Side-by-sideGlobalISO/IEC 27017

ISO/IEC 27017 vs ISO/IEC 27018

Use ISO/IEC 27017 for cloud security responsibilities and ISO/IEC 27018:2025 when a public cloud provider processes PII for a customer.

The standards complement each other. Neither replaces applicable privacy law, the controller's duties, the processing contract, or service-specific risk assessment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ISO/IEC 27017:2015 covers cloud information security for providers and customers. ISO/IEC 27018:2025 covers protection of personally identifiable information (PII) in public cloud services when the provider acts as a . Apply ISO/IEC 27017 to the service's broader cloud security boundary and add ISO/IEC 27018 only where the public-cloud, PII, and processor conditions are met.

Side-by-side comparison

ISO/IEC 27017 vs ISO/IEC 27018: scope, duties, evidence, and decision rule

Compare the service scope, actor test, control focus, evidence, and limits of reuse between the two standards.

Review all sources
First framework
ISO/IEC 27017

Cloud information security guidance for providers and customers across the provision and use of cloud services.

Second framework
ISO/IEC 27018

PII protection guidance for public cloud providers acting as PII processors, with privacy-specific controls and implementation guidance.

Comparison row 1

Scope and covered activity

ISO/IEC 27017

ISO/IEC 27017 gives cloud-specific security control guidance for cloud service providers and cloud service customers.

ISO/IEC 27018

ISO/IEC 27018:2025 applies to protection of PII in public cloud services when the cloud service provider acts as a .

Operational implication

Apply ISO/IEC 27017 broadly to cloud security. Add ISO/IEC 27018 only after documenting the public-cloud, PII, and processor conditions.

Comparison row 2

Who must act

ISO/IEC 27017

The cloud service provider and cloud service customer each receive guidance; their actions depend on the agreed security responsibility allocation and service model.

ISO/IEC 27018

The public cloud provider is the and the cloud customer is normally the party giving processing instructions. Controller duties and any provider processing for its own purposes need separate analysis.

Operational implication

Record roles by processing purpose and service. One organization can act as processor for one activity and controller for another.

Comparison row 3

Trigger or threshold

ISO/IEC 27017

ISO/IEC 27017 is relevant when an organization provides or uses a cloud service and adopts its cloud-specific security guidance.

ISO/IEC 27018

ISO/IEC 27018 becomes relevant when a public cloud provider processes PII on behalf of a customer as a .

Operational implication

The presence of PII alone does not decide scope. Confirm the deployment model and role before assigning ISO/IEC 27018 controls.

Comparison row 4

Core obligations

ISO/IEC 27017

ISO/IEC 27017 covers broader cloud security topics such as responsibility allocation, customer assets, administrative operations, monitoring, change, virtual environments, and network alignment.

ISO/IEC 27018

ISO/IEC 27018 adds privacy guidance for public-cloud processor activities, including support for PII principals' rights, instructions, disclosures, transfers, return or deletion, and PII breach handling.

Operational implication

Maintain one integrated control plan but preserve the source and owner for every security and privacy outcome.

Comparison row 5

Evidence and records

ISO/IEC 27017

Evidence includes the service and responsibility scope, agreements, provider assurance, customer configurations, access reviews, logs, backup tests, vulnerability records, change notices, and incident records.

ISO/IEC 27018

Evidence adds the processing and role record, instructions, PII location and transfer records, subprocessors, disclosures, assistance requests, deletion or return results, and PII breach records.

Operational implication

Reuse a record only when it covers the correct entity, service, role, PII, location, control, period, and exception status.

Comparison row 6

Timing and cadence

ISO/IEC 27017

ISO/IEC 27017 review timing follows service selection, risk, architecture, supplier, contract, incident, audit, and service-change cycles.

ISO/IEC 27018

ISO/IEC 27018 review timing also follows changes in processing purpose, PII, processor role, public-cloud status, location, subprocessors, and the privacy contract.

Operational implication

Neither standard sets one universal compliance deadline. Track framework editions, contract dates, assurance periods, and legal deadlines separately.

Comparison row 7

Assurance and legal effect

ISO/IEC 27017

ISO/IEC 27017 can support an ISO/IEC 27001 control environment, certification scope, internal audit, contract, or customer assurance, but it is not legislation or a standalone certification scheme.

ISO/IEC 27018

ISO/IEC 27018 can support privacy control design and assurance for its stated scope, but it does not replace binding privacy law or decide controller and processor roles.

Operational implication

State the exact certification, audit, contract, or legal claim. Do not present adoption of either guidance standard as automatic legal compliance.

Comparison row 8

Overlap and reuse

ISO/IEC 27017

Security records under ISO/IEC 27017 can support overlapping ISO/IEC 27018 controls, including access, logging, incident, supplier, and deletion-related evidence.

ISO/IEC 27018

ISO/IEC 27018 still requires evidence for its narrower processor and PII outcomes that a general cloud security record may not cover.

