ISO 27017:2015
ISO 27017 certification online: Cloud Security by self-assessment
With the ISO 27017 certificate from Zertify, you demonstrate your management system online. ISO 27017 certification works by self-assessment: you receive the certificate within 4 hours and pay once, CHF 799. It is not an accredited certificate and does not replace an audit.
- Questions
- 30
- Validity
- 3 years
- One-time price
- CHF 799
01: Overview
What is ISO 27017?
ISO 27017:2015 is a code of practice for information security controls that apply specifically to cloud computing services. The standard supplements ISO 27001 and ISO 27002 with cloud-specific controls and addresses both cloud service providers and cloud customers. It defines roles and responsibilities and helps address security risks in cloud environments.
02: Benefits
Your benefits
- Clear security responsibilities between provider and customer
- Controls tailored to cloud environments
- Complements and strengthens the ISO 27001 certificate
- Trust among cloud customers and partners
- Reduced risk when using cloud services
- Compliance with cloud security requirements
03: Who it is for
Who is ISO 27017 for?
- Cloud service providers (IaaS, PaaS, SaaS)
- Companies that use cloud services
- IT service providers with cloud offerings
- Data centres and hosting providers
- Software companies with cloud solutions
- Managed service providers
04: Requirements
Key requirements
Carry out a cloud-specific risk analysis
Define responsibilities clearly (shared responsibility)
Ensure data isolation and tenant segregation
Guarantee secure deletion of customer data
Implement virtualization security
Establish cloud-specific incident response
05: Demand
Who asks for ISO 27017?
ISO 27017 is asked for where data moves to the cloud and customers want to know who is responsible for which security.
- Customers of cloud providers
- Companies that buy SaaS or hosting check the provider for tenant separation, administrator access and return of data.
- SaaS and hosting providers
- Anyone who sells cloud services is asked about ISO 27017 alongside ISO 27001 in security questionnaires, because it proves the cloud controls.
- Regulated industries
- Finance and healthcare demand a traceable split of responsibility and control over the provider when they outsource to the cloud.
06: Cost
What does ISO 27017 cost? Audit, consulting or self-assessment
ISO 27017 is usually not audited on its own but together with ISO 27001. The figures below therefore describe the surcharge for a company with 10 to 50 employees.
| Route | Indicative range | What is behind it |
|---|---|---|
| Accredited audit | As an extension of ISO 27001, CHF 2,000 to 5,000 on top | The extra cost comes from additional audit days for the cloud controls. Without an existing ISO 27001 certification, its cost is added. |
| Consulting and implementation | CHF 5,000 to 15,000 one-off | Clarifying shared responsibility, hardening standard and logging. The effort is smaller when an ISMS already exists. |
| Zertify self-assessment | CHF 799 once, valid 3 years | You check whether shared responsibility, return of data, tenant separation and administrator access are demonstrably settled. It does not replace ISO 27001 certification. |
All amounts are non-binding indicative ranges for Swiss SMEs, not quotes. The offers of the individual providers are what counts.
07: Duration
How long does ISO 27017 take?
If you already run an ISMS, you add ISO 27017 in a few months. Without an ISMS, the route starts at ISO 27001.
| Phase | Accredited | Zertify |
|---|---|---|
| Add cloud controls | 2 to 4 months with an existing ISMS, otherwise 9 to 12 months including ISO 27001 | None. You rate the current state of your cloud use |
| Assessment | Extra audit days within the ISO 27001 audit, samples from cloud configuration | About 20 to 30 minutes online, scored immediately |
| Certificate | Release after 2 to 6 weeks, valid within the ISO 27001 certification cycle | PDF with QR verification within 4 hours |
08: Sample questions
Sample questions from the ISO 27017 assessment
Four of 30 questions from the catalog, with the reason each one counts.
Is the division of tasks between your company and the cloud provider documented in writing in a shared responsibility model?
Without a written split of duties, each side assumes the other secures something. This model is the core of the standard.
Is it contractually agreed that the cloud provider returns or verifiably deletes all customer data at the end of the contract?
On termination the contract decides whether your data comes back and when it is deleted. After that it is too late to negotiate.
Have you verified with the cloud provider that your data is strictly logically segregated from other tenants?
Several customers share the same infrastructure. You have to make sure that your data is logically separated.
Are privileged cloud administrator accounts protected with multi-factor authentication?
A compromised administrator account opens the whole cloud environment. Multi-factor authentication is the simplest effective barrier.
09: Assessment
How the assessment works
The assessment consists of 30 yes/no questions. You answer them online, at your own pace. With 20 or more yes answers you pass.
| The questions are grouped by these topics: | Questions |
|---|---|
| Shared responsibilities | 5 questions |
| Asset management and data return | 4 questions |
| Tenant segregation and isolation | 5 questions |
| Virtual machines and hardening | 4 questions |
| Administrator access and privilege management | 4 questions |
| Cloud monitoring and logging | 4 questions |
| Network security in the cloud | 2 questions |
| Incident response in the cloud | 2 questions |
10: Price
Price and validity
What is included
- Online assessment with 30 questions
- Certificate as PDF, issued by SICE
- QR code for public verification
- 3 years of validity
- Support by email
The certificate is based on a self-assessment. It is not an accredited certification. Read more in the FAQ
11: More standards
More standards
Many companies combine several standards. From two standards you get a discount.
- ISO 27001:2022: View standard
Information Security Management
ISO 27017 builds on the ISMS. Without risk analysis, SoA and audits the foundation is missing.
from CHF 849
- ISO 27018:2019: View standard
Cloud Privacy
If the cloud holds personal data, ISO 27018 adds data protection duties such as purpose limitation and deletion to the technical controls.
from CHF 799
12: Questions
Frequently asked questions about ISO 27017
ISO 27017 certificate within 4 hours.
Start the assessment for free. You only pay after you pass.
The certificate is based on a self-assessment. It is not an accredited certification.