Security

What is ISO 27017 – security controls for cloud services?

Written by

Organizations today operate in a landscape of digitalization and expanding information technology. One of the most significant fronts of that transformation is the shift of computing and storage systems to cloud providers, driven by the considerable advantages and potential these services offer.

As expected, these changes bring new information security risks and opportunities that must be properly managed, in the same way they are applied and managed when systems are hosted in-house. Both cases must fall within the scope of the company’s Information Security Management System (ISMS), based on the ISO 27001 standard, so that business requirements can be met.

What complementary controls does ISO 27017 introduce?

ISO 27017 introduces a set of controls that complement ISO 27002, aimed directly at services deployed in the cloud and at the providers that deliver them, proposing specific controls linked to the management and provision of secure cloud services.

It is worth recalling that ISO 27001 defines a set of 114 security controls structured across 14 domains, applied within the scope each company establishes when implementing its Information Security Management System.

With regard to risk management, the standard sets out references for identifying and mitigating the specific risks associated with cloud environments, so that they can be treated appropriately.

In addition, implementing ISO 27017 gives cloud service providers an image of consistency and commitment to security management in the eyes of their clients, and requires ISO 27001 to already be in place. The main objective is the secure management of the data stored on behalf of clients, increasing confidence in how information is managed and processed.

What does ISO 27017 mainly focus on?

This standard focuses on protecting virtualization environments and the configuration of the virtual machines hosted in them to deliver services, as well as on the process of handing over and deleting information when a client terminates their contract with a cloud service provider.

Similarly, it establishes the framework of the relationship between the client and the cloud service provider, in reference to the management and administration of the services offered by the provider, with the aim of ensuring the protection of key dimensions of information security such as confidentiality, integrity, and availability of information.

From the perspective of companies that wish to implement or transfer part of their systems and services to the cloud, ISO 27017 provides a clear reference regarding controls and risks that must be properly evaluated and addressed, as well as visibility of cloud service providers that maintain correct alignment between technology, risk management, and security.

For cloud service providers, it represents a clear opportunity to convey trust and accountability in the products and services they offer.

How to address ISO 27017 with software?

At GlobalSuite Solutions we offer GlobalSuite® Security: software developed entirely by our own team that enables the implementation, management and maintenance of Information Security Management Systems based on the ISO 27001 and ISO 27017 standards. A tool that helps companies and teams manage the standard end to end, covering its full cycle — from project kick-off and planning through to maintenance and continuous improvement.

Our specialist consulting team also provides the advice and support companies need to achieve both ISO 27001 and ISO 27017.

Tabla de contenidos