Register

What is the ISO/IEC 27017:2015 standard?

ISO 27017:2015 is a code of practice which provides guidelines on how to manage information security controls based on ISO/IEC 27002 for cloud services. It is intended for use by organizations that provide a cloud service, as well as by organizations that use a cloud service.


ISO 27017:2015 specifies guidelines for implementing information security controls in a cloud computing environment. It also provides recommendations and guidance on how to manage information security risks associated with the use of cloud services.


Download the ISO/IEC 27017:2015 certificate.

FAQ

What is the relationship between ISO 27017:2015 and ISO/IEC 27001:2013?

ISO 27017:2015 provides guidelines on how to manage information security controls based on ISO/IEC 27002 for cloud services. It is intended for use by both cloud service providers and cloud service users.

ISO/IEC 27001:2013 is the international standard that specifies requirements for an ISMS. It is intended for use by organizations in any sector.

ISO 27017:2015 and ISO/IEC 27001:2013 are intended for use together to provide a set of best practice recommendations for managing information security risks in cloud computing environments.

Download additional compliance reports from the Exoscale compliance center.

Exoscale

Contact our Compliance Team

A doubt? Unsure if we comply to a specific regulation not listed here?

Contact our Compliance Team and let us know your requirements. It may be covered by other certifications or regulations we comply to.