Cloud services introduce specific information security and privacy risks. Responsibilities are divided between cloud service providers and cloud service customers, while data and systems can be distributed across different locations and technical environments.
ISO/IEC 27017 and ISO/IEC 27018 provide additional controls and implementation guidance for managing these risks. They complement an Information Security Management System based on ISO 27001.
Would you like to discuss whether these standards are applicable to your cloud services? Schedule an introductory meeting to discuss the scope and assessment process.

What is ISO 27017?
ISO 27017 provides information security controls and implementation guidance for the provision and use of cloud services. The standard is intended for both cloud service providers and cloud service customers. It supplements the general information security controls in ISO 27002 with guidance and controls specifically related to cloud environments. These address subjects such as:
- the division of responsibilities between cloud providers and customers;
- the removal and return of customer assets;
- separation between customers in virtual environments;
- security of virtual machines and administrative operations;
- monitoring of cloud services;
- coordination of information security activities between providers and customers.
The applicable controls depend on the organization’s role, services, risks and cloud environment.
What is ISO 27018?
ISO 27018 provides guidance for protecting personally identifiable information, or PII, in public cloud services. It is specifically intended for public cloud service providers acting as processors of personal data on behalf of their customers. The standard addresses subjects such as:
- processing personal data only for agreed purposes;
- transparency about the processing of personal data;
- the use of subprocessors;
- return, transfer and deletion of personal data;
- access to and disclosure of personal data;
- information security incidents involving personal data;
- supporting customers in meeting their privacy obligations.
ISO 27018 can help cloud providers demonstrate that they have implemented specific measures for protecting personal data. Applying the standard does not automatically demonstrate compliance with all applicable privacy legislation. Legal compliance must always be assessed separately.
What is the difference between ISO 27017 and ISO 27018?
ISO 27017 focuses broadly on information security within cloud services. It applies to cloud service providers as well as cloud service customers. ISO 27018 focuses specifically on the protection of personal data in public cloud services where the cloud provider acts as a processor.
| Standard | Primary focus | Intended users |
|---|---|---|
| ISO/IEC 27017 | Information security for cloud services | Cloud service providers and cloud service customers |
| ISO/IEC 27018 | Protection of personal data in public cloud services | Public cloud providers acting as processors of personal data |
| ISO/IEC 27001 | Requirements for an information security management system | Organizations of all types and sizes |
Depending on the organization’s activities, ISO/IEC 27017 and ISO/IEC 27018 can be assessed individually or together.
How do ISO 27017 and ISO 27018 relate to ISO 27001?
ISO 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System. ISO 27017 and ISO 27018 provide additional guidance and controls for specific cloud-related risks. They can be incorporated into the organization’s ISMS and risk treatment process.
Assessment of these additional controls can take place:
- alongside an ISO 27001 certification audit;
- during a later surveillance or recertification audit;
- through a separate additional assessment, subject to the applicable certification arrangements.
Having an accredited ISO 27001 certificate does not mean that an additional ISO 27017 or ISO 27018 certificate is also accredited.
Who are these certificates intended for?
ISO 27017 certification can be relevant for:
- software-as-a-service providers;
- infrastructure and platform providers;
- managed service providers;
- data centres and hosting providers;
- organizations that purchase or manage significant cloud services;
- organizations that want to clarify cloud security responsibilities.
ISO 27018 certification can be relevant for public cloud providers that process personal data on behalf of customers, including providers of:
- hosted software applications;
- cloud storage and backup services;
- cloud-based HR or financial systems;
- healthcare or customer data platforms;
- other public cloud services involving personal data.
During the intake, Brand Compliance determines which standard or combination of standards is appropriate for the proposed scope.
Benefits of ISO 27017 and ISO 27018 certification
Independent assessment of the applicable controls can help an organization:
- demonstrate its approach to cloud security;
- clarify responsibilities between cloud providers and customers;
- strengthen the protection of personal data in cloud environments;
- provide customers and partners with additional assurance;
- support supplier assessments and tender requirements;
- identify opportunities for improving cloud security and privacy controls;
- align cloud-specific controls with its ISO/IEC 27001 management system.
Certification does not replace the organization’s responsibility to meet applicable legal, regulatory and contractual requirements.
Strengthen confidence in your cloud services
ISO 27017 and ISO 27018 provide cloud-specific guidance for information security and the protection of personal data. An independent assessment by Brand Compliance can demonstrate that the applicable controls have been implemented effectively. Following a positive assessment and certification decision, Brand Compliance issues the applicable certificate or certificates. This certification is not performed under accreditation.
Would you like to know what ISO 27017 and ISO 27018 certification means for your organization? Schedule an introductory meeting to discuss the scope, certification criteria and assessment process.
More informationFAQ
ISO 27017 provides information security controls and implementation guidance for cloud services. It is intended for both cloud service providers and cloud service customers and supplements the controls in ISO 27002.
ISO 27018 provides guidance for protecting personally identifiable information in public cloud services. It is specifically intended for public cloud providers acting as processors of personal data.
ISO 27017 focuses on information security for cloud services. ISO 27018 focuses specifically on protecting personal data processed by public cloud providers. An organization can apply one or both standards depending on its services and role.
The controls are normally incorporated into an Information Security Management System based on ISO 27001. They can be assessed alongside an ISO 27001 audit or through an additional assessment for an organization that already holds ISO 27001 certification. The precise prerequisites are determined during the intake.
Yes. When both standards are relevant to the organization, their controls can be assessed during the same audit process. Their applicability, scope and required audit time are determined separately.