731 901 601
ISO 27017 vs ISO 27018 – key differences in cloud security and data protection

ISO 27017 vs ISO 27018 – key differences in cloud security and data protection

ISO 27017 and ISO 27018 are two standards that are often confused with one another, as both relate to cloud environments. In reality, however, they focus on different areas of security. ISO 27017 relates to the general security of cloud services and the division of responsibility between the provider and the customer, whilst ISO 27018 focuses exclusively on the protection of personal information (PII) processed in the cloud. Both standards are extensions of ISO 27001 and supplement its requirements in the specific context of cloud services.

Scope and approach: cloud security versus personal data protection

The fundamental difference between the standards lies in their scope. ISO 27017 focuses on the security of cloud infrastructure and services, covering, amongst other things, access management, service configuration and the shared responsibility model. Its aim is to clarify the security arrangements between the cloud provider and the customer.

ISO 27018, on the other hand, focuses on the protection of personal data processed in the cloud. It covers principles relating to privacy, restrictions on data processing, data minimisation and transparency towards users. Unlike ISO 27017, it does not apply to the entire infrastructure, but specifically to personal data.

Responsibilities and roles in both standards

In ISO 27017, a key element is the shared responsibility model, which specifies which security aspects are the responsibility of the cloud provider and which are the responsibility of the customer. The provider is primarily responsible for the infrastructure and service availability, whilst the customer is responsible for configuration, data and user management.

In ISO 27018, the emphasis is on the provider’s role as a data processor. The standard sets out the provider’s obligations regarding the protection of personal data, transparency of processing and supporting the customer in fulfilling the rights of data subjects. The customer, on the other hand, remains the data controller and determines the purposes of data processing.

The application and integration of standards within organisations

ISO 27017 is primarily used in organisations that use or provide cloud services and need to address technical and organisational security issues. ISO 27018 is particularly important where personal data is processed in the cloud and high standards of privacy protection are required, including compliance with the GDPR.

In many organisations, both standards are applied in parallel as they complement one another. ISO 27017 provides a security framework for the entire cloud environment, whilst ISO 27018 adds a layer of protection for personal data. This approach enables comprehensive management of both infrastructure and data privacy.

The benefits of combining ISO 27017 and ISO 27018

Combining both standards helps to better organise cloud security matters, as it covers both technical aspects and those relating to the protection of personal data. Organisations gain greater clarity regarding accountability, a consistent approach to risk management, and better alignment with regulatory requirements such as the GDPR. As a result, cloud security is not treated in a piecemeal manner, but as a coherent system encompassing both the infrastructure and the data processed within it.

 

Read other posts

ISO 3834 – the key to markets that pay more

ISO 3834 – the key to markets that pay more

Polish welding companies have one of the best reputations in Europe when it comes to workmanship and value for money. And yet many of them hit a glass ceiling when trying to enter Western European markets or secure a contract with an international client. read more
A highly secure company – what does ISO 27001 really mean for your business?

A highly secure company – what does ISO 27001 really mean for your business?

Imagine two scenarios. In the first: a company employee receives an email with a link to an ‘urgent document from the accounts department’. They click on it. Two days later... read more
Until recently a ‘bonus’, now a prerequisite for working with many clients – ISO 14001

Until recently a ‘bonus’, now a prerequisite for working with many clients – ISO 14001

Just a few years ago, ISO 14001 certification was, for many companies, a matter of image – it looked good on their website, appeared in email footers and on signs at the office entrance. Today, that era is over. read more
More posts