verified_user
Standardful
首页chevron_right标准chevron_rightISO/IEC 27017:2015
有效国际标准update 最后更新:2015年12月

ISO/IEC 27017:2015

信息技术 安全技术 基于 ISO/IEC 27002 的云服务信息安全控制实践指南

apartment发布组织:国际标准化组织 (ISO)

标准简介

ISO/IEC 27017:2015 是由 国际标准化组织 (ISO) 发布的有效标准,常用于科技、服务业、金融银行、医疗健康等行业,并适用于全球等市场。

本页汇总了 ISO/IEC 27017:2015 的官方文档、当前状态以及常见相关认证或评估机构,便于快速理解要求与落地路径。

cloud

Cloud-Specific Controls

Provides 7 additional controls beyond ISO 27002, addressing shared responsibility, virtual machine hardening, customer asset removal, and virtual environment segregation.

handshake

Shared Responsibility Model

Clearly delineates security responsibilities between cloud service providers and cloud service customers — a critical distinction often misunderstood in cloud deployments.

visibility

Customer Monitoring

Requires cloud providers to enable customers to monitor relevant activities within their cloud environment, supporting transparency and compliance verification.

list_alt Key Control Areas

  • Shared roles and responsibilities in cloud environments
  • Virtual machine hardening and isolation requirements
  • Customer asset removal upon contract termination
  • Virtual environment segregation between tenants
  • Cloud administrative operations procedures
  • Customer activity monitoring capabilities
  • Alignment of virtual and physical network security
  • Guidance for both cloud service providers and customers

Who Needs to Comply?

groups

Cloud service providers (IaaS, PaaS, SaaS) and organizations consuming cloud services that need to demonstrate robust cloud security controls. Especially relevant for technology companies, financial services, healthcare, and government agencies.

Key Requirements

1

Responsibility Delineation

Clearly define and document the division of information security responsibilities between the cloud service provider and the cloud service customer. Ensure both parties understand their respective obligations.

2

Virtual Environment Isolation

Implement controls to ensure adequate separation of virtual environments between different cloud service customers. Prevent unauthorized access across tenant boundaries.

3

Asset Management on Termination

Establish and communicate procedures for the return or secure deletion of customer assets, data, and configurations when a cloud service agreement ends or transitions to another provider.

4

Cloud Operations Security

Implement procedures for administrative operations specific to cloud computing environments, including monitoring of cloud resources, logging of cloud-specific events, and hardening of virtual machines.

Penalties & Enforcement

warning

No direct legal penalties — ISO/IEC 27017 is a voluntary code of practice (not independently certifiable). However, it supplements ISO 27001 certification and is increasingly expected by enterprise customers and regulators evaluating cloud security posture.

官方文档

查看全部

实施时间线

description
2005年
ISO/IEC 27002 published as the base code of practice
security
2013年
ISO/IEC 27001:2013 establishes ISMS framework for cloud providers
check_circle
2015年12月
ISO/IEC 27017:2015 published with cloud-specific guidance
update
2022年
ISO/IEC 27002:2022 published — updated base control set
cloud
2023年
Major cloud providers (AWS, Azure, GCP) maintain ISO 27017 attestations

相关分类