- Current information-security control guidance to which ISO says ISO/IEC 27018:2025 is aligned.
"Information security controls"
Use this checklist to verify a public-cloud PII processor control set from scope through operation. Give each item an owner, evidence, an exception path, and a review trigger.
ISO/IEC 27018:2025 is the current edition. ISO published it in August 2025, aligned it with ISO/IEC 27002:2022, and added Annex B. Detailed checklist items drawn from the withdrawn 2019 edition are identified as historical guidance and must be reconciled to the 2025 text.
Structured answer sets in this page tree.
Cited legal and guidance references.
Complete the checklist for a defined provider entity and service, not for a cloud brand in general. Confirm the role first, then mark each item implemented, not applicable with a reason, or open with an owner and due date. ISO/IEC 27018 is voluntary guidance unless a contract or other binding requirement makes specified controls mandatory. A policy alone does not show that a control operated.
The service is in scope only where the provider supplies processing through the public-cloud model and processes PII on behalf of and according to a customer's instructions. Assess provider-controlled purposes separately. The same organization can be a processor for hosted customer content and a controller for another activity.
Record the ISO/IEC 27018 edition used. ISO published edition 3 on 26 August 2025 and withdrew the 2019 edition the same day. The current edition is aligned with ISO/IEC 27002:2022; the withdrawn edition was based on ISO/IEC 27002:2013. Reconcile older mappings rather than carrying clause numbers forward unchanged.
The 2019 edition said contract PII should not be processed for a purpose independent of the customer's instructions and should not be used for marketing or advertising without express consent that is not a condition of service. It also called for contractual specification of the information or technical measures the customer needs to support PII principal rights. Verify the corresponding 2025 controls before claiming current-edition conformance.
Allocate each security control to the party that can operate it in the actual SaaS, PaaS, or IaaS model. The 2019 edition covered customer access administration, cryptography information, event logs, subprocessor notice and flow-down, processing countries, legally binding disclosures, and customer incident notification. Applicable law and the 2025 edition may require additional or different controls.
Define the outcome for live data, temporary files, logs, replicas, backups, business-continuity copies, support systems, and subprocessor copies. The 2019 edition allowed return, transfer, secure deletion or destruction, anonymization, or archival depending on the agreed purpose and contract; it also called for a documented period for erasing unused temporary files.
A deletion statement is incomplete if it omits backups, retention exceptions, the disposal mechanism, or the period after service termination. Where law requires continued storage, document the legal basis, access restriction, owner, location, and final disposition trigger.
Give every applicable control an owner, evidence location, exception path, and review trigger.
Convert the checklist into tasks, evidence requests, exception decisions, and review checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
Close the checklist only when every item has evidence or an approved not-applicable rationale. A gap stays open when the team has a policy but cannot show operation, when the evidence covers a different service or period, or when a 2019 mapping has not been reconciled to the 2025 edition.
Match the external claim to the assurance obtained. State the provider entity, service, locations if relevant, ISO/IEC 27018 edition, assessment criteria, period or date, assessor, exceptions, and relationship to any ISO/IEC 27001 certificate. Do not turn a control mapping into a legal-compliance or certification claim.
"Information security controls"
"provided sufficient transparency is provided"
"Edition 3"