ISO/IEC 27017:2015: the clauses behind the split
The code of practice for information security in cloud services, written for both the customer and the provider. It allocates each control between the two, which is why its clause stands behind every split. Always shown.
Shown on every map. The framework on the compliance library.
Control areas it anchors
14Every clause cited, quoted
20 of the 44 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
ISO/IEC 27017 5.1.1 Policies for information securityThe cloud service customer's information security policy should address the use of cloud services: which information may be placed in which services, who may procure them, how the customer keeps accountability for information a provider processes, and the provider's obligations the customer expects to see in the agreement. The cloud service provider's policy should cover the security of the cloud service it delivers, including its baseline of protection for customer information, multi-tenancy, customer access to the service's security functions, and the boundary between its responsibilities and the customer's.
- Information security policy with a cloud services section (customer)
- Provider policy stating the baseline security of the service and the shared-responsibility boundary
- Approval record and communication of the policy to cloud users or customers
- Corporate policy silent on cloud, so business units adopt services with no rule on what data may go there
- Provider policy that does not state what the customer remains responsible for
ISO/IEC 27017 6.1.1 Information security roles and responsibilitiesRoles and responsibilities for the security of each cloud service should be allocated between the cloud service customer and the cloud service provider and inside each organisation. The customer should assign who owns the relationship, who manages customer-side controls and who evaluates the provider's information; the provider should state which responsibilities it accepts and which remain with the customer for each service it offers, so that no control falls between the two.
- Responsibility matrix per cloud service naming customer and provider owners
- Provider service description or terms stating accepted responsibilities
- Internal role assignments for cloud relationship and control ownership
- A control both parties assume the other performs, typically backup, logging or key management
- Responsibility matrix drafted at onboarding and never updated for new service features
ISO/IEC 27017 8.1.1 Inventory of assetsThe cloud service customer's asset inventory should record the information and assets it holds in each cloud service, so that cloud-hosted assets are not invisible to its own management. The cloud service provider should inventory the assets associated with the cloud service, including the assets of each customer that it holds, in a way that lets it identify and separate them by customer.
- Customer asset inventory with entries for cloud-hosted information and services
- Provider inventory identifying customer assets by customer
- Inventory review records
- Cloud-hosted data absent from the inventory because it was never on the customer's own systems
- Provider inventory that cannot tell which customer a stored asset belongs to
ISO/IEC 27017 8.2.2 Labelling of informationThe customer should label information according to its classification before and while it is in a cloud service, using labelling the service can carry, and the provider should describe what labelling capability the service offers and whether labels survive processing. Both should agree how labels are handled where the provider's staff can see customer information.
- Labelling scheme applied to cloud-hosted information
- Provider documentation of labelling features
- Test that labels persist through the service
- Labels stripped when information is uploaded to a service that cannot carry them
- No labelling rule for information created inside the cloud service
ISO/IEC 27017 9.2.3 Management of privileged access rightsPrivileged access in a cloud service sits on both sides. The customer should control the privileged rights it holds over its tenancy, using strong authentication and keeping the number of privileged users small, and the provider should control privileged access of its own staff to the cloud service and to customer environments, with the assurance the customer asks for. The provider should offer sufficient authentication techniques for the customer's privileged accounts.
- List of privileged cloud accounts on the customer side with approvals
- Provider description of privileged access controls for its staff
- Evidence of multi-factor authentication on privileged cloud accounts
- Provider root or console credentials shared between customer staff
- No statement from the provider on how its administrators reach customer environments
ISO/IEC 27017 10.1.2 Key managementCryptographic keys used by the service should be explained to the customer: the provider should give information about the keys the service uses and the key management options available, including whether the customer may manage its own keys and how keys are protected and destroyed. The customer should decide who manages the keys for its cloud-hosted information and should keep management of keys it controls under its own key management policy.
- Key management arrangement per cloud service stating who holds keys
- Provider documentation of key protection, rotation and destruction
- Customer key management records for customer-managed keys
- Keys held by the provider with no statement of who can access them
- Customer-managed keys lost, making cloud-hosted data unrecoverable
ISO/IEC 27017 11.2.7 Secure disposal or re-use of equipmentThe provider should arrange for secure disposal or re-use of equipment that has held customer information, so that customer data cannot be recovered from storage that is retired or reassigned to another tenant, and should tell customers about the arrangement. The customer should confirm that the provider's disposal practice meets its requirements for the information it places in the service.