Operational implication

Link shared evidence once, then list the privacy-specific gap and owner rather than claiming the two control sets are equivalent.

Comparison row 9

Practical decision rule

ISO/IEC 27017

Use ISO/IEC 27017 for the cloud service's security responsibility and control model.

ISO/IEC 27018

Add ISO/IEC 27018:2025 for public-cloud PII processing performed by the provider as processor.

Operational implication

If ISO/IEC 27018 does not apply, keep the privacy analysis under the relevant law, contract, and other applicable standards rather than forcing this control set onto the service.

Practical decision rule

What is the practical decision rule?

  • Apply ISO/IEC 27017 to the security of providing and using the cloud service.
  • Add ISO/IEC 27018:2025 when a public cloud provider processes PII as a processor for the customer.
  • Keep applicable privacy law, controller duties, processor contract terms, and service-specific risk decisions visible as separate sources.
Section 1

Which standard applies to the cloud service?

Use ISO/IEC 27017 for the security of providing and using a cloud service, whether the service is public, private, community, or hybrid and whether or not it processes PII. It addresses provider and customer responsibilities across the cloud service.

Add ISO/IEC 27018:2025 when the service is a public cloud, PII is processed, and the provider acts as a under contract to the customer. For example, a multi-tenant SaaS provider processing a customer's employee records only on that customer's instructions can meet those scope conditions. The same provider's separate use of account contact data for purposes it determines can place that activity outside the processor scope. A provider acting as a controller, or a private-cloud arrangement outside that scope, needs separate privacy analysis even if some guidance remains useful.

Record the standard edition and the organization's role for each service. ISO/IEC 27018:2019 was withdrawn when the 2025 third edition was published; the 2025 edition aligns with ISO/IEC 27002:2022 and adds extended implementation guidance in Annex B.

  • Test four facts for ISO/IEC 27018: public cloud, PII processing, provider acting as processor, and processing under contract for the customer.
  • Apply ISO/IEC 27017 to the broader service security boundary and map overlap without dropping privacy-specific controls.
  • Check applicable privacy law and contract separately; an ISO claim does not decide the legal role or establish legal compliance.
Section 2

What evidence belongs to each standard?

ISO/IEC 27017 evidence should show how provider and customer security duties work across the service. ISO/IEC 27018 evidence should additionally show the public-cloud scope and the privacy controls applied to processing on the customer's behalf.

Some records support both standards, such as the contract, access controls, incident records, deletion results, supplier information, and independent assurance. Reuse them only when the entity, service, role, data, location, control, period, and exception coverage match.

  • ISO/IEC 27017: responsibility matrix, cloud agreement, service description, customer configuration, access review, logs, backup or restore tests, change notices, and incident records.
  • ISO/IEC 27018: processing scope, processor instructions, PII locations and transfers, subprocessor records, disclosure handling, data-subject assistance, return or deletion evidence, and PII breach records.
  • Shared assurance: exact entity and service, applicable criteria, assessment period, exceptions, subservice organizations, and customer actions.
  • Decision record: role analysis, applicable edition, gaps, owner, remediation or risk decision, and review trigger.
Section 3

How should teams apply the standards together?

First scope the cloud service and allocate security responsibilities under ISO/IEC 27017. Then identify PII, determine whether the service is public cloud, and document whether the provider acts as processor for the relevant processing.

Where ISO/IEC 27018 applies, add its privacy-specific control set and extended guidance. Map overlapping controls to shared evidence, but retain separate tasks for privacy purpose, instructions, disclosures, data-subject support, return or deletion, and other processor-specific outcomes.

  • Scope the service, deployment model, provider chain, data, regions, agreement, and provider/customer security boundary.
  • Identify PII processing and document controller or processor roles for each purpose rather than for the organization as a whole.
  • Map security and privacy controls, owners, evidence, gaps, and applicable legal or contractual duties.
  • Review the result when processing purpose, data, role, subprocessor, location, service, or contract changes.
Section 4

What scope mistakes should teams avoid?

Do not apply ISO/IEC 27018 to every cloud service merely because it stores account data. The scope depends on public-cloud processing of PII by a provider acting as processor. A service can contain several processing activities with different roles.

Do not treat ISO/IEC 27018 as a replacement for ISO/IEC 27017 or privacy law. It narrows the subject to public-cloud protection, while ISO/IEC 27017 covers broader cloud security and law supplies binding duties.

  • Do not use the withdrawn 2019 edition as the current baseline without a documented transition reason.
  • Do not infer the provider's processor role from a certificate; determine the role from the actual purposes and contract.
  • Do not assume security evidence covers processor-specific privacy controls.
  • Do not claim that either standard by itself establishes compliance with a jurisdiction's privacy law.
Section 5

When should applicability and evidence be reviewed?

Review before onboarding and after changes to processing purpose, PII categories, controller or processor role, public-cloud status, region, subprocessor, service architecture, contract, or assurance scope. A PII breach or failed deletion test should trigger a targeted review.

