How should teams handle Cloud Service Agreements under ISO/IEC 27017?
First identify the exact customer and provider legal entities, named service and tier, service model, permitted locations, provider chain, incorporated documents, and effective versions. Clause 6.1.1 says both parties' information-security roles should be stated in an agreement. The customer should confirm it can perform its allocation; the provider should document its allocation with customers, upstream cloud providers, and suppliers. The customer remains accountable for the decision to use the service, while the provider is accountable for the security it states in the agreement.
For each relevant process, name the provider action, customer action, handoff, evidence, and escalation route. Clause 15.1.2 lists malware protection, backup, cryptographic controls, vulnerability and incident management, technical compliance checking, security testing, auditing, evidence and logs, termination protection, authentication and access control, and identity and access management. Add monitoring, continuity, data and record protection, capacity, and jurisdiction terms where the service or other requirements make them relevant.
Make incident terms operational. The provider documentation should define which incidents it reports, the level of disclosure about detection and response, the target notification timeframe, the notification procedure, contacts, and any remedies. Both parties need mechanisms to report an event to the other and let the customer track status. Do not replace these fields with a generic promise to provide notice.
Define provider changes by category, planned date and time, technical description, and notice of start and completion where an adverse security effect is possible. Cover changes inherited from an upstream cloud provider. For exit, list customer assets, export format and method, schedule, access period, return or removal steps, and deletion of all copies from provider systems. CLD.8.1.5 calls for a documented, timely process but does not prescribe a universal deletion certificate or fixed number of days.
- Name the customer service owner, provider contract contact, control owners, incident contacts, exit owner, reviewer, and risk acceptor.
- Record the operative document versions, service scope, assumptions, allocation decision, approval date, evidence location, exception, renewal date, and change-trigger rule.
- Record every gap between the customer's requirement and the provider's fixed terms as a negotiated change, customer control, alternative treatment, or explicit risk decision.
ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.
The identical 2015 recommendation says both parties' security roles should be stated in an agreement, lists processes whose allocation the customer should confirm, and covers timely return or removal of customer assets at termination.