ISO and IEC have published ISO/IEC 27017:2026, the second edition of the code of practice for information security controls for cloud services, replacing the 2015 edition.
Key points
- Provides cloud-specific guidance building on ISO/IEC 27002.
- Applies to cloud service customers and cloud service providers.
- Clarifies the division of security responsibilities between customers and providers.
- Covers public, private and hybrid cloud deployments.
- Brings the standard into line with the updated ISO/IEC 27002 control set.
Many UK organisations use ISO/IEC 27017 alongside ISO/IEC 27001 certification to show cloud security assurance. Cloud providers should review their controls and plan a transition, and customers should revisit shared responsibility models in their contracts.
Source: ISO/IEC 27017:2026 (ISO)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.