achieving this certification demonstrate their ability to engineer cloud infrastructure with robust multi-tenancy security, comprehensive forensic capabilities, and stringent customer data isolation protocols.

Key Requirements

Cloud Service Customer Information System Identification and Responsibility Clarification

Cloud service providers must explicitly document and communicate which information systems and data elements belong to customers versus those owned/operated by the provider, with detailed responsibility matrices that distinguish between provider-managed infrastructure security, customer-managed application security, and shared security functions.

Data centers must establish formal service level agreements (SLAs) with specific security obligations mapped to each customer's workload tier, including explicit statements about what the provider will and will not secure, preventing the dangerous assumption that 'cloud' means 'the provider secures everything.'.

Virtual Machine and Hypervisor Security Hardening

Data center operators must implement mandatory technical controls for hypervisor hardening including disabled unnecessary services, resource consumption limits per virtual machine to prevent denial-of-service attacks, and secure virtual machine migration protocols that prevent unauthorized data access during movement between physical hosts.

The standard requires documented procedures for virtual machine image management including immutable base images, signed container registries, and automated vulnerability scanning of all virtual machine templates before deployment to production cloud infrastructure.

Cloud-Specific Cryptographic Key Management and Encryption Architecture

ISO 27017 mandates that cloud providers implement customer-controlled encryption for data at rest and in transit, with key management systems that ensure customers retain cryptographic control over their own data, preventing CSP access to unencrypted customer information.

Data centers must establish Hardware Security Module (HSM) infrastructure separate from general computing resources, implement key rotation policies that allow customer-initiated key changes without service interruption, and provide documented evidence that encryption key material is never accessible to cloud provider personnel except in narrowly-defined disaster recovery scenarios with mandatory multi-party authorization.

Logical and Physical Isolation of Multi-Tenant Resources

Data center facilities must demonstrate technical enforcement of logical isolation between customer virtual environments through network segmentation, storage isolation, and compute resource boundaries that prevent one customer's workload from accessing another customer's data or performance metrics.

The standard requires regular penetration testing specifically targeting tenant isolation boundaries, documentation of approved hypervisor versions with known isolation vulnerabilities patched, and architectural diagrams showing how customer data flows are physically isolated at the storage, network, and compute layers within multi-tenant infrastructure.

Cloud Service Customer Access Control and Authentication Management

Providers must implement role-based access control (RBAC) systems that allow customers to define and enforce their own access policies within their cloud tenancy without affecting other customers' security posture, including support for multi-factor authentication, single sign-on integration, and customer-defined privileged access management protocols.

Data centers must audit and log all administrative access to customer-facing APIs, explicitly prevent shared credentials between customers and provider support staff, and implement secure credential delivery mechanisms that ensure customer administrative passwords are never visible to CSP personnel.

Audit Logging, Monitoring, and Forensic Capability in Cloud Environments

ISO 27017 requires comprehensive logging of all data access events, configuration changes, and administrative actions within customer tenancies, with immutable audit trails stored separately from production systems and accessible to customers for compliance investigations.

Data centers must implement real-time threat detection capabilities that monitor for anomalous access patterns, unauthorized API calls, and lateral movement attempts between virtual machines, with automated alerting that reaches customer security teams within minutes of incident detection, enabling genuine shared responsibility incident response.

Data Residency, Geographic Isolation, and Customer Data Sovereignty

Cloud providers must document explicit data storage locations and processing regions for each customer tenant, with technical controls that enforce geographic boundaries preventing data from being moved to different jurisdictions without customer authorization.

The standard requires implementation of legal and technical mechanisms that prevent government access to customer data without due process, including transparency reporting, customer notification of lawful data demands, and the architectural capability to separate customer data by geographic region even within the same data center facility.

Secure Deletion and Data Destruction in Multi-Tenant Environments

Data centers must implement verified data destruction procedures that guarantee complete removal of customer data when tenancies are terminated, including destruction of all backup copies, cache data, and temporary files created during processing, with cryptographic proof of destruction provided to customers.

The standard mandates that deletion requests are honored within contractually-specified timeframes, that customers can verify non-recovery of deleted data through forensic audits, and that physical media containing customer data is destroyed using approved destruction methods documented and certified by authorized third parties.

Who Uses & Why

ISO/IEC 27017 certification becomes mandatory for organizations providing cloud services in highly regulated industries, including healthcare, financial services, and government sectors. Specifically, cloud service providers must obtain this certification when serving clients with strict compliance requirements such as HIPAA, SOC 2 Type II, or FedRAMP standards. For Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) providers, certification is crucial, particularly when operating multi-tenant public cloud platforms. Enterprise and mid-market data centers transitioning to cloud service models should consider certification as a prerequisite for attracting sophisticated customers, especially those serving Fortune 500 organizations. Geographic considerations play a significant role in certification decisions. European and Asia-Pacific markets demonstrate stronger demand for cloud security certifications compared to North American markets. Private cloud operators serving specific geographic boundaries (such as EU data centers) will find particular value in demonstrating compliance with data residency and sovereignty requirements. Organizations should evaluate certification based on their customer demographics, market positioning, and long-term cloud strategy. While not universally mandatory, ISO 27017 provides a competitive advantage in markets where major cloud service providers have already established these security standards.