FAQGlobalISO/IEC 27017

ISO/IEC 27017 FAQ Virtualization Responsibilities

Who is responsible for virtualization security under ISO/IEC 27017?

In multi-tenant services, the provider should enforce tenant isolation; each party should harden the virtual machines it configures; and the provider should keep virtual-network configuration consistent with its physical-network security policy.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Allocate each , image, snapshot, guest operating system, hypervisor function, virtual network, storage layer, self-service portal, and backup capability to the party that can configure, operate, verify, and evidence it. In a multi-tenant service, the provider should isolate customer resources from other tenants and provider administration. Each customer or provider should harden the virtual machines it configures. The provider should define a virtual-network policy consistent with its physical-network policy and ensure the virtual configuration matches it, even though the party performing configuration can vary by service type. ISO/IEC 27017:2015 is voluntary guidance and sets no universal hardening baseline or review interval. ISO lists the 2015 edition as published and a revision as under development.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams handle Virtualization Responsibilities under ISO/IEC 27017?

Apply three separate tests. First, if the service is multi-tenant, CLD.9.5.1 assigns the provider logical segregation of customer data, virtualized applications, operating systems, storage, and networks between tenants and from the provider's internal administration. The customer should define its segregation requirements and obtain evidence for the named service, tier, region, and architecture. A dedicated service may change the tenant-isolation test, but it does not remove access-control, hardening, administration, or network-policy duties.

Second, identify who configures each . CLD.9.5.2 tells customers and providers to harden the machines they configure for business needs, including allowing only needed ports, protocols, and services and applying appropriate measures such as anti-malware and logging. In an IaaS service, the customer commonly configures guest machines; in a managed platform or SaaS service, the provider may control the layer. Allocate images, snapshots, dormant or offline instances, guest operating systems, hypervisor exposure, self-service portals, and backups separately because the service label does not settle every layer.

Third, map the virtual network. CLD.13.1.4 assigns the provider the policy and verification duty: the provider should define a virtual-network security policy consistent with its physical-network policy and ensure that virtual configuration matches it regardless of how the configuration is created. The standard notes that the party configuring the virtual network can vary by service type. Customer-configurable rules still need a named customer owner and evidence, but the provider's stated consistency duty should not be reassigned solely because the customer enters the rule.

Document customer critical operations whose failure could cause unrecoverable damage, including installing, changing, or deleting virtual servers, networks, or storage; terminating cloud use; and backup or restoration. CLD.12.1.5 says the customer procedure should specify supervisor monitoring, while the provider should supply critical-operation documentation to customers who require it.

  • Name the owner for isolation assurance, each customer-configured machine and image, virtual-network rules, critical-operation supervision, backup, and review.
  • Record the service and tier, tenancy model, layer, configuring party, required baseline or policy, observed control, provider dependency, approval date, evidence location, exception, and next review trigger.
  • Escalate any layer that neither party can configure, verify, or evidence, and record the resulting treatment before placing the workload in service.
Citations
ISO/IEC 27017:2015 standard page

ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.

Question 2

What evidence shows virtualization responsibilities are operating?

Keep the current service architecture, tenancy statement, layer-by-layer responsibility matrix, provider segregation assurance, customer and provider virtual-machine baselines where available, image controls, snapshot and dormant-instance inventory, virtual and physical network-policy mapping, privileged-operation logs, critical-operation procedure, and backup and restoration results.

Sample one active , image or snapshot, virtual-network rule set, isolation control claim, and critical administrative operation where each exists. Record the service and resource, configuring party, expected baseline or policy, observed result, evidence period, owner, reviewer, exception, follow-up owner, and due date.

  • Verify that unnecessary ports, protocols, and services are disabled on sampled customer-configured machines.
  • Confirm provider evidence covers the relevant multi-tenant service, region, and period rather than a generic provider entity.
  • Track unmanaged images, stale snapshots, dormant instances, policy mismatches, and failed critical operations to correction or authorized risk acceptance.
Citations
ISO/IEC 27001:2022 standard page

Primary ISO listing for ISMS requirements that frame ownership, evidence, risk treatment, and review of virtualization responsibilities.

Question 3

Who should approve Virtualization Responsibilities decisions under ISO/IEC 27017?

ISO/IEC 27017 allocates customer and provider duties but does not prescribe internal approval titles. As a practical model, the cloud service owner can approve the layer allocation; platform, network, image, backup, and security owners can accept customer activities; and supplier management can maintain provider commitments and assurance.

A supervisor should monitor the customer critical operations identified by the procedure. Send any unowned layer or unsupported provider assumption to the authorized risk owner.

  • Use a named owner, named backup, and named escalation forum.
  • Separate preparation work from risk acceptance and final approval.
  • Keep approval records with the evidence rather than in disconnected email threads.
Citations
ISO/IEC 27017:2015 standard page

Primary ISO listing for cloud-service security control guidance, including the cloud-specific control context used for virtualization responsibility splits.

Question 4

When should Virtualization Responsibilities be reviewed under ISO/IEC 27017?

ISO/IEC 27017:2015 sets no universal virtualization-review interval. Review when the tenancy or service model, hypervisor or orchestration platform, image pipeline, network architecture, provider feature, agreement, or responsibility boundary changes.

