Register

What is ISO/IEC 27017:2015?

ISO/IEC 27017:2015 is an international code of practice that extends ISO/IEC 27002 with specific guidelines for cloud security.

The standard addresses the unique risks and responsibilities in cloud computing by defining best-practice controls for both cloud service providers and cloud service customers.

Key topics include shared security responsibilities, data ownership, cloud customer monitoring, and secure cloud service agreements.


Access the certificate and audit reports via our Compliance Center.

FAQ

How does ISO/IEC 27017 relate to ISO/IEC 27001?

ISO/IEC 27017:2015 provides additional guidance and recommended controls for securing cloud services, complementing the requirements of ISO/IEC 27001, the leading standard for information security management systems (ISMS).

ISO/IEC 27001 defines the management framework and risk-based approach, while ISO/IEC 27017 addresses specific cloud security challenges—such as clarifying roles and responsibilities between cloud provider and customer.

Exoscale

Contact our Compliance Team

Need more details on our cloud security certifications or compliance support? Contact our Compliance Team and tell us your requirements—we’re here to help.