Register

What is the ISO/IEC 27017:2015 standard?

ISO 27017:2015 is a code of practice which provides guidelines on how to manage information security controls based on ISO/IEC 27002 for cloud services. It is intended for use by organizations that provide a cloud service, as well as by organizations that use a cloud service.


ISO 27017:2015 specifies guidelines for implementing information security controls in a cloud computing environment. It also provides recommendations and guidance on how to manage information security risks associated with the use of cloud services.


Download the certificate using the Compliance Center.

FAQ

What is the relationship between ISO 27017:2015 and ISO/IEC 27001:2013?

ISO 27017:2015 provides guidelines on how to manage information security controls based on ISO/IEC 27002 for cloud services. It is intended for use by both cloud service providers and cloud service users.

ISO/IEC 27001:2013 is the international standard that specifies requirements for an ISMS. It is intended for use by organizations in any sector.

ISO 27017:2015 and ISO/IEC 27001:2013 are intended for use together to provide a set of best practice recommendations for managing information security risks in cloud computing environments.

Download additional compliance reports from the Exoscale compliance center.

Exoscale

Contact our Compliance Team

A doubt? Unsure if we comply to a specific regulation not listed here?

Contact our Compliance Team and let us know your requirements. It may be covered by other certifications or regulations we comply to.