Skip to content

ISO 27017:2015

ISO 27017 certification online: Cloud Security by self-assessment

With the ISO 27017 certificate from Zertify, you demonstrate your management system online. ISO 27017 certification works by self-assessment: you receive the certificate within 4 hours and pay once, CHF 799. It is not an accredited certificate and does not replace an audit.

Questions
30
Validity
3 years
One-time price
CHF 799

01: Overview

What is ISO 27017?

ISO 27017:2015 is a code of practice for information security controls that apply specifically to cloud computing services. The standard supplements ISO 27001 and ISO 27002 with cloud-specific controls and addresses both cloud service providers and cloud customers. It defines roles and responsibilities and helps address security risks in cloud environments.

02: Benefits

Your benefits

  • Clear security responsibilities between provider and customer
  • Controls tailored to cloud environments
  • Complements and strengthens the ISO 27001 certificate
  • Trust among cloud customers and partners
  • Reduced risk when using cloud services
  • Compliance with cloud security requirements

03: Who it is for

Who is ISO 27017 for?

  • Cloud service providers (IaaS, PaaS, SaaS)
  • Companies that use cloud services
  • IT service providers with cloud offerings
  • Data centres and hosting providers
  • Software companies with cloud solutions
  • Managed service providers

04: Requirements

Key requirements

  1. Carry out a cloud-specific risk analysis

  2. Define responsibilities clearly (shared responsibility)

  3. Ensure data isolation and tenant segregation

  4. Guarantee secure deletion of customer data

  5. Implement virtualization security

  6. Establish cloud-specific incident response

05: Demand

Who asks for ISO 27017?

ISO 27017 is asked for where data moves to the cloud and customers want to know who is responsible for which security.

Customers of cloud providers
Companies that buy SaaS or hosting check the provider for tenant separation, administrator access and return of data.
SaaS and hosting providers
Anyone who sells cloud services is asked about ISO 27017 alongside ISO 27001 in security questionnaires, because it proves the cloud controls.
Regulated industries
Finance and healthcare demand a traceable split of responsibility and control over the provider when they outsource to the cloud.

06: Cost

What does ISO 27017 cost? Audit, consulting or self-assessment

ISO 27017 is usually not audited on its own but together with ISO 27001. The figures below therefore describe the surcharge for a company with 10 to 50 employees.

Indicative SME ranges compared: accredited audit, consulting and self-assessment
RouteIndicative rangeWhat is behind it
Accredited auditAs an extension of ISO 27001, CHF 2,000 to 5,000 on topThe extra cost comes from additional audit days for the cloud controls. Without an existing ISO 27001 certification, its cost is added.
Consulting and implementationCHF 5,000 to 15,000 one-offClarifying shared responsibility, hardening standard and logging. The effort is smaller when an ISMS already exists.
Zertify self-assessmentCHF 799 once, valid 3 yearsYou check whether shared responsibility, return of data, tenant separation and administrator access are demonstrably settled. It does not replace ISO 27001 certification.

All amounts are non-binding indicative ranges for Swiss SMEs, not quotes. The offers of the individual providers are what counts.

07: Duration

How long does ISO 27017 take?

If you already run an ISMS, you add ISO 27017 in a few months. Without an ISMS, the route starts at ISO 27001.

Timeline: accredited route compared with the self-assessment
PhaseAccreditedZertify
Add cloud controls2 to 4 months with an existing ISMS, otherwise 9 to 12 months including ISO 27001None. You rate the current state of your cloud use
AssessmentExtra audit days within the ISO 27001 audit, samples from cloud configurationAbout 20 to 30 minutes online, scored immediately
CertificateRelease after 2 to 6 weeks, valid within the ISO 27001 certification cyclePDF with QR verification within 4 hours

08: Sample questions

Sample questions from the ISO 27017 assessment

Four of 30 questions from the catalog, with the reason each one counts.

  1. Is the division of tasks between your company and the cloud provider documented in writing in a shared responsibility model?

    Without a written split of duties, each side assumes the other secures something. This model is the core of the standard.

  2. Is it contractually agreed that the cloud provider returns or verifiably deletes all customer data at the end of the contract?

    On termination the contract decides whether your data comes back and when it is deleted. After that it is too late to negotiate.

  3. Have you verified with the cloud provider that your data is strictly logically segregated from other tenants?

    Several customers share the same infrastructure. You have to make sure that your data is logically separated.

  4. Are privileged cloud administrator accounts protected with multi-factor authentication?

    A compromised administrator account opens the whole cloud environment. Multi-factor authentication is the simplest effective barrier.

09: Assessment

How the assessment works

The assessment consists of 30 yes/no questions. You answer them online, at your own pace. With 20 or more yes answers you pass.

The questions are grouped by these topics:
The questions are grouped by these topics:Questions
Shared responsibilities5 questions
Asset management and data return4 questions
Tenant segregation and isolation5 questions
Virtual machines and hardening4 questions
Administrator access and privilege management4 questions
Cloud monitoring and logging4 questions
Network security in the cloud2 questions
Incident response in the cloud2 questions

10: Price

Price and validity

One-time price

CHF 799

Renewal after 3 years
CHF 479
Validity
3 years
Start assessment

What is included

  • Online assessment with 30 questions
  • Certificate as PDF, issued by SICE
  • QR code for public verification
  • 3 years of validity
  • Support by email

The certificate is based on a self-assessment. It is not an accredited certification. Read more in the FAQ

11: More standards

More standards

Many companies combine several standards. From two standards you get a discount.

  • ISO 27001:2022: View standard

    Information Security Management

    ISO 27017 builds on the ISMS. Without risk analysis, SoA and audits the foundation is missing.

    from CHF 849

  • ISO 27018:2019: View standard

    Cloud Privacy

    If the cloud holds personal data, ISO 27018 adds data protection duties such as purpose limitation and deletion to the technical controls.

    from CHF 799

12: Questions

Frequently asked questions about ISO 27017

ISO 27017 certificate within 4 hours.

Start the assessment for free. You only pay after you pass.

The certificate is based on a self-assessment. It is not an accredited certification.