How should teams handle Virtualization Responsibilities under ISO/IEC 27017?
Apply three separate tests. First, if the service is multi-tenant, CLD.9.5.1 assigns the provider logical segregation of customer data, virtualized applications, operating systems, storage, and networks between tenants and from the provider's internal administration. The customer should define its segregation requirements and obtain evidence for the named service, tier, region, and architecture. A dedicated service may change the tenant-isolation test, but it does not remove access-control, hardening, administration, or network-policy duties.
Second, identify who configures each . CLD.9.5.2 tells customers and providers to harden the machines they configure for business needs, including allowing only needed ports, protocols, and services and applying appropriate measures such as anti-malware and logging. In an IaaS service, the customer commonly configures guest machines; in a managed platform or SaaS service, the provider may control the layer. Allocate images, snapshots, dormant or offline instances, guest operating systems, hypervisor exposure, self-service portals, and backups separately because the service label does not settle every layer.
Third, map the virtual network. CLD.13.1.4 assigns the provider the policy and verification duty: the provider should define a virtual-network security policy consistent with its physical-network policy and ensure that virtual configuration matches it regardless of how the configuration is created. The standard notes that the party configuring the virtual network can vary by service type. Customer-configurable rules still need a named customer owner and evidence, but the provider's stated consistency duty should not be reassigned solely because the customer enters the rule.
Document customer critical operations whose failure could cause unrecoverable damage, including installing, changing, or deleting virtual servers, networks, or storage; terminating cloud use; and backup or restoration. CLD.12.1.5 says the customer procedure should specify supervisor monitoring, while the provider should supply critical-operation documentation to customers who require it.
- Name the owner for isolation assurance, each customer-configured machine and image, virtual-network rules, critical-operation supervision, backup, and review.
- Record the service and tier, tenancy model, layer, configuring party, required baseline or policy, observed control, provider dependency, approval date, evidence location, exception, and next review trigger.
- Escalate any layer that neither party can configure, verify, or evidence, and record the resulting treatment before placing the workload in service.
ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.
The identical 2015 recommendation assigns logical segregation in multi-tenant virtual environments to the provider and hardening to whichever party configures the virtual machine.