How should teams handle Customer Controls under ISO/IEC 27017?
Use a five-step decision. Define the customer's legal, contractual, policy, availability, confidentiality, integrity, and recovery requirements; identify the exact service, tier, region, and provider capabilities; allocate each task between customer and provider; treat every capability gap; then test and approve the resulting control set. ISO/IEC 27017:2015 says customers should consider gaps before selection, manage service use to meet their requirements, and add controls when preset provider controls do not adequately mitigate risk.
Apply the service-model branch to each layer instead of using the service label as the answer. In IaaS, provider event logging can stop at infrastructure components while the customer logs its virtual machines and applications; backup generally resides with the customer unless the provider supplies it. A PaaS customer may also need to back up customer data produced through development capabilities, including executable files. In SaaS, the provider may operate more technical layers, but the customer still controls its service decision, customer identities, available configuration, customer procedures, and assigned handoffs.
When the provider supplies backup, request specifications for scope and schedule, methods and formats, encryption where relevant, retention, integrity verification, restore procedures and timescales, testing, and storage location. Verify those specifications against the customer's requirements. If the provider does not supply the needed backup capability, the standard assigns implementation to the customer; buying the service does not create a backup by itself.
Document each customer control against the named service, risk or requirement, responsible actor, configuration or procedure, provider dependency, evidence source, exception, and review trigger. A provider certificate can support a provider claim within its scope, but it does not show that the customer enabled a setting, reviewed access, collected its application logs, tested restoration, or completed another customer-operated task.
- Name the service owner and the customer owner for identity, configuration, logging, backup, incident response, evidence, change, continuity, and exit where each activity applies.
- Record the requirement, service and tier, allocation, provider dependency, expected setting or procedure, approval date, evidence location, exception, and next review trigger.
- Treat unavailable or fixed provider capabilities as a gap to resolve through another service tier, an added customer control, contract change, alternative service, or authorized risk acceptance.
ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.
The identical 2015 recommendation tells customers to compare requirements with service capabilities and add controls when preset provider controls leave risk gaps.