Also review after isolation findings, unexpected exposure, failed restoration, destructive administrative error, or stale-image discovery. Update the architecture, matrix, baseline, procedure, and risk treatment together.

  • Set a planned review date and a change-trigger rule.
  • Use findings to update controls, procedures, contracts, risk registers, or training.
  • Carry unresolved items into management review or risk acceptance.
Citations
ISO/IEC 27017:2015 standard page

Primary ISO listing for cloud-service security control guidance, including the cloud-specific control context used for virtualization responsibility splits.

Primary sources

References and citations

iso.org
Referenced sections
  • Primary ISO listing for ISMS requirements that frame ownership, evidence, risk treatment, and review of virtualization responsibilities.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • Primary ISO listing for the current ISO/IEC 27002 information-security control guidance.
"Information security controls"
iso.org
Referenced sections
  • Primary ISO listing for cloud-service security control guidance, including the cloud-specific control context used for virtualization responsibility splits.
"Code of practice for information security controls based on ISO/IEC 27002 for cloud services"
itu.int
Referenced sections
  • The identical 2015 recommendation assigns logical segregation in multi-tenant virtual environments to the provider and hardening to whichever party configures the virtual machine.
"Virtual machines in a cloud computing environment should be hardened to meet business needs."
Related guides

Explore more topics

ISO/IEC 27017 Audit Rights FAQ
ISO/IEC 27017 does not grant unrestricted cloud-provider audits. Define the contract route for independent assurance, supporting access, exceptions, and escalation.
ISO/IEC 27017 Certification Reality Guide
ISO/IEC 27017 is cloud control guidance, not a standalone management-system certification standard. Learn how to check the actual ISO/IEC 27001 claim and scope.
ISO/IEC 27017 Cloud Admin Access FAQ
Apply ISO/IEC 27017 to customer and provider cloud administrators: strong authentication, limited privileges, logged operations, supervised critical work, and review evidence.
ISO/IEC 27017 Cloud Provider Checklist Template and Workflow
ISO/IEC 27017 cloud provider checklist covering service scope, shared responsibilities, agreements, tenant isolation, operations, evidence, and secure exit.
ISO/IEC 27017 Cloud Security FAQ
Answers to ISO/IEC 27017:2015 cloud-security questions on shared roles, agreements, administration, logging, assurance, virtualization, and customer controls.
ISO/IEC 27017 Cloud Service Agreements FAQ
Use ISO/IEC 27017 to define cloud security roles, provider measures, evidence, incident handling, supplier dependencies, and exit terms in the service agreement.
ISO/IEC 27017 Compliance Guide
How cloud providers and customers apply ISO/IEC 27017:2015 through scoped risks, allocated responsibilities, agreements, controls, evidence, and review.
ISO/IEC 27017 Control Mapping to ISO/IEC 27001 Guide
Map ISO/IEC 27017:2015 cloud guidance and CLD controls into an ISO/IEC 27001:2022 ISMS with edition-aware rationale, owners, evidence, and SoA treatment.
ISO/IEC 27017 CSP vs CSC Role Split Comparison
Compare ISO/IEC 27017 responsibilities for cloud service providers and customers, with service-model examples, evidence, and review triggers.
ISO/IEC 27017 Customer Controls FAQ
Identify the cloud controls the customer should assess, configure, operate, monitor, evidence, and review when provider controls do not meet every security requirement.
ISO/IEC 27017 Hyperscaler Evidence Pack
What an ISO/IEC 27017:2015 hyperscaler evidence pack should contain, how to test coverage, and where provider assurance must be joined to customer evidence.
ISO/IEC 27017 Hyperscaler Evidence Pack Workflow
A service-specific workflow for testing hyperscaler claims, collecting provider and customer evidence, resolving gaps, and approving cloud risk under ISO/IEC 27017:2015.
ISO/IEC 27017 Logging FAQ
Allocate cloud event logging and monitoring between provider and customer, verify accessible events, privileged operations, timestamps, retention, alerts, and evidence.
ISO/IEC 27017 Provider Evidence FAQ
Check whether a cloud provider's certificate, audit report, or self-assessment supports its claims for the entity, service, location, controls, and period in scope.
ISO/IEC 27017 Shared Responsibility FAQ
Allocate ISO/IEC 27017 cloud-security roles to named provider, customer, and upstream parties for one service, then document, communicate, implement, and review the split.
ISO/IEC 27017 Shared Responsibility Model Guide
How to allocate provider, customer, and shared cloud security activities under ISO/IEC 27017:2015, document hand-offs, and test the allocation against evidence.
ISO/IEC 27017 vs CSA CCM Comparison
Compare ISO/IEC 27017:2015 with CSA CCM v4.1 by scope, control structure, responsibility mapping, assurance use, and evidence.
ISO/IEC 27017 vs ISO/IEC 27018 Comparison
Compare ISO/IEC 27017:2015 cloud security guidance with ISO/IEC 27018:2025 public-cloud PII processor guidance by scope, role, controls, and evidence.
ISO/IEC 27017 vs SOC 2 Comparison
Compare ISO/IEC 27017 cloud control guidance with SOC 2 attestation reports by purpose, scope, criteria, period, evidence, and customer responsibilities.