{"id":13661,"date":"2022-04-11T16:22:59","date_gmt":"2022-04-11T14:22:59","guid":{"rendered":"https:\/\/brandcompliance.com\/services\/iso-27017-en-iso-27018\/"},"modified":"2026-07-20T16:47:48","modified_gmt":"2026-07-20T14:47:48","slug":"iso-27017-and-iso-27018","status":"publish","type":"page","link":"https:\/\/brandcompliance.com\/en\/services\/iso-27017-and-iso-27018\/","title":{"rendered":"ISO 27017 and ISO 27018 certification"},"content":{"rendered":"<p>Cloud services introduce specific information security and privacy risks. Responsibilities are divided between cloud service providers and cloud service customers, while data and systems can be distributed across different locations and technical environments.<\/p>\n<p>ISO\/IEC 27017 and ISO\/IEC 27018 provide additional controls and implementation guidance for managing these risks. They complement an Information Security Management System based on ISO 27001.<\/p>\n<p>Would you like to discuss whether these standards are applicable to your cloud services? Schedule an <a href=\"https:\/\/brandcompliance.com\/en\/contact\/meet-brand-compliance\/\">introductory meeting<\/a> to discuss the scope and assessment process.<\/p>\n<p><img decoding=\"async\" class=\"alignleft wp-image-17501 \" src=\"http:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-300x200.jpg\" alt=\"ISO 27017\" width=\"273\" height=\"182\" srcset=\"https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-300x200.jpg 300w, https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-1024x683.jpg 1024w, https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-768x512.jpg 768w, https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-360x240.jpg 360w, https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-1536x1024.jpg 1536w, https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-2048x1365.jpg 2048w, https:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/hand-holding-cloud-system-with-data-protection-600x400.jpg 600w\" sizes=\"(max-width: 273px) 100vw, 273px\" \/><\/p>\n<h2>What is ISO 27017?<\/h2>\n<p>ISO 27017 provides information security controls and implementation guidance for the provision and use of cloud services. The standard is intended for both cloud service providers and cloud service customers. It supplements the general information security controls in ISO 27002 with guidance and controls specifically related to cloud environments. These address subjects such as:<\/p>\n<ul>\n<li>the division of responsibilities between cloud providers and customers;<\/li>\n<li>the removal and return of customer assets;<\/li>\n<li>separation between customers in virtual environments;<\/li>\n<li>security of virtual machines and administrative operations;<\/li>\n<li>monitoring of cloud services;<\/li>\n<li>coordination of information security activities between providers and customers.<\/li>\n<\/ul>\n<p>The applicable controls depend on the organization\u2019s role, services, risks and cloud environment.<\/p>\n<h2>What is ISO 27018?<\/h2>\n<p>ISO 27018 provides guidance for protecting personally identifiable information, or PII, in public cloud services. It is specifically intended for public cloud service providers acting as processors of personal data on behalf of their customers. The standard addresses subjects such as:<\/p>\n<ul>\n<li>processing personal data only for agreed purposes;<\/li>\n<li>transparency about the processing of personal data;<\/li>\n<li>the use of subprocessors;<\/li>\n<li>return, transfer and deletion of personal data;<\/li>\n<li>access to and disclosure of personal data;<\/li>\n<li>information security incidents involving personal data;<\/li>\n<li>supporting customers in meeting their privacy obligations.<\/li>\n<\/ul>\n<p>ISO 27018 can help cloud providers demonstrate that they have implemented specific measures for protecting personal data. Applying the standard does not automatically demonstrate compliance with all applicable privacy legislation. Legal compliance must always be assessed separately.<\/p>\n<h3 class=\"PDq2pG_selectionAnchorContainer\" data-section-id=\"f1lcy1\" data-start=\"3792\" data-end=\"3851\">What is the difference between ISO 27017 and ISO 27018?<\/h3>\n<p data-start=\"3853\" data-end=\"4003\">ISO 27017 focuses broadly on information security within cloud services. It applies to cloud service providers as well as cloud service customers. ISO 27018 focuses specifically on the protection of personal data in public cloud services where the cloud provider acts as a processor.<\/p>\n<div style=\"overflow-x: auto; margin: 24px 0;\">\n<table style=\"width: 100%; min-width: 700px; border-collapse: collapse; border: 1px solid #6EC1E4; font-family: Calibri, Arial, sans-serif; font-size: 16px; line-height: 1.5; color: #304269; text-align: left;\">\n<thead>\n<tr style=\"background-color: #304269; color: #ffffff;\">\n<th style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\" scope=\"col\">Standard<\/th>\n<th style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\" scope=\"col\">Primary focus<\/th>\n<th style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\" scope=\"col\">Intended users<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background-color: #ffffff;\">\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top; font-weight: bold; color: #304269;\">ISO\/IEC 27017<\/td>\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\">Information security for cloud services<\/td>\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\">Cloud service providers and