- Supports keeping cloud-provider checklist decisions inside the ISMS evidence, ownership, and review process.
"Information security, cybersecurity and privacy protection — Information security management systems — Requirements"
Use this ISO/IEC 27017 checklist to decide whether a specific cloud service can meet the customer's security requirements and what each party should operate.
The checklist follows ISO/IEC 27017:2015 guidance. It is not an official form, a universal control set, or proof of certification. Adapt it to the service risk, agreement, architecture, jurisdiction, and the edition used.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this checklist to evaluate a cloud provider and the customer's ability to use the service securely. It is not a universal pass/fail certification checklist: select depth and evidence from the service risk, contract, architecture, and applicable legal or regulatory requirements.
Start with the legal provider entity, named service, deployment and service models, regions, data and workloads, administrators, interfaces, upstream providers, business dependency, and exit constraints. Evidence for another service, entity, region, or period does not answer the assessment.
Compare the customer's requirements with the provider's fixed and configurable capabilities before contracting. For every gap, choose another service, add an enforceable commitment, implement a customer control, or obtain authorized risk acceptance.
Confirm that the agreement allocates provider, customer, and shared responsibilities. ISO/IEC 27017 specifically addresses access, backup, cryptography, vulnerability management, incidents, testing, audit evidence, logging, continuity, and protection of information when the agreement ends.
Test relevant operations, including tenant isolation, virtual-machine and network configuration, privileged access, monitoring, logs, backup and recovery, incident notification, and supervised critical operations. The exact split changes with the service model and provider design.
Completion requires evidence for both sides of the responsibility boundary. A provider report can support controls operated by the provider, but it does not show that the customer enabled logging, restricted administrators, hardened workloads, or tested recovery.
Record the evidence's service scope, provider entity, locations, period, exceptions, and method. Where individual customer audits are impractical or add security risk, ISO/IEC 27017 allows for independent evidence, with sufficient transparency, or a disclosed provider self-assessment when an independent audit is impractical.
The customer service owner coordinates the assessment with security, architecture, legal or procurement, privacy where applicable, operations, and the provider. Control owners supply evidence for their allocated duties; only an authorized risk owner accepts unresolved residual risk.
Run the checklist before selection or renewal, then repeat it after material changes to the service, region, provider chain, architecture, , contract, or applicable requirements. Incidents, failed tests, and expiring assurance are additional triggers.
A yes/no answer without scope, owner, evidence, exception, and review trigger is not enough to support a service decision. Reject marketing claims and certificates that do not cover the named provider entity and service.
Do not assume that the provider performs a control because it operates the infrastructure. ISO/IEC 27017 notes, for example, that IaaS customers may be responsible for backing up data produced in their environment and for logging events in their own virtual machines and applications.
Keep the checklist with the risk decision and evidence index. When a trigger occurs, reopen the affected checks and update the , control evidence, agreement record, and downstream operating procedures together.
As of 24 July 2026, ISO lists Edition 2 of ISO/IEC 27017 as under publication and intended to replace the 2015 edition. Record the edition now, then assess the published replacement before changing control identifiers or evidence mappings.
Assign each check, attach service-specific evidence, record exceptions and approvals, and reopen the assessment when the service or provider boundary changes.
Convert ISO/IEC 27017 Cloud Provider Checklist into accountable tasks, evidence requests, and review checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
"Information security, cybersecurity and privacy protection — Information security management systems — Requirements"
"Information security controls"
"Code of practice for information security controls based on ISO/IEC 27002 for cloud services"