
The growing use of cloud services is changing the way organisations store, process and share data. However, the flexibility, scalability and availability of the cloud go hand in hand with new challenges in the area of information security. The traditional approach, based solely on general security principles, is often insufficient, as cloud environments have their own specific characteristics – particularly regarding the division of responsibility between the provider and the customer.
It is precisely in this area that ISO/IEC 27017 comes into play – a set of guidelines supplementing ISO 27001, focused on the security of cloud services. This standard clarifies issues of responsibility, outlines good security practices and helps to mitigate the risks arising from the use of cloud infrastructure.
ISO 27001 forms the basis of an Information Security Management System (ISMS) and covers the entire organisation. ISO 27017 is an extension of this standard, focusing exclusively on cloud environments.
The key difference between the two standards is the clarification of the shared responsibility model. In the cloud, some security responsibilities lie with the service provider, whilst others lie with the customer. ISO 27017 helps to clearly define these boundaries, thereby reducing the risk of security vulnerabilities arising from ambiguous divisions of responsibility.

The use of SaaS, PaaS and IaaS models entails specific risks, such as misconfigurations, unauthorised access, loss of control over data and improper permissions management. ISO 27017 sets out a series of recommended security measures to help mitigate these risks. These include, amongst others:
A key principle is that cloud security is not the responsibility of a single party – it requires cooperation between the service provider and the user.
ISO 27017 is worth implementing in organisations that make extensive use of cloud services or provide them themselves. The standard can serve as a complement to an existing ISO 27001 system [KC2.1], without the need to build an entire system from scratch.
The key benefits include: an increased level of security for data processed in the cloud, better management of operational and technological risks, greater clarity regarding responsibilities between parties, and increased trust among customers and business partners.
As a result, ISO 27017 not only supports security but also streamlines processes related to cloud usage, which translates into greater stability and predictability in the organisation’s operations.