Skip to main content
ISO/IEC 27017

Certifications

ISO/IEC 27017

The ISO/IEC 27001 extension dedicated to cloud services: it adds controls specific to designing, administering and consuming cloud infrastructure.

What it is

ISO/IEC 27017 is a code of practice that supplements the ISO/IEC 27001 controls with cloud-specific guidance. It clarifies how responsibilities are split between service provider and customer, and addresses the issues that behave differently in the cloud: separation of virtual environments, administrative account management, data removal at end of service, and resource monitoring.

What it means for you

Projects we host or operate on cloud infrastructure follow controls designed for that context: limited, explicitly assigned administrative roles, isolation between different projects' environments, configuration managed as code and therefore auditable, and clear rules for what happens to data when a service is decommissioned.

How we maintain it

We keep infrastructure configuration under version control, so every change is tracked and repeatable. We review privileged accounts periodically, monitor running resources, and document the split of responsibilities with the cloud providers we use.

Frequently asked questions

Certificate details, the certification body and the exact scope of certification are available on request: get in touch and we'll send you the current documentation.

ISO/IEC 27001 defines the security management system as a whole. ISO/IEC 27017 does not replace it: it adds controls specific to the cloud, where responsibility is shared between provider and customer and some risks take a different form.

Ready to kick off the digital transformation of your business?

Talk directly with our technical lead.