Skip to content
Back to Governance & ComplianceCompliance Framework

ISO/IEC 27017 & 27018: Cloud Security and Cloud Privacy

The cloud security and privacy extensions to ISO 27001

ISO/IEC 27017 and 27018 are the cloud extensions to ISO 27001: 27017 hardens cloud security for providers and customers, while 27018 protects personal data in public clouds. Together they prove your cloud stack is safe to trust.

What is ISO 27017/18?

ISO/IEC 27017 (Information Security Controls for Cloud Services) and ISO/IEC 27018 (Protection of PII in Public Clouds) are international standards that extend ISO/IEC 27002, currently published in their 2026 and 2025 editions respectively. ISO 27017 gives cloud-specific security guidance for both providers and customers, while ISO 27018 sets controls for protecting personally identifiable information (PII) processed in public clouds. Certification is achieved as an extension to an ISO 27001 certificate, not as a standalone credential.

ISO/IEC 27017:2026 provides implementation guidance for cloud-specific controls, covering both sides of the shared responsibility model: what cloud service providers must do, and what cloud customers remain accountable for. It addresses the areas generic information security standards leave ambiguous, such as virtual machine isolation, shared environment segregation, cloud asset return and deletion, and administrative separation between customer environments.

ISO/IEC 27018:2025 focuses on privacy: it sets controls for public clouds acting as PII processors, covering consent, transparency, data minimisation, subprocessor management, breach notification, and the rights of data subjects. For Australian organisations, ISO 27018 alignment maps closely to obligations under the Privacy Act 1988 and the Australian Privacy Principles, and it provides strong evidence for GDPR and CCPA due diligence. Because both standards build directly on ISO 27001, they are typically certified together as an extension audit, adding cloud and privacy assurance to an existing ISMS.

Who Needs It

Who Needs ISO 27017/18?

SaaS companies and cloud service providers processing customer data on AWS, Azure, or GCP

Organisations acting as PII processors for enterprise customers with strict privacy due diligence

Cloud customers who need assurance their use of shared cloud services is properly controlled

Businesses subject to the Privacy Act 1988 or selling into GDPR and CCPA regulated markets

Managed service providers hosting client workloads in multi-tenant environments

Organisations already certified to ISO 27001 that want to extend coverage to cloud operations

Key Requirements

What It Covers

Existing ISO 27001 ISMS

ISO 27017 and 27018 are extensions, not standalone standards: your ISMS scope and Statement of Applicability must be updated to include the cloud and privacy control sets.

Shared Responsibility Mapping

Documented allocation of security responsibilities between your organisation, your cloud providers, and your own customers for every in-scope service.

Cloud-Specific Controls

ISO 27017 controls covering virtual environment isolation, cloud asset return and deletion, administrator separation, and cloud service configuration management.

PII Processing Controls

ISO 27018 controls covering lawful processing, consent, purpose limitation, data minimisation, retention and disposal of personal information in the cloud.

Subprocessor & Supplier Management

Due diligence, contractual privacy terms, and ongoing monitoring for subprocessors and cloud suppliers handling PII on your behalf.

Transparency & Data Subject Rights

Published privacy notices, breach notification procedures, and operational processes for access, correction, and deletion requests.

Extension Audit

Your certification body assesses the 27017 and 27018 control sets alongside your ISO 27001 surveillance or recertification audit.

Business Value

Benefits of ISO 27017/18

Answer the cloud security and privacy sections of enterprise vendor assessments with certified evidence

Demonstrate Privacy Act, GDPR, and CCPA alignment without building a separate privacy programme

Clarify the shared responsibility model so nothing falls between you and your cloud providers

Differentiate your SaaS or managed service against competitors with a generic ISO 27001 certificate

Extend your existing ISMS at a fraction of the cost of a standalone privacy certification

Our Process

How We Help You Achieve It

1

Scoping

We map your cloud services, PII flows, and the provider/customer split to define the extension scope.

2

Gap Assessment

We benchmark your current cloud and privacy controls against the ISO 27017 and 27018 guidance.

3

SoA Update

We extend your Statement of Applicability and risk treatment plan to cover the additional control sets.

4

Control Implementation

We help you implement cloud-specific and PII protection controls, from subprocessor terms to data disposal.

5

Internal Audit

We audit the extended ISMS so the new controls are evidenced and effective before the external audit.

6

Extension Audit Support

We coordinate with your certification body to add 27017 and 27018 to your ISO 27001 certificate.

FAQ

Frequently Asked Questions

Ready to Start Your ISO 27017/18 Journey?

Begin with a free cybersecurity gap assessment to understand where you stand, then let our experts guide you to certification. If you would rather not run the implementation yourself, this is what our cyber security consulting firm does day to day.