731 901 601
ISO/IEC 27017, ISO 27001 and ISO 27018 – how do these standards differ?

ISO/IEC 27017, ISO 27001 and ISO 27018 – how do these standards differ?

A difference of just three letters and a number can cause considerable confusion. ISO 27001, ISO 27017, ISO 27018 – to someone not involved in information security on a daily basis, these designations sound almost identical, yet they cover completely different areas of data protection. Understanding where one standard ends and another begins is crucial, particularly for companies planning to implement security measures in a cloud environment and wishing to avoid overpaying for certification of something they do not need at all.

In a nutshell: what distinguishes the two standards

  • ISO/IEC 27017 is a code of practice concerning information security in cloud services – it is not a standalone management system, but an extension focused on cloud computing.
  • ISO/IEC 27001 is a standard setting out the requirements for the entire Information Security Management System (ISMS) – it is the only one of the three that can be certified independently.
  • ISO/IEC 27018 addresses a narrow but significant aspect of the subject: the protection of personal information (PII) processed in public clouds.
  • Both cloud standards – 27017 and 27018 – are based on the same foundation: a management system established in accordance with ISO/IEC 27001.
  • The ISO/IEC 27018 standard dates from 2014, whilst the first version of ISO/IEC 27017 dates from 2015; both were designed to complement the same framework.

ISO 27017 vs ISO 27001 – a different level, a different objective

The simplest way to understand the difference between these standards is to look at the level at which each operates.

Criterion ISO/IEC 27001ISO/IEC 27017
PurposeEstablishes a general Information Security Management System covering the entire organisationClarifies and adds security controls specific to cloud environments
Standalone status   Enables the organisation to obtain an independent, fully separate certificateIt is implemented as a supplement to a system based on ISO 27001 (or ISO 27002), not as a separate entity  
Organisational scope   The entire organisation, regardless of whether it uses the cloud   Exclusively processes and resources related to cloud services  
ResponsibilityDefines general roles and responsibilities within the information security management systemEstablishes a clear division of shared responsibility between the cloud provider and the cloud customer

In practice, this means that a company cannot ‘just have ISO 27017’ – in order to claim compliance with this standard at all, it must first have a functioning information security management system based on ISO 27001. It is only on this foundation that additional cloud-related security measures are built.

ISO 27017 vs ISO 27018 – security versus privacy

This comparison can be misleading for another reason – both standards cover the same domain (the cloud), but approach it from completely different perspectives. ISO/IEC 27017 focuses on information security in a cloud environment; we discuss its requirements and application in more detail in the article ‘ISO 27017 – how to effectively secure data in the cloud’.

CriterionISO/IEC 27017ISO/IEC 27018
Main area   General security of cloud infrastructure – configuration management, virtualisation, access control  Protection of personal information (PII) processed in public clouds  
Reference pointInformation security as such, regardless of whether the data relates to naturalPrivacy principles linked to regulations such as the GDPR
Who is primarily affectedAll parties involved in cloud relationships – cloud service providers (CSPs) and cloud service customers (CSCs) using any cloud services  Primarily entities acting as personal data processors in the public cloud
Typical implementation scenario   Companies migrating their IT infrastructure to the cloud, regardless of the nature of the data being processedCompanies processing sensitive data in the cloud – HR, medical, financial, and individual customer data  

The two standards do not compete with one another – many organisations implement them in parallel, as they address different risks. A public cloud provider that processes its customers’ personal data usually needs both: 27017 for the general security of the environment, and 27018 to demonstrate compliance in the area of privacy.

Which option to choose in practice

The decision rarely boils down to choosing one standard at the expense of the other – it is rather a question of the order and scope of implementation:

  • An organisation that does not yet hold ISO 27001 certification should start by establishing an information security management system – without this foundation, no cloud extension has the legal or formal basis for implementation.
  • A cloud service provider (CSP) will almost always benefit from implementing ISO 27017 – this is a standard that institutional clients are increasingly requiring during the supplier evaluation stage.
  • An organisation processing personal data on a large scale in the cloud should also consider ISO 27018, particularly if it operates in regulated sectors where compliance with the GDPR is subject to regular audits.

Understanding this hierarchy – with ISO 27001 as the foundation, and ISO 27017 and ISO 27018 as specialised extensions – helps to avoid the common mistake of attempting to implement a cloud standard in isolation from the underlying information security management system.

 

Read other posts

Psychosocial risks at work — how to assess them before it becomes a requirement under ISO 45001:2027

Psychosocial risks at work — how to assess them before it becomes a requirement under ISO 45001:2027

In most companies, occupational risk assessment is associated with a specific, tangible list of hazards — noise, chemicals, working at height, and operating machinery. read more
Why is ISO 50001 worth it? 5 key benefits for businesses

Why is ISO 50001 worth it? 5 key benefits for businesses

ISO 50001 is often perceived as a standard ‘for large-scale industry’ or a tool implemented solely to meet legal obligations. read more
EUDR – the deadline is approaching, and companies that act now will have an advantage over those that wait

EUDR – the deadline is approaching, and companies that act now will have an advantage over those that wait

The EUDR has already seen several deadline extensions and numerous amendments. This has led some companies to adopt a wait-and-see approach: “It will change again, so we’ll wait.” read more
More posts