cloud service customers<\/td>\n<\/tr>\n<tr style=\"background-color: #f5d1b9;\">\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top; font-weight: bold; color: #304269;\">ISO\/IEC 27018<\/td>\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\">Protection of personal data in public cloud services<\/td>\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\">Public cloud providers acting as processors of personal data<\/td>\n<\/tr>\n<tr style=\"background-color: #ffffff;\">\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top; font-weight: bold; color: #304269;\">ISO\/IEC 27001<\/td>\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\">Requirements for an information security management system<\/td>\n<td style=\"padding: 14px; border: 1px solid #6EC1E4; vertical-align: top;\">Organizations of all types and sizes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p data-start=\"3853\" data-end=\"4003\">Depending on the organization\u2019s activities, ISO\/IEC 27017 and ISO\/IEC 27018 can be assessed individually or together.<\/p>\n<h2>How do ISO 27017 and ISO 27018 relate to ISO 27001?<\/h2>\n<p>ISO 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System. ISO 27017 and ISO 27018 provide additional guidance and controls for specific cloud-related risks. They can be incorporated into the organization\u2019s ISMS and risk treatment process.<\/p>\n<p>Assessment of these additional controls can take place:<\/p>\n<ul>\n<li>alongside an ISO 27001 certification audit;<\/li>\n<li>during a later surveillance or recertification audit;<\/li>\n<li>through a separate additional assessment, subject to the applicable certification arrangements.<\/li>\n<\/ul>\n<p>Having an accredited ISO 27001 certificate does not mean that an additional ISO 27017 or ISO 27018 certificate is also accredited.<\/p>\n<h2>Who are these certificates intended for?<\/h2>\n<p>ISO 27017 certification can be relevant for:<\/p>\n<ul>\n<li>software-as-a-service providers;<\/li>\n<li>infrastructure and platform providers;<\/li>\n<li>managed service providers;<\/li>\n<li>data centres and hosting providers;<\/li>\n<li>organizations that purchase or manage significant cloud services;<\/li>\n<li>organizations that want to clarify cloud security responsibilities.<\/li>\n<\/ul>\n<p>ISO 27018 certification can be relevant for public cloud providers that process personal data on behalf of customers, including providers of:<\/p>\n<ul>\n<li>hosted software applications;<\/li>\n<li>cloud storage and backup services;<\/li>\n<li>cloud-based HR or financial systems;<\/li>\n<li>healthcare or customer data platforms;<\/li>\n<li>other public cloud services involving personal data.<\/li>\n<\/ul>\n<p>During the intake, Brand Compliance determines which standard or combination of standards is appropriate for the proposed scope.<\/p>\n<h2>Benefits of ISO 27017 and ISO 27018 certification<\/h2>\n<p>Independent assessment of the applicable controls can help an organization:<\/p>\n<ul>\n<li>demonstrate its approach to cloud security;<\/li>\n<li>clarify responsibilities between cloud providers and customers;<\/li>\n<li>strengthen the protection of personal data in cloud environments;<\/li>\n<li>provide customers and partners with additional assurance;<\/li>\n<li>support supplier assessments and tender requirements;<\/li>\n<li>identify opportunities for improving cloud security and privacy controls;<\/li>\n<li>align cloud-specific controls with its ISO\/IEC 27001 management system.<\/li>\n<\/ul>\n<p>Certification does not replace the organization\u2019s responsibility to meet applicable legal, regulatory and contractual requirements.<\/p>\n<h2>Strengthen confidence in your cloud services<\/h2>\n<p>ISO 27017 and ISO 27018 provide cloud-specific guidance for information security and the protection of personal data. An independent assessment by Brand Compliance can demonstrate that the applicable controls have been implemented effectively. Following a positive assessment and certification decision, Brand Compliance issues the applicable certificate or certificates. This certification is not performed under accreditation.<\/p>\n<p>Would you like to know what ISO 27017 and ISO 27018 certification means for your organization? Schedule an <a href=\"https:\/\/brandcompliance.com\/en\/contact\/meet-brand-compliance\/\">introductory meeting<\/a> to discuss the scope, certification criteria and assessment process.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cloud services introduce specific information security and privacy risks. Responsibilities are divided between cloud service providers and cloud service customers, while data and systems can&#8230;<\/p>\n","protected":false},"author":6,"featured_media":15013,"parent":16202,"menu_order":9,"comment_status":"closed","ping_status":"closed","template":"layouts\/diensten-layout.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-13661","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/13661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/comments?post=13661"}],"version-history":[{"count":9,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/13661\/revisions"}],"predecessor-version":[{"id":26883,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/13661\/revisions\/26883"}],"up":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/16202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/media\/15013"}],"wp:attachment":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/media?parent=13661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}