ISO/IEC 27017:2015 has now been formally withdrawn (stage 95.99, dated 2026-07-27) and replaced by a newly published edition, ISO/IEC 27017:2026. GRC professionals relying on the cloud security controls code of practice should transition to the 2026 edition.
VIEW SOURCE ↗ISO/IEC 27017
Information SecurityIssued by ISO/IEC
ISO/IEC 27017 extends the controls in ISO/IEC 27002 with cloud-specific implementation guidance, addressing issues unique to cloud environments — shared responsibility between provider and customer, segregation of virtual environments, and return or deletion of customer data on contract termination. It applies to both cloud service providers and cloud service customers, though in practice it is pursued mainly by providers (AWS, Azure, and Google Cloud all hold it) to demonstrate cloud-specific security controls during enterprise vendor due diligence. Like 27002 it is not independently certifiable — a company extends the scope of its ISO/IEC 27001 audit to cover these controls. The current edition is ISO/IEC 27017:2026, published 27 July 2026, superseding the 2015 edition.
Get notified the moment ISO/IEC 27017 actually changes — reviewed by a human before it ever reaches you.
Get started freeMost recent update
▸ 1 EARLIER UPDATE IN THE FULL HISTORY
The complete change log for ISO/IEC 27017 — every confirmed update, with severity and source — is included in every account, free ones too.
Sign up free to see the full history