731 901 601
Cloud provider or customer – who is responsible for what? Division of roles according to ISO 27017

Cloud provider or customer – who is responsible for what? Division of roles according to ISO 27017

Imagine you are renting an office. The building owner is responsible for the door locks, CCTV in the corridors and security of the entire premises. You, on the other hand, are responsible for who has a key to your office, how you store documents, and who you let onto your floor. The cloud works in a similar way. And it is precisely this analogy that the ISO 27017 standard clarifies – specifying where the provider’s responsibility ends and the customer’s begins.

The problem the standard addresses

For years, one of the biggest sources of misunderstanding in cloud relationships was the belief among customers that, since they were paying for the service, the provider was ‘taking care of all security matters’. Providers, in turn, assumed that the customer knew what they were doing with their data and how to manage access.

In practice, this led to a situation where no one felt responsible for certain areas – and security gaps arose precisely where the line of responsibility became blurred. ISO 27017 brings a clear framework to this area.

What are the responsibilities of a cloud service provider?

The provider (CSP) is primarily responsible for the security of the infrastructure on which the services operate. According to the standard’s guidelines, they should, amongst other things:

  • provide the customer with full and accurate information on how the cloud platform is structured – including the technologies used, data location and security measures in place,
  • maintain procedures for monitoring and responding to security incidents,
  • clearly specify what data is collected during the provision of the service and for what purpose,
  • upon termination of the contract – enable the customer to retrieve their data and confirm its deletion from their systems.

What is the customer’s responsibility?

The customer (CSC) is not a passive recipient of the service – they have their own set of responsibilities. The standard specifies that the customer should, amongst other things:

  • understand and verify the elements of the cloud environment that may affect security or regulatory compliance (data location, encryption, access control),
  • independently manage their users’ access to cloud resources,
  • know how to report security incidents and how to track their handling by the provider.

In other words: the provider builds and secures the building, but the customer decides for themselves who to give the keys to.

The division of responsibility described in ISO 27017 is not a bureaucratic exercise – it is a practical tool that protects both parties. The customer knows what they can expect from the provider. The provider knows what they must deliver. And where there was previously ambiguity and potential gaps – transparency and mutual trust emerge.

Read other posts

A revolution in FSC Chain of Custody and labelling

A revolution in FSC Chain of Custody and labelling

The Forest Stewardship Council (FSC) system is increasingly moving beyond forest management itself. read more
What is Good Manufacturing Practice (GMP) and what is it for?

What is Good Manufacturing Practice (GMP) and what is it for?

Good Manufacturing Practice is a standard familiar to every business in the food, pharmaceutical and cosmetics industries – sectors where end products must be completely safe for consumers’ health. read more
GMP+ as a gateway to the Dutch, German and Scandinavian markets – what do Polish feed manufacturers need to know?

GMP+ as a gateway to the Dutch, German and Scandinavian markets – what do Polish feed manufacturers need to know?

Poland is one of Europe’s leading feed producers. We have modern facilities, competitive prices and growing production capacity. read more
More posts