731 901 601
Cloud provider or customer – who is responsible for what? Division of roles according to ISO 27017

Cloud provider or customer – who is responsible for what? Division of roles according to ISO 27017

Imagine you are renting an office. The building owner is responsible for the door locks, CCTV in the corridors and security of the entire premises. You, on the other hand, are responsible for who has a key to your office, how you store documents, and who you let onto your floor. The cloud works in a similar way. And it is precisely this analogy that the ISO 27017 standard clarifies – specifying where the provider’s responsibility ends and the customer’s begins.

The problem the standard addresses

For years, one of the biggest sources of misunderstanding in cloud relationships was the belief among customers that, since they were paying for the service, the provider was ‘taking care of all security matters’. Providers, in turn, assumed that the customer knew what they were doing with their data and how to manage access.

In practice, this led to a situation where no one felt responsible for certain areas – and security gaps arose precisely where the line of responsibility became blurred. ISO 27017 brings a clear framework to this area.

What are the responsibilities of a cloud service provider?

The provider (CSP) is primarily responsible for the security of the infrastructure on which the services operate. According to the standard’s guidelines, they should, amongst other things:

  • provide the customer with full and accurate information on how the cloud platform is structured – including the technologies used, data location and security measures in place,
  • maintain procedures for monitoring and responding to security incidents,
  • clearly specify what data is collected during the provision of the service and for what purpose,
  • upon termination of the contract – enable the customer to retrieve their data and confirm its deletion from their systems.

What is the customer’s responsibility?

The customer (CSC) is not a passive recipient of the service – they have their own set of responsibilities. The standard specifies that the customer should, amongst other things:

  • understand and verify the elements of the cloud environment that may affect security or regulatory compliance (data location, encryption, access control),
  • independently manage their users’ access to cloud resources,
  • know how to report security incidents and how to track their handling by the provider.

In other words: the provider builds and secures the building, but the customer decides for themselves who to give the keys to.

The division of responsibility described in ISO 27017 is not a bureaucratic exercise – it is a practical tool that protects both parties. The customer knows what they can expect from the provider. The provider knows what they must deliver. And where there was previously ambiguity and potential gaps – transparency and mutual trust emerge.

Read other posts

PPWR – a revolution in packaging. What does the new regulation mean for businesses?

PPWR – a revolution in packaging. What does the new regulation mean for businesses?

The PPWR (Packaging and Packaging Waste Regulation), which covers packaging and packaging waste, is one of the most significant regulatory changes of recent years in the field of the environment and waste management. read more
IFS or BRC in the food industry – which standard to choose?

IFS or BRC in the food industry – which standard to choose?

Food producers are increasingly faced with the question: IFS or BRC? Both standards are recognised by the GFSI, both require the implementation of HACCP and a quality management system, and both open up access to retail chains. read more
TISAX-certified companies are growing faster in the automotive sector. Coincidence or the norm?

TISAX-certified companies are growing faster in the automotive sector. Coincidence or the norm?

When a company first hears about TISAX, it is usually presented as a requirement. read more
More posts