- Provider media sanitisation and disposal procedure
- Disposal or destruction records
- Customer review of the provider's disposal statement
- Storage reassigned between tenants without sanitisation
- Customer requirement for certified destruction not passed to the provider
ISO/IEC 27017 12.3.1 Information backupThe provider should specify the backup capabilities it offers, including scope, frequency, retention, protection of the backups and how the customer may restore, and should state what it does not back up. The customer should decide which of its cloud-hosted information needs backup, whether to rely on the provider's backups or keep its own, and should test that restoration works.
- Provider backup specification for the service
- Customer backup decision and arrangements per cloud service
- Restore test records
- Customer assumes the provider backs up its data when the service only replicates it
- Backups held only inside the same cloud account they protect
ISO/IEC 27017 12.6.1 Management of technical vulnerabilitiesTechnical vulnerabilities in a cloud service are divided between what the provider patches and what the customer patches, and the provider should give the customer information about how it manages vulnerabilities affecting the cloud service, including the parts the provider patches and the parts the customer must patch itself, and the notification it gives. The customer should manage vulnerabilities in the components it controls (its virtual machines, applications and configuration) and should track the provider's handling of the rest.
- Provider vulnerability management statement and notification channel
- Customer vulnerability process covering cloud-hosted components it controls
- Patch records for customer-managed cloud assets
- Customer assumes the provider patches guest operating systems it actually leaves to the customer
- No provider channel for vulnerability notification the customer monitors
ISO/IEC 27017 14.2.1 Secure development policyWhere the customer develops applications on a cloud service, its secure development policy should address the cloud environment, including the provider's development tools and interfaces and the security of code and data in shared development resources. The provider should give customers information about the secure development practices and the interfaces it makes available.
- Customer secure development policy with a cloud section
- Provider documentation of development interfaces and practices
- Review of cloud-hosted development environments against the policy
- Production credentials used in a cloud development environment
- Customer developers using provider tooling with no security guidance
ISO/IEC 27017 15.1.2 Addressing security within supplier agreementsThe agreement between customer and provider should set out the information security requirements for the cloud service, including the responsibilities of each party, the provider's controls, handling of customer information, incident notification, the customer's rights to information and audit, and what happens at termination. The provider should offer terms that state these, and the customer should confirm the agreement covers its requirements before it uses the service.
- Cloud service agreement with the security provisions identified
- Customer review of the agreement against its requirements
- Record of negotiated security terms
- Click-through terms accepted with no review of the security clauses
- Agreement silent on incident notification or on return of data at termination
ISO/IEC 27017 15.1.3 Information and communication technology supply chainThe provider should identify the peer cloud services and suppliers on which the cloud service depends and should tell the customer how information security requirements are passed to them, since a weakness in a sub-provider is a weakness in the service. The customer should ask for that information and should include the provider's supply chain in its own risk assessment.
- Provider disclosure of sub-providers and peer cloud services
- Evidence of security requirements flowed down to sub-providers
- Customer risk assessment covering the provider's supply chain
- Customer discovers the service runs on another provider's infrastructure only during an outage
- Provider's sub-provider agreements with no security clauses
ISO/IEC 27017 16.1.2 Reporting information security eventsThe provider should give the customer a mechanism to report information security events it observes in the cloud service, and should report to the customer events and incidents affecting the customer's information within the agreed time. The customer should report to the provider events it detects that may affect the service, and should tell its own users how to report events involving cloud services.
- Provider reporting channel and notification commitment
- Customer procedure for reporting events to the provider
- Records of events reported in each direction
- Incident notification obligation in the contract with no working contact behind it
- Customer users unaware that cloud service events should be reported
ISO/IEC 27017 CLD.6.3.1 Shared roles and responsibilities within a cloud computing environmentResponsibilities for information security in the use of a cloud service are shared, and the standard requires that they be allocated to identified parties, documented, communicated and implemented by both the cloud service customer and the cloud service provider. The provider should document and publish the responsibilities it takes on and those it leaves with the customer; the customer should record the allocation, assign owners inside its organisation, and act on its share.
