
ISO/IEC 27017
ISO/IEC 27017 cloud security controls implementation
ISO/IEC 27017 consulting helps companies clarify security responsibilities in cloud services. Vosurein reviews service models, contracts and actual configurations to determine what the provider and customer each manage, addressing gaps between their responsibilities.
For Your Business
Who this service is for and when to start
Suitable for enterprises providing or using cloud services. Before new service procurement, system migration, private and hybrid cloud integration, or supplier replacement, control responsibilities should be confirmed, not just whether the other party holds certificates.
The Challenge
Common challenges faced by businesses
A supplier protecting infrastructure does not mean that enterprise accounts, configurations, and data usage are properly managed. If the responsibility is only stated as jointly held by both parties, anomalies may still go unhandled.
The scope of the supplier's report does not necessarily cover the services, regions, or periods used this time, and it needs to correspond to the actual usage scenario.
Our Approach
Methods and applicable requirements
ISO/IEC 27017:2026 was released in July 2026, replacing the 2015 version. It is based on ISO/IEC 27002, providing cloud control guidance and additional controls, applicable to cloud customers and suppliers, including public, private, and hybrid clouds.
The priorities below depend on the organisation’s context. Confirm the scope and level of supporting evidence at the start.
Shared Responsibilities
Assign responsibility for accounts, configurations, infrastructure and incident coordination according to the service model. Each control needs a clear owner and supporting evidence.
Control Mapping
Map existing information security measures to cloud risks and contract conditions, checking which are executed by the enterprise and which require reliance on the supplier.
Contracts and Evidence
Confirm service scope, change notifications, accessible reports, and audit information to avoid only receiving a certification unrelated to the actual service.
Operational Review
Check permissions, anomalies, and exit procedures; during migration or service termination, data retrieval, account closure, and records still require clear responsibility allocation.
Process
Consulting scope and process
Map cloud service relationships
Organize services, deployment models, and user departments, confirming adopted versions and assessment scope.
Compare Control Responsibilities
Review contracts and existing measures to identify gaps at the interface between customer and supplier.
Pilot Management Check
Select permissions, changes, or event flow tests to confirm evidence and communication channels are available.
Included in supply management
Organize procedures and supplier tracking items that need updates, and schedule regular and change reviews.
Preparation
What documents do companies need to prepare?
- Cloud services: Platform, service model, purpose, and responsible person.
- Contracts and reports: Service scope, terms, and available audit data.
- Control and configuration: Access permissions, management procedures and configuration summaries.
- Operational records: Changes, incidents, redundancy and service exit arrangements.
An index or summary is enough for an initial discussion. Before sharing personal data, confidential contract information or system records, agree on access authorisation, redaction and retention.
Project Planning
Estimating time and cost
We assess scope by service and provider numbers, deployment models and the depth of control review. Configuration changes, vulnerability testing and third-party assessments are distinct from document review. Edition transitions require confirmation of the applicable scheme and provisions.
FAQ
Frequently asked questions
Is it only applicable to public cloud?
No, it also covers private and hybrid clouds; Roles and controls between internal departments still need to be adjusted according to the context.
If the provider is certified, do we still need to manage cloud risks?
Yes. Confirm the company’s own responsibilities for accounts, data and configurations, and check that the evidence covers the services actually used.
Has the 2026 edition been released?
Published. This item is based on ISO/IEC 27017:2026. Adjustments to existing arrangements must be confirmed according to the actual control and evaluation plan.
Can it replace ISO/IEC 27001?
No. Cloud controls can form part of existing information security management, but the management system requirements still need separate review.
Will the consultant log in to the live environment?
Not by default. We can start with configuration summaries and records. Any necessary access requires separate agreement on authorisation, scope and how the work will be performed.
Will you be guaranteed to obtain a cloud certificate?
No guarantees. If there is a third-party assessment requirement, the plan, applicable version, and service scope must be verified first.
Related
Related services and enquiries
Tell us your industry, the activities you want to improve, your existing system and your target completion date so we can define the scope together.
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

