Contact us
Illustration for ISO management-system services

ISO/IEC 27017

ISO/IEC 27017 cloud security controls implementation

ISO/IEC 27017 consulting helps companies clarify security responsibilities in cloud services. Vosurein reviews service models, contracts and actual configurations to determine what the provider and customer each manage, addressing gaps between their responsibilities.

Discuss ISO/IEC 27017 cloud security control consulting

For Your Business

Who this service is for and when to start

Suitable for enterprises providing or using cloud services. Before new service procurement, system migration, private and hybrid cloud integration, or supplier replacement, control responsibilities should be confirmed, not just whether the other party holds certificates.

The Challenge

Common challenges faced by businesses

A supplier protecting infrastructure does not mean that enterprise accounts, configurations, and data usage are properly managed. If the responsibility is only stated as jointly held by both parties, anomalies may still go unhandled.

The scope of the supplier's report does not necessarily cover the services, regions, or periods used this time, and it needs to correspond to the actual usage scenario.

Our Approach

Methods and applicable requirements

ISO/IEC 27017:2026 was released in July 2026, replacing the 2015 version. It is based on ISO/IEC 27002, providing cloud control guidance and additional controls, applicable to cloud customers and suppliers, including public, private, and hybrid clouds.

The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.

Shared Responsibilities

Assign responsibility for accounts, configurations, infrastructure and incident coordination according to the service model. Each control needs a clear owner and supporting evidence.

Control Mapping

Map existing information security measures to cloud risks and contract conditions, checking which are executed by the enterprise and which require reliance on the supplier.

Contracts and Evidence

Confirm service scope, change notifications, accessible reports, and audit information to avoid only receiving a certification unrelated to the actual service.

Operational Review

Check permissions, anomalies, and exit procedures; during migration or service termination, data retrieval, account closure, and records still require clear responsibility allocation.

Process

Consulting scope and process

  1. Map cloud service relationships

    Organize services, deployment models, and user departments, confirming adopted versions and assessment scope.

  2. Compare Control Responsibilities

    Review contracts and existing measures to identify gaps at the interface between customer and supplier.

  3. Pilot Management Check

    Select permissions, changes, or event flow tests to confirm evidence and communication channels are available.

  4. Included in supply management

    Organize procedures and supplier tracking items that need updates, and schedule regular and change reviews.

Preparation

What documents do companies need to prepare?

  • Cloud services: Platform, service model, purpose, and responsible person.
  • Contracts and reports: Service scope, terms, and available audit data.
  • Control and configuration: Access permissions, management procedures and configuration summaries.
  • Operational records: Changes, incidents, redundancy and service exit arrangements.

An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.

Project Planning

Estimating time and cost

We assess scope by service and provider numbers, deployment models and the depth of control review. Configuration changes, vulnerability testing and third-party assessments are distinct from document review. Edition transitions require confirmation of the applicable scheme and provisions.

FAQ

Frequently asked questions

Is it only applicable to public cloud?

No, it also covers private and hybrid clouds; Roles and controls between internal departments still need to be adjusted according to the context.

If the provider is certified, do we still need to manage cloud risks?

Yes. Confirm the company’s own responsibilities for accounts, data and configurations, and check that the evidence covers the services actually used.

Has the 2026 edition been released?

Published. This item is based on ISO/IEC 27017:2026. Adjustments to existing arrangements must be confirmed according to the actual control and evaluation plan.

Can it replace ISO/IEC 27001?

No. Cloud controls can form part of existing information security management, but the management system requirements still need separate review.

Will the consultant log in to the live environment?

Not by default. We can start with configuration summaries and records. Any necessary access requires separate agreement on authorisation, scope and how the work will be performed.

Will you be guaranteed to obtain a cloud certificate?

No guarantees. If there is a third-party assessment requirement, the plan, applicable version, and service scope must be verified first.

Related

Related services and enquiries

Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents