FAQGlobalISO/IEC 27017

ISO/IEC 27017 FAQ Cloud Admin Access

How should customer and provider cloud-administrator access be controlled under ISO/IEC 27017?

Map each administrative capability to the party that operates it, then apply risk-based authentication, approval, restriction, logging, supervision, and review.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Control each according to who can perform it and the damage it can cause. Identify provider and customer administrators, support paths, service identities, and emergency accounts; restrict their privileges; use authentication sufficient for the assessed risk; log delegated operations; and supervise customer operations that could cause unrecoverable damage. ISO/IEC 27017:2015 gives voluntary guidance for cloud service customers and providers. It does not create a universal legal duty, certification result, review interval, or mandatory use of ; contracts, laws, policies, risk treatment, or an ISO/IEC 27001 management system can make particular measures necessary. ISO lists the 2015 edition as published and a revision as under development.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams handle Cloud Admin Access under ISO/IEC 27017?

Start with one named service, service tier, region, administrative interface, and provider chain. List customer consoles, provider support access, APIs, hypervisor or orchestration functions where exposed, emergency accounts, and automated identities. For each capability, record whether the customer, provider, or both can use it and whether it can view data, change security, create or delete resources, terminate service, or affect recovery.

For customer cloud administrators, clause 9.2.3 says the customer should use authentication techniques sufficient for the identified risks and the provider should supply suitable capabilities. is the standard's example, not an unconditional rule for every administrative action. The customer should also ensure that access to cloud functions and data can be restricted under its access-control policy. Provider utilities capable of bypassing normal operating or security procedures should be limited to authorized personnel and reviewed and audited regularly.

Apply two additional branches. If the provider delegates an elevated action to the customer, clause 12.4.3 says the operation and its performance should be logged, and the customer should decide whether provider logging is adequate or add its own. If failure of a customer administrative operation could cause unrecoverable damage, CLD.12.1.5 says the customer should document the procedure and specify supervisor monitoring. Examples are installing, changing, or deleting virtual servers, networks, or storage; terminating cloud use; and backup or restoration.

  • Name the accountable service owner, the person or system receiving each privilege, the provisioner, the supervisor for critical operations, and the reviewer.
  • Record the service scope, administrative capability, risk, authentication method, approval, grant and expiry dates, logging route, supervision requirement, evidence location, exception, and next review trigger.
  • Separate routine user access, administration, approval, and review where the risk requires it.
  • Define emergency-access issuance, monitoring, expiry, and after-use review instead of leaving permanent fallback privileges.
  • Revoke or revalidate access when employment, role, service, supplier, or risk changes.
Citations
ISO/IEC 27017:2015 standard page

ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.

Question 2

What evidence shows cloud administrator access is controlled and current?

Keep the administrative-interface inventory, role design, approval, identity-provider settings, authentication configuration, current entitlement export, provider-support terms, emergency-account record, privileged-operation logs, critical-operation procedure, supervisor record, and completed review. Provider evidence should cover the contracted service and provider access; customer evidence should show the customer's own grants and settings.

Sample a new grant, role change, leaver, emergency use, delegated privileged action, and destructive or recovery operation where each exists. Match every human identity to a person and every workload identity to a controlled process. Record approved duties, authentication, grant and expiry, last use, log event, supervisor where required, reviewer, exception, and removal or revalidation.

  • Use source records from the system of work, not screenshots created only for audit day.
  • Keep exceptions visible as risk acceptance, corrective action, or management-review input.
  • Update linked registers when the answer changes an owner, risk, control, service, supplier, or review date.
Citations
Question 3

Who should approve Cloud Admin Access decisions under ISO/IEC 27017?

ISO/IEC 27017 allocates actions between customer and provider but does not assign the customer's internal job titles. As a practical governance model, the manager accountable for the service can approve customer administrator roles, the platform or identity owner can provision them, and someone independent of the access holder can review them where practical.

Supplier management and security should assess provider-administrator commitments and assurance for the contracted service. The authorized risk owner, not the access holder or provisioner, should decide whether an unresolved exception is acceptable.

  • Use a named owner, named backup, and named escalation forum.
  • Separate preparation work from risk acceptance and final approval.
  • Keep approval records with the evidence rather than in disconnected email threads.
Citations
Question 4

When should Cloud Admin Access be reviewed under ISO/IEC 27017?

ISO/IEC 27017:2015 does not set a fixed access-review interval. Set one from risk, applicable requirements, and the agreement, then review whenever a person's role or employment changes, a new administrative interface or identity type appears, provider support access changes, or an incident exposes misuse or weak monitoring.

Immediately review emergency access after use and revoke temporary privileges when the approved period ends. Record the decision, removal, unresolved exception, and next owner.

