
A difference of just three letters and a number can cause considerable confusion. ISO 27001, ISO 27017, ISO 27018 – to someone not involved in information security on a daily basis, these designations sound almost identical, yet they cover completely different areas of data protection. Understanding where one standard ends and another begins is crucial, particularly for companies planning to implement security measures in a cloud environment and wishing to avoid overpaying for certification of something they do not need at all.
The simplest way to understand the difference between these standards is to look at the level at which each operates.
| Criterion | ISO/IEC 27001 | ISO/IEC 27017 |
| Purpose | Establishes a general Information Security Management System covering the entire organisation | Clarifies and adds security controls specific to cloud environments |
| Standalone status | Enables the organisation to obtain an independent, fully separate certificate | It is implemented as a supplement to a system based on ISO 27001 (or ISO 27002), not as a separate entity |
| Organisational scope | The entire organisation, regardless of whether it uses the cloud | Exclusively processes and resources related to cloud services |
| Responsibility | Defines general roles and responsibilities within the information security management system | Establishes a clear division of shared responsibility between the cloud provider and the cloud customer |
In practice, this means that a company cannot ‘just have ISO 27017’ – in order to claim compliance with this standard at all, it must first have a functioning information security management system based on ISO 27001. It is only on this foundation that additional cloud-related security measures are built.

This comparison can be misleading for another reason – both standards cover the same domain (the cloud), but approach it from completely different perspectives. ISO/IEC 27017 focuses on information security in a cloud environment; we discuss its requirements and application in more detail in the article ‘ISO 27017 – how to effectively secure data in the cloud’.
| Criterion | ISO/IEC 27017 | ISO/IEC 27018 |
| Main area | General security of cloud infrastructure – configuration management, virtualisation, access control | Protection of personal information (PII) processed in public clouds |
| Reference point | Information security as such, regardless of whether the data relates to natural | Privacy principles linked to regulations such as the GDPR |
| Who is primarily affected | All parties involved in cloud relationships – cloud service providers (CSPs) and cloud service customers (CSCs) using any cloud services | Primarily entities acting as personal data processors in the public cloud |
| Typical implementation scenario | Companies migrating their IT infrastructure to the cloud, regardless of the nature of the data being processed | Companies processing sensitive data in the cloud – HR, medical, financial, and individual customer data |
The two standards do not compete with one another – many organisations implement them in parallel, as they address different risks. A public cloud provider that processes its customers’ personal data usually needs both: 27017 for the general security of the environment, and 27018 to demonstrate compliance in the area of privacy.
The decision rarely boils down to choosing one standard at the expense of the other – it is rather a question of the order and scope of implementation:
Understanding this hierarchy – with ISO 27001 as the foundation, and ISO 27017 and ISO 27018 as specialised extensions – helps to avoid the common mistake of attempting to implement a cloud standard in isolation from the underlying information security management system.