Skip to main content
Framework library
Framework module · iso-27017-2026

ISO/IEC 27017

Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.

2026 · ISO/IEC 27017:2026 · published 2026-07-27

Standing today
Directory entry

00Answer

from the registry record
What is ISO/IEC 27017?
Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.
Who does ISO/IEC 27017 apply to?
ISO/IEC 27017 applies to cloud services, SaaS, technology, all sectors, global, per ISO/IEC 27017:2026.
What is the current version of ISO/IEC 27017?
The current edition is 2026, issued by ISO/IEC 27017:2026 and published 2026-07-27. Source: https://www.iso.org/standard/27017.
What does an assessment under ISO/IEC 27017 require?
No control catalog has been ingested for ISO/IEC 27017 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

ISO/IEC 27017 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Cloud shared responsibility · Cloud customer guidance · Cloud provider guidance · Virtualized environments
Applies to
cloud services · SaaS · technology · all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
2015Supersededdate not published
2026Current edition · supersedes 20152026-07-27

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to cloud services · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

  2. Also applies to cloud services · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.

  3. CSA STARSTAR Level 1 and Level 2

    Also applies to cloud services · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.

  4. Also applies to all sectors · The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.

ISO/IEC 27017 | ControlFrame