Phone: (011) 7541-421, 3409-301, 3409-335, 6547-293, 3409-310
E-mail: Standards sales: prodaja@iss.rs Education: iss-edukacija@iss.rs Information about standards: infocentar@iss.rs
Stevana Brakusa 2, 11030 Beograd
Main menu

ISO/IEC 27017:2026

Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services

Jul 27, 2026

General information

60.60     Jul 27, 2026

ISO/IEC

ISO/IEC JTC 1/SC 27

International Standard

03.100.70     35.030  

English   French  

Buying

Published

Language in which you want to receive the document.

Scope

This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:

additional guidance for relevant controls specified in ISO/IEC 27002:2022;
additional controls with guidance that specifically relate to cloud services.

This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE            This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.

Life cycle

PREVIOUSLY

WITHDRAWN
ISO/IEC 27017:2015

NOW

PUBLISHED
ISO/IEC 27017:2026
60.60 Standard published
Jul 27, 2026

National adoptions

Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)

50.60   Close of voting. Proof returned by secretariat

I224 more