- Primary ISO listing for the current ISO/IEC 27001 ISMS requirements standard.
"Information security, cybersecurity and privacy protection — Information security management systems — Requirements"
Map ISO/IEC 27017 cloud guidance through risk treatment and the Statement of Applicability; do not substitute one edition's clause number for another.
ISO/IEC 27017:2015 follows ISO/IEC 27002:2013. A current ISO/IEC 27001:2022 ISMS uses the reorganized 2022 Annex A controls, so every link needs an edition, rationale, responsibility split, and evidence.
Structured answer sets in this page tree.
Cited legal and guidance references.
extends the control guidance in ISO/IEC 27002:2013 for cloud providers and customers. ISO/IEC 27001 supplies certifiable ISMS requirements; mapping the older cloud guidance to a 2022 ISMS therefore requires version-aware traceability, not a clause-number substitution.
Keep four layers separate: ISO/IEC 27001 ISMS requirements, its Annex A reference controls, ISO/IEC 27002 implementation guidance, and ISO/IEC 27017 cloud-specific guidance and additional controls. A cross-reference does not make guidance a certifiable requirement.
follows the 2013 ISO/IEC 27002 structure and adds seven CLD controls: shared roles, removal of customer assets, virtual-environment segregation, virtual-machine hardening, administrator operational security, cloud-service monitoring, and alignment of virtual and physical network security.
ISO/IEC 27001:2022 and ISO/IEC 27002:2022 reorganized and renumbered the control set. Map each 2015 item by purpose and risk treatment, record whether coverage is full or partial, and add an organization-specific control where no single 2022 control expresses the treatment.
For an ISO/IEC 27001-conformant ISMS, the 2015 standard says the should be extended to include its Annex A cloud controls when the organization intends to implement them. The organization still determines necessary controls through risk treatment and records inclusion, implementation status, and justification in its current SoA.
A useful map explains the relationship instead of listing two identifiers. It should show the source text's purpose, the cloud risk, the chosen ISO/IEC 27001 treatment, and what remains outside the target control.
Separate provider evidence from customer evidence. A provider control may support the treatment while a customer configuration, monitoring rule, access review, or recovery test remains necessary. For example, provider evidence for tenant segregation does not establish that an IaaS customer hardened its virtual machines, restricted required ports and services, enabled malware protection, or collected guest and application logs.
Build the map once for the organization's approved editions, then apply it to each cloud service through its risk assessment and responsibility model. A library crosswalk can suggest candidates, but the service record should explain the selected treatment and evidence.
Review ambiguous or partial mappings with the ISMS control owner. If the 2015 cloud objective is broader than the candidate 2022 control, retain the remainder as an additional control or separate treatment rather than declaring complete coverage.
Record both editions, mapping rationale, partial coverage, provider and customer owners, SoA treatment, and the evidence that shows each control operates.
Convert ISO/IEC 27017 Control Mapping to ISO/IEC 27001 into accountable tasks, evidence requests, and review checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
Correct maps that hide editions, equate guidance with requirements, or assume one 2022 control fully covers a broader cloud objective. A mapping is an implementation decision, not proof that the control operates.
Keep legal and contractual requirements in the same traceability chain but identify their source. ISO/IEC 27017 can help structure a treatment; it does not create the law or contract duty.
Review the mapping when the source or target standard changes, and reapply it when the service model, provider chain, architecture, agreement, risk, or responsibility boundary changes. Update the SoA, control register, evidence index, and service assessment together.
As of 24 July 2026, ISO lists ISO/IEC 27017 Edition 2 as under publication and says it will replace the 2015 edition. Edition 2 is based on ISO/IEC 27002:2022, but do not predict its final identifiers or overwrite the 2015 map until the published text is available and adopted.
"Information security, cybersecurity and privacy protection — Information security management systems — Requirements"
"Information security controls"
"Code of practice for information security controls based on ISO/IEC 27002 for cloud services"