- Shared responsibility document for each cloud service, agreed by both parties
- Communication of the allocation to the customer's users and the provider's staff
- Evidence the customer performs its allocated responsibilities
- A published provider responsibility model that the customer never mapped to its own roles
- Allocation that names organisations but no individuals
ISO/IEC 27017 CLD.8.1.5 Removal of cloud service customer assetsAssets of the cloud service customer that are on the cloud service provider's premises are to be removed, and returned where necessary, in a timely manner when the cloud service agreement ends. The provider should describe how customer assets are returned and deleted at termination, in what form and within what time; the customer should plan for termination from the start, including retrieval of its data in a usable format and confirmation of deletion.
- Provider termination and data return procedure with timescales
- Customer exit plan for the cloud service
- Confirmation of deletion after termination
- Data return window shorter than the customer's migration takes
- Provider deletes customer data with no confirmation, or keeps it in backups indefinitely
ISO/IEC 27017 CLD.9.5.1 Segregation in virtual computing environmentsA customer's virtual environment running on a cloud service is to be protected from other customers of the service and from unauthorised persons. The provider should enforce logical segregation between tenants across compute, storage and network, should segregate its own management environment from customer environments, and should describe the segregation to customers; the customer relies on that segregation and should verify the description before placing sensitive information in the service.
- Provider description of tenant segregation across compute, storage and network
- Independent assurance covering tenant isolation
- Customer review of the segregation before onboarding
- Isolation claimed at the hypervisor with shared storage that is not segregated
- Provider management plane reachable from a customer network
ISO/IEC 27017 CLD.9.5.2 Virtual machine hardeningVirtual machines in a cloud computing environment are to be hardened to meet business needs. Whichever party configures a virtual machine should apply hardening: only needed ports, protocols and services enabled, unnecessary components removed, and technical controls such as anti-malware and logging appropriate to the workload; the customer hardens the machines it controls and the provider those it operates, including the images it offers to customers.
- Hardening standard for cloud virtual machines
- Configuration evidence or scan results for a sample of machines
- Provider statement on hardening of provided images
- Provider default images deployed unchanged with all services enabled
- Customer hardening standard written for physical servers and never applied to cloud images
ISO/IEC 27017 CLD.12.1.5 Administrator's operational securityProcedures for administrative operations of a cloud computing environment are to be defined, documented and monitored. The provider should document how its administrators operate the service and monitor their activity; the customer should document the administrative procedures for its own use of the service, covering critical operations such as configuration changes, backup and restore, and access management, and should monitor that they are followed, because a mistaken administrative action in a cloud console can affect the whole tenancy.
- Documented administrative procedures for the cloud environment on each side
- Monitoring records of administrative activity
- Provider description of its administrative practice
- Cloud console administration done ad hoc with no procedure for high-impact actions
- Administrative activity logged but never monitored
ISO/IEC 27017 CLD.12.4.5 Monitoring of cloud servicesThe cloud service customer is to have the capability to monitor specified aspects of the operation of the cloud services it uses. The provider should give customers the means to monitor the aspects relevant to their security, such as service availability, security events and the use of their resources, and should describe those capabilities; the customer should decide which aspects it needs to monitor and should use the capabilities provided, supplementing them where the provider's monitoring is not enough.
- Provider description of monitoring capabilities offered to customers
- Customer monitoring configuration for the cloud service
- Evidence the monitoring output is reviewed and acted on
- Monitoring capability offered but never enabled by the customer
- Customer security monitoring that stops at its own network edge
ISO/IEC 27017 CLD.13.1.4 Alignment of security management for virtual and physical networksWhen virtual networks are configured, the consistency of configurations between virtual and physical networks is to be verified against the provider's network security policy. The provider should apply the same network security policy to the virtual networks it provides as to its physical networks, should verify the two stay consistent when virtual networks are created or changed, and should describe the arrangement to customers; the customer should confirm the description meets its requirements for the virtual networks it uses.
- Provider network security policy covering virtual and physical networks
- Verification records when virtual networks are configured
- Customer review of the provider's virtual network security statement
- Virtual network rules that permit traffic the physical firewall policy forbids
- Virtual networks created by automation with no policy check