731 901 601
ISO 27017 – how to effectively secure data in the cloud?

ISO 27017 – how to effectively secure data in the cloud?

The growing use of cloud services is changing the way organisations store, process and share data. However, the flexibility, scalability and availability of the cloud go hand in hand with new challenges in the area of information security. The traditional approach, based solely on general security principles, is often insufficient, as cloud environments have their own specific characteristics – particularly regarding the division of responsibility between the provider and the customer.

It is precisely in this area that ISO/IEC 27017 comes into play – a set of guidelines supplementing ISO 27001, focused on the security of cloud services. This standard clarifies issues of responsibility, outlines good security practices and helps to mitigate the risks arising from the use of cloud infrastructure.

ISO 27017 and ISO 27001 – how do they differ and why does it matter?

ISO 27001 forms the basis of an Information Security Management System (ISMS) and covers the entire organisation. ISO 27017 is an extension of this standard, focusing exclusively on cloud environments.

The key difference between the two standards is the clarification of the shared responsibility model. In the cloud, some security responsibilities lie with the service provider, whilst others lie with the customer. ISO 27017 helps to clearly define these boundaries, thereby reducing the risk of security vulnerabilities arising from ambiguous divisions of responsibility.

Cloud security risks and key best practices

The use of SaaS, PaaS and IaaS models entails specific risks, such as misconfigurations, unauthorised access, loss of control over data and improper permissions management. ISO 27017 sets out a series of recommended security measures to help mitigate these risks. These include, amongst others:

  • precise management of user access and identities,
  • the use of data encryption both in transit and at rest,
  • clear allocation of responsibility for backups and data recovery,
  • monitoring and logging of activity within the cloud environment.

A key principle is that cloud security is not the responsibility of a single party – it requires cooperation between the service provider and the user.

Implementation of the ISO 27017 standard and benefits for organisations

ISO 27017 is worth implementing in organisations that make extensive use of cloud services or provide them themselves. The standard can serve as a complement to an existing ISO 27001 system [KC2.1], without the need to build an entire system from scratch.
The key benefits include: an increased level of security for data processed in the cloud, better management of operational and technological risks, greater clarity regarding responsibilities between parties, and increased trust among customers and business partners.
As a result, ISO 27017 not only supports security but also streamlines processes related to cloud usage, which translates into greater stability and predictability in the organisation’s operations.

 

Read other posts

What new directions and trends will emerge in quality management?

What new directions and trends will emerge in quality management?

The forthcoming update to ISO 9001 is not merely an adaptation of the standard to current business realities. read more
FSSC 22000 v7 – what’s changing, when you need to act, and where to start

FSSC 22000 v7 – what’s changing, when you need to act, and where to start

In May 2026, the FSSC Foundation published version 7 of the FSSC 22000 standard. This is the most significant change to the scheme in several years – more substantial than the transition from v5.1 to v6. read more
ISO 22000 – the cornerstone of food safety management worldwide

ISO 22000 – the cornerstone of food safety management worldwide

Among all food safety management systems, ISO 22000 holds a special place – as the only standard with a truly global scope, developed by the International Organisation for Standardisation, it covers the entire food chain from raw material producers to distributors. read more
More posts