
Imagine you are renting an office. The building owner is responsible for the door locks, CCTV in the corridors and security of the entire premises. You, on the other hand, are responsible for who has a key to your office, how you store documents, and who you let onto your floor. The cloud works in a similar way. And it is precisely this analogy that the ISO 27017 standard clarifies – specifying where the provider’s responsibility ends and the customer’s begins.
For years, one of the biggest sources of misunderstanding in cloud relationships was the belief among customers that, since they were paying for the service, the provider was ‘taking care of all security matters’. Providers, in turn, assumed that the customer knew what they were doing with their data and how to manage access.
In practice, this led to a situation where no one felt responsible for certain areas – and security gaps arose precisely where the line of responsibility became blurred. ISO 27017 brings a clear framework to this area.
The provider (CSP) is primarily responsible for the security of the infrastructure on which the services operate. According to the standard’s guidelines, they should, amongst other things:

The customer (CSC) is not a passive recipient of the service – they have their own set of responsibilities. The standard specifies that the customer should, amongst other things:
In other words: the provider builds and secures the building, but the customer decides for themselves who to give the keys to.
The division of responsibility described in ISO 27017 is not a bureaucratic exercise – it is a practical tool that protects both parties. The customer knows what they can expect from the provider. The provider knows what they must deliver. And where there was previously ambiguity and potential gaps – transparency and mutual trust emerge.