How should teams handle Cloud Admin Access under ISO/IEC 27017?
Start with one named service, service tier, region, administrative interface, and provider chain. List customer consoles, provider support access, APIs, hypervisor or orchestration functions where exposed, emergency accounts, and automated identities. For each capability, record whether the customer, provider, or both can use it and whether it can view data, change security, create or delete resources, terminate service, or affect recovery.
For customer cloud administrators, clause 9.2.3 says the customer should use authentication techniques sufficient for the identified risks and the provider should supply suitable capabilities. is the standard's example, not an unconditional rule for every administrative action. The customer should also ensure that access to cloud functions and data can be restricted under its access-control policy. Provider utilities capable of bypassing normal operating or security procedures should be limited to authorized personnel and reviewed and audited regularly.
Apply two additional branches. If the provider delegates an elevated action to the customer, clause 12.4.3 says the operation and its performance should be logged, and the customer should decide whether provider logging is adequate or add its own. If failure of a customer administrative operation could cause unrecoverable damage, CLD.12.1.5 says the customer should document the procedure and specify supervisor monitoring. Examples are installing, changing, or deleting virtual servers, networks, or storage; terminating cloud use; and backup or restoration.
- Name the accountable service owner, the person or system receiving each privilege, the provisioner, the supervisor for critical operations, and the reviewer.
- Record the service scope, administrative capability, risk, authentication method, approval, grant and expiry dates, logging route, supervision requirement, evidence location, exception, and next review trigger.
- Separate routine user access, administration, approval, and review where the risk requires it.
- Define emergency-access issuance, monitoring, expiry, and after-use review instead of leaving permanent fallback privileges.
- Revoke or revalidate access when employment, role, service, supplier, or risk changes.
ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.
The identical 2015 recommendation covers risk-based authentication for customer cloud administrators, logging when privileged operations are delegated to the customer, and documented and monitored administrative procedures.