
ISO 27017 and ISO 27018 are two standards that are often confused with one another, as both relate to cloud environments. In reality, however, they focus on different areas of security. ISO 27017 relates to the general security of cloud services and the division of responsibility between the provider and the customer, whilst ISO 27018 focuses exclusively on the protection of personal information (PII) processed in the cloud. Both standards are extensions of ISO 27001 and supplement its requirements in the specific context of cloud services.
The fundamental difference between the standards lies in their scope. ISO 27017 focuses on the security of cloud infrastructure and services, covering, amongst other things, access management, service configuration and the shared responsibility model. Its aim is to clarify the security arrangements between the cloud provider and the customer.
ISO 27018, on the other hand, focuses on the protection of personal data processed in the cloud. It covers principles relating to privacy, restrictions on data processing, data minimisation and transparency towards users. Unlike ISO 27017, it does not apply to the entire infrastructure, but specifically to personal data.

In ISO 27017, a key element is the shared responsibility model, which specifies which security aspects are the responsibility of the cloud provider and which are the responsibility of the customer. The provider is primarily responsible for the infrastructure and service availability, whilst the customer is responsible for configuration, data and user management.
In ISO 27018, the emphasis is on the provider’s role as a data processor. The standard sets out the provider’s obligations regarding the protection of personal data, transparency of processing and supporting the customer in fulfilling the rights of data subjects. The customer, on the other hand, remains the data controller and determines the purposes of data processing.
ISO 27017 is primarily used in organisations that use or provide cloud services and need to address technical and organisational security issues. ISO 27018 is particularly important where personal data is processed in the cloud and high standards of privacy protection are required, including compliance with the GDPR.
In many organisations, both standards are applied in parallel as they complement one another. ISO 27017 provides a security framework for the entire cloud environment, whilst ISO 27018 adds a layer of protection for personal data. This approach enables comprehensive management of both infrastructure and data privacy.
Combining both standards helps to better organise cloud security matters, as it covers both technical aspects and those relating to the protection of personal data. Organisations gain greater clarity regarding accountability, a consistent approach to risk management, and better alignment with regulatory requirements such as the GDPR. As a result, cloud security is not treated in a piecemeal manner, but as a coherent system encompassing both the infrastructure and the data processed within it.