What is BS EN ISO/IEC 27017:2026 - Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services about?
BS EN ISO/IEC 27017:2026 is an internationally recognized standard that gives you information security controls and guidance for cloud computing environments.
It is designed for both cloud service providers and cloud service customers, helping you manage cloud-specific security risks more effectively. It builds on BS EN ISO/IEC 27002:2022 by extending general security controls with cloud-specific guidance.
As a horizontal standard, it applies across all cloud deployment models, including private, public, hybrid, and multi-cloud environments. It gives you a consistent foundation for securing cloud services, regardless of how they are delivered or consumed.
Who is BS EN ISO/IEC 27017:2026 - Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services for?
This standard is for any organization that provides, uses, or manages cloud services and needs to strengthen cloud security.
BS EN ISO/IEC 27017:2026 is particularly relevant for:
- chief information security officers, overseeing cloud security strategy and governance;
- cloud security architects, designing secure cloud environments;
- cloud service providers, demonstrating security maturity and building customer trust;
- legal and data protection teams, ensuring cloud arrangements meet regulatory requirements;
- IT risk and compliance managers, managing cloud-related risks; and
procurement and vendor management teams, assessing cloud supplier security obligations.
What does BS EN ISO/IEC 27017:2026 - Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services cover?
This standard gives you guidance on addressing the security challenges specific to cloud environments.
BS EN ISO/IEC 27017:2026 covers:
- information security controls tailored to cloud computing;
- access management, cryptography, incident response, and supplier relationships;
- shared responsibilities between cloud providers and customers;
- risks linked to multi-tenancy, shared infrastructure, and layered suppliers;
- a consistent framework that supports all cloud deployment models.
It also recognizes that organizations can act as both cloud providers and customers, helping you manage security responsibilities across complex supply chains.
Why should you use BS EN ISO/IEC 27017:2026 - Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services?
If you rely on cloud services, you need confidence that your security approach is fit for purpose.
BS EN ISO/IEC 27017:2026 helps you:
- apply security controls that are designed specifically for cloud environments;
- extend your existing BS EN ISO/IEC 27001 or BS EN ISO/IEC 27002 work without starting again;
- clarify responsibilities between cloud providers and customers;
- manage risks linked to outsourced and multi-cloud environments;
- demonstrate security maturity and due diligence to customers, regulators, and auditors.
It also supports organizations building or hosting AI solutions, where cloud security directly affects system safety and reliability.
What’s changed?
BS EN ISO/IEC 27017:2026 is a revised edition that replaces BS EN ISO/IEC 27017:2015.
Key changes include:
- Alignment with BS EN ISO/IEC 27002:2022, using a simplified control structure.
- A total of 97 controls, reflecting modern cloud security needs.
- Four new cloud-specific controls covering:
- shared roles and responsibilities;
- cloud service partner roles;
- segregation in virtual environments; and
- detection and prevention of unauthorized cloud use.
- Updated scope and positioning as a horizontal standard across all cloud models.
These changes reflect the evolution of cloud computing, including increased complexity, supply chain risks, and the growing use of cloud infrastructure for AI.