| Scope and covered activity | ISO/IEC 27017 gives cloud-specific security control guidance for cloud service providers and cloud service customers. | CCM v4.1 contains 207 security and privacy controls across 17 cloud domains for providers and customers to assess and manage cloud risk. | Use ISO/IEC 27017 for ISO-aligned cloud guidance and CCM when its detailed controls, mappings, questionnaire, or CSA assurance route is required. Use both when both outcomes matter. |
|---|
| Who must act | ISO/IEC 27017 gives separate guidance to the cloud service provider and cloud service customer where their actions differ and common guidance where it is the same. | CCM uses shared-security-responsibility and service-model attributes to indicate how a control relates to providers and customers across IaaS, PaaS, and SaaS. | Map the responsible actor as well as the control objective. Similar control text can produce a different owner in a different service model. |
|---|
| Trigger or threshold | Adopt ISO/IEC 27017 when cloud services fall within an ISO/IEC 27001 or 27002-based control environment or when contracts and customers call for its guidance. | Adopt CCM when the organization needs cloud-specific control detail, vendor assessment through CAIQ, CCM mappings, continuous metrics, or a CSA STAR-aligned route. | Select frameworks from the required outcome. Neither framework has a universal legal commencement date. |
|---|
| Core obligations | ISO/IEC 27017 supplements selected ISO/IEC 27002 controls and adds seven cloud-specific controls, including shared roles, asset return or removal, virtual environment hardening, administrator operations, monitoring, cloud-service change, and virtual network alignment. | CCM expresses cloud security and privacy outcomes as individual control specifications grouped by domain and links them to implementation, auditing, responsibility, questionnaire, metric, and mapping material. | Keep the source control identifier on every task. A single task may support both frameworks, but its acceptance criteria must cover both texts. |
|---|
| Evidence and records | Evidence usually combines the responsibility agreement, provider information, customer configurations, operational records, risk decisions, and any ISO/IEC 27001 audit or certification material in scope. | Evidence can include control implementation records, CAIQ responses, auditing-guideline workpapers, metrics, STAR submissions or reports, and provider and customer artifacts tied to each CCM control. | A questionnaire response or crosswalk is not operating evidence. Link each answer to a current record and record who supplied it. |
|---|
| Timing and cadence | ISO/IEC 27017 review timing follows the organization's risk, change, supplier, incident, internal-audit, certification, and management-review cycles. | CCM timing follows the adopted release, assessment or STAR cycle, customer request, control-test period, and the organization's framework-transition plan. | Record framework versions and evidence periods separately. A current CCM mapping does not update an old control sample. |
|---|
| Assurance route | ISO/IEC 27017 can support an ISO/IEC 27001 ISMS and can be referenced in certification scope or customer assurance, but it is not a standalone certification scheme. | CCM supports assessment and CSA STAR programs. The result depends on the selected STAR level and assessment route; CCM itself is not legislation. | Name the exact certificate, attestation, self-assessment, audit, or contract claim. Do not shorten all of them to 'certified.' |
|---|
| Overlap and reuse | ISO/IEC 27017 records can support related CCM controls where the objective, actor, service, and implemented outcome align. | CCM mappings can identify likely ISO/IEC 27017 relationships but may leave unmatched detail or split one ISO control across several CCM controls. | Classify each relationship as full, partial, or none. Document the residual requirement before reusing evidence. |
|---|
| Practical decision rule | Use ISO/IEC 27017 as the primary guide when the control environment is organized around ISO/IEC 27001 and ISO/IEC 27002. | Use CCM as the primary register when the program, customer, vendor review, or STAR route requires CCM identifiers and artifacts. | If both apply, choose one primary register, preserve both identifiers and texts, and track framework-specific gaps. |
|---|