  • Set a planned review date and a change-trigger rule.
  • Use findings to update controls, procedures, contracts, risk registers, or training.
  • Carry unresolved items into management review or risk acceptance.
Citations
Primary sources

References and citations

iso.org
Referenced sections
  • Primary ISO listing for the current ISO/IEC 27001 ISMS requirements standard.
"Information security, cybersecurity and privacy protection — Information security management systems — Requirements"
iso.org
Referenced sections
  • Primary ISO listing for the ISO/IEC 27002 information security control guidance standard.
"Information security controls"
iso.org
Referenced sections
  • Primary ISO listing for cloud-service security control guidance.
"Code of practice for information security controls based on ISO/IEC 27002 for cloud services"
itu.int
Referenced sections
  • The identical 2015 recommendation covers risk-based authentication for customer cloud administrators, logging when privileged operations are delegated to the customer, and documented and monitored administrative procedures.
"If a privileged operation is delegated to the cloud service customer, the operation and performance of those operations should be logged."
Related guides

Explore more topics

ISO/IEC 27017 Audit Rights FAQ
ISO/IEC 27017 does not grant unrestricted cloud-provider audits. Define the contract route for independent assurance, supporting access, exceptions, and escalation.
ISO/IEC 27017 Certification Reality Guide
ISO/IEC 27017 is cloud control guidance, not a standalone management-system certification standard. Learn how to check the actual ISO/IEC 27001 claim and scope.
ISO/IEC 27017 Cloud Provider Checklist Template and Workflow
ISO/IEC 27017 cloud provider checklist covering service scope, shared responsibilities, agreements, tenant isolation, operations, evidence, and secure exit.
ISO/IEC 27017 Cloud Security FAQ
Answers to ISO/IEC 27017:2015 cloud-security questions on shared roles, agreements, administration, logging, assurance, virtualization, and customer controls.
ISO/IEC 27017 Cloud Service Agreements FAQ
Use ISO/IEC 27017 to define cloud security roles, provider measures, evidence, incident handling, supplier dependencies, and exit terms in the service agreement.
ISO/IEC 27017 Compliance Guide
How cloud providers and customers apply ISO/IEC 27017:2015 through scoped risks, allocated responsibilities, agreements, controls, evidence, and review.
ISO/IEC 27017 Control Mapping to ISO/IEC 27001 Guide
Map ISO/IEC 27017:2015 cloud guidance and CLD controls into an ISO/IEC 27001:2022 ISMS with edition-aware rationale, owners, evidence, and SoA treatment.
ISO/IEC 27017 CSP vs CSC Role Split Comparison
Compare ISO/IEC 27017 responsibilities for cloud service providers and customers, with service-model examples, evidence, and review triggers.
ISO/IEC 27017 Customer Controls FAQ
Identify the cloud controls the customer should assess, configure, operate, monitor, evidence, and review when provider controls do not meet every security requirement.
ISO/IEC 27017 Hyperscaler Evidence Pack
What an ISO/IEC 27017:2015 hyperscaler evidence pack should contain, how to test coverage, and where provider assurance must be joined to customer evidence.
ISO/IEC 27017 Hyperscaler Evidence Pack Workflow
A service-specific workflow for testing hyperscaler claims, collecting provider and customer evidence, resolving gaps, and approving cloud risk under ISO/IEC 27017:2015.
ISO/IEC 27017 Logging FAQ
Allocate cloud event logging and monitoring between provider and customer, verify accessible events, privileged operations, timestamps, retention, alerts, and evidence.
ISO/IEC 27017 Provider Evidence FAQ
Check whether a cloud provider's certificate, audit report, or self-assessment supports its claims for the entity, service, location, controls, and period in scope.
ISO/IEC 27017 Shared Responsibility FAQ
Allocate ISO/IEC 27017 cloud-security roles to named provider, customer, and upstream parties for one service, then document, communicate, implement, and review the split.
ISO/IEC 27017 Shared Responsibility Model Guide
How to allocate provider, customer, and shared cloud security activities under ISO/IEC 27017:2015, document hand-offs, and test the allocation against evidence.
ISO/IEC 27017 Virtualization Responsibilities FAQ
Allocate tenant isolation, virtual-machine hardening, administrative operations, images, snapshots, and virtual-network policy under ISO/IEC 27017.
ISO/IEC 27017 vs CSA CCM Comparison
Compare ISO/IEC 27017:2015 with CSA CCM v4.1 by scope, control structure, responsibility mapping, assurance use, and evidence.
ISO/IEC 27017 vs ISO/IEC 27018 Comparison
Compare ISO/IEC 27017:2015 cloud security guidance with ISO/IEC 27018:2025 public-cloud PII processor guidance by scope, role, controls, and evidence.
ISO/IEC 27017 vs SOC 2 Comparison
Compare ISO/IEC 27017 cloud control guidance with SOC 2 attestation reports by purpose, scope, criteria, period, evidence, and customer responsibilities.