For organizations moving from ISO/IEC 27018:2019, record how the 2025 edition's alignment with ISO/IEC 27002:2022 and extended implementation guidance affect the control map, evidence, and open remediation.

  • Keep the applicable standard edition in the service and control registers.
  • Recheck the legal role by processing purpose when the service or contract changes.
  • Track gaps to remediation or an authorized risk decision without presenting that decision as legal compliance.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO listing used for management-system context when comparing cloud security and cloud privacy controls.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO listing for the current ISO/IEC 27002 information-security control guidance.
"Information security controls"
iso.org
Referenced sections
  • ISO listing used to support ISO/IEC 27017 cloud-service security controls for providers and customers.
"Code of practice for information security controls based on ISO/IEC 27002 for cloud services"
iso.org
Referenced sections
  • Official ISO scope and lifecycle page for the published third edition, ISO/IEC 27018:2025, covering PII protection in public clouds where the provider acts as a PII processor.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27017 Audit Rights FAQ
ISO/IEC 27017 does not grant unrestricted cloud-provider audits. Define the contract route for independent assurance, supporting access, exceptions, and escalation.
ISO/IEC 27017 Certification Reality Guide
ISO/IEC 27017 is cloud control guidance, not a standalone management-system certification standard. Learn how to check the actual ISO/IEC 27001 claim and scope.
ISO/IEC 27017 Cloud Admin Access FAQ
Apply ISO/IEC 27017 to customer and provider cloud administrators: strong authentication, limited privileges, logged operations, supervised critical work, and review evidence.
ISO/IEC 27017 Cloud Provider Checklist Template and Workflow
ISO/IEC 27017 cloud provider checklist covering service scope, shared responsibilities, agreements, tenant isolation, operations, evidence, and secure exit.
ISO/IEC 27017 Cloud Security FAQ
Answers to ISO/IEC 27017:2015 cloud-security questions on shared roles, agreements, administration, logging, assurance, virtualization, and customer controls.
ISO/IEC 27017 Cloud Service Agreements FAQ
Use ISO/IEC 27017 to define cloud security roles, provider measures, evidence, incident handling, supplier dependencies, and exit terms in the service agreement.
ISO/IEC 27017 Compliance Guide
How cloud providers and customers apply ISO/IEC 27017:2015 through scoped risks, allocated responsibilities, agreements, controls, evidence, and review.
ISO/IEC 27017 Control Mapping to ISO/IEC 27001 Guide
Map ISO/IEC 27017:2015 cloud guidance and CLD controls into an ISO/IEC 27001:2022 ISMS with edition-aware rationale, owners, evidence, and SoA treatment.
ISO/IEC 27017 CSP vs CSC Role Split Comparison
Compare ISO/IEC 27017 responsibilities for cloud service providers and customers, with service-model examples, evidence, and review triggers.
ISO/IEC 27017 Customer Controls FAQ
Identify the cloud controls the customer should assess, configure, operate, monitor, evidence, and review when provider controls do not meet every security requirement.
ISO/IEC 27017 Hyperscaler Evidence Pack
What an ISO/IEC 27017:2015 hyperscaler evidence pack should contain, how to test coverage, and where provider assurance must be joined to customer evidence.
ISO/IEC 27017 Hyperscaler Evidence Pack Workflow
A service-specific workflow for testing hyperscaler claims, collecting provider and customer evidence, resolving gaps, and approving cloud risk under ISO/IEC 27017:2015.
ISO/IEC 27017 Logging FAQ
Allocate cloud event logging and monitoring between provider and customer, verify accessible events, privileged operations, timestamps, retention, alerts, and evidence.
ISO/IEC 27017 Provider Evidence FAQ
Check whether a cloud provider's certificate, audit report, or self-assessment supports its claims for the entity, service, location, controls, and period in scope.
ISO/IEC 27017 Shared Responsibility FAQ
Allocate ISO/IEC 27017 cloud-security roles to named provider, customer, and upstream parties for one service, then document, communicate, implement, and review the split.
ISO/IEC 27017 Shared Responsibility Model Guide
How to allocate provider, customer, and shared cloud security activities under ISO/IEC 27017:2015, document hand-offs, and test the allocation against evidence.
ISO/IEC 27017 Virtualization Responsibilities FAQ
Allocate tenant isolation, virtual-machine hardening, administrative operations, images, snapshots, and virtual-network policy under ISO/IEC 27017.
ISO/IEC 27017 vs CSA CCM Comparison
Compare ISO/IEC 27017:2015 with CSA CCM v4.1 by scope, control structure, responsibility mapping, assurance use, and evidence.
ISO/IEC 27017 vs SOC 2 Comparison
Compare ISO/IEC 27017 cloud control guidance with SOC 2 attestation reports by purpose, scope, criteria, period, evidence, and customer responsibilities.