Cloud Shared Responsibility Mapper
Framework

ISO/IEC 27017:2015: the clauses behind the split

The code of practice for information security in cloud services, written for both the customer and the provider. It allocates each control between the two, which is why its clause stands behind every split. Always shown.

Shown on every map. The framework on the compliance library.

Control areas it anchors

14
AreaClause
Governance and policyISO/IEC 27017 5.1.1 · ISO/IEC 27017 6.1.1
Identity and accessISO/IEC 27017 9.2.3
Data classification and handlingISO/IEC 27017 8.2.2
Encryption and keysISO/IEC 27017 10.1.2
Network securityISO/IEC 27017 CLD.9.5.1 · ISO/IEC 27017 CLD.13.1.4
Logging and monitoringISO/IEC 27017 CLD.12.4.5
Vulnerability and patch managementISO/IEC 27017 12.6.1
Configuration and hardeningISO/IEC 27017 CLD.9.5.2 · ISO/IEC 27017 CLD.12.1.5
Application securityISO/IEC 27017 14.2.1
Incident responseISO/IEC 27017 16.1.2
Business continuity and backupISO/IEC 27017 12.3.1
Physical and environmentalISO/IEC 27017 11.2.7
Supplier and subserviceISO/IEC 27017 CLD.6.3.1 · ISO/IEC 27017 15.1.2
AI use and data retentionISO/IEC 27017 CLD.8.1.5

Every clause cited, quoted

20 of the 44 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

ISO/IEC 27017 5.1.1 Policies for information security

The cloud service customer's information security policy should address the use of cloud services: which information may be placed in which services, who may procure them, how the customer keeps accountability for information a provider processes, and the provider's obligations the customer expects to see in the agreement. The cloud service provider's policy should cover the security of the cloud service it delivers, including its baseline of protection for customer information, multi-tenancy, customer access to the service's security functions, and the boundary between its responsibilities and the customer's.

What an assessor asks to see:
  • Information security policy with a cloud services section (customer)
  • Provider policy stating the baseline security of the service and the shared-responsibility boundary
  • Approval record and communication of the policy to cloud users or customers
Where it usually falls short:
  • Corporate policy silent on cloud, so business units adopt services with no rule on what data may go there
  • Provider policy that does not state what the customer remains responsible for
Source: ISO/IEC 27017:2015
ISO/IEC 27017 6.1.1 Information security roles and responsibilities

Roles and responsibilities for the security of each cloud service should be allocated between the cloud service customer and the cloud service provider and inside each organisation. The customer should assign who owns the relationship, who manages customer-side controls and who evaluates the provider's information; the provider should state which responsibilities it accepts and which remain with the customer for each service it offers, so that no control falls between the two.

What an assessor asks to see:
  • Responsibility matrix per cloud service naming customer and provider owners
  • Provider service description or terms stating accepted responsibilities
  • Internal role assignments for cloud relationship and control ownership
Where it usually falls short:
  • A control both parties assume the other performs, typically backup, logging or key management
  • Responsibility matrix drafted at onboarding and never updated for new service features
Source: ISO/IEC 27017:2015
ISO/IEC 27017 8.1.1 Inventory of assets

The cloud service customer's asset inventory should record the information and assets it holds in each cloud service, so that cloud-hosted assets are not invisible to its own management. The cloud service provider should inventory the assets associated with the cloud service, including the assets of each customer that it holds, in a way that lets it identify and separate them by customer.

What an assessor asks to see:
  • Customer asset inventory with entries for cloud-hosted information and services
  • Provider inventory identifying customer assets by customer
  • Inventory review records
Where it usually falls short:
  • Cloud-hosted data absent from the inventory because it was never on the customer's own systems
  • Provider inventory that cannot tell which customer a stored asset belongs to
Source: ISO/IEC 27017:2015
ISO/IEC 27017 8.2.2 Labelling of information

The customer should label information according to its classification before and while it is in a cloud service, using labelling the service can carry, and the provider should describe what labelling capability the service offers and whether labels survive processing. Both should agree how labels are handled where the provider's staff can see customer information.

What an assessor asks to see:
  • Labelling scheme applied to cloud-hosted information
  • Provider documentation of labelling features
  • Test that labels persist through the service
Where it usually falls short:
  • Labels stripped when information is uploaded to a service that cannot carry them
  • No labelling rule for information created inside the cloud service
Source: ISO/IEC 27017:2015
ISO/IEC 27017 9.2.3 Management of privileged access rights

Privileged access in a cloud service sits on both sides. The customer should control the privileged rights it holds over its tenancy, using strong authentication and keeping the number of privileged users small, and the provider should control privileged access of its own staff to the cloud service and to customer environments, with the assurance the customer asks for. The provider should offer sufficient authentication techniques for the customer's privileged accounts.

What an assessor asks to see:
  • List of privileged cloud accounts on the customer side with approvals
  • Provider description of privileged access controls for its staff
  • Evidence of multi-factor authentication on privileged cloud accounts
Where it usually falls short:
  • Provider root or console credentials shared between customer staff
  • No statement from the provider on how its administrators reach customer environments
Source: ISO/IEC 27017:2015
ISO/IEC 27017 10.1.2 Key management

Cryptographic keys used by the service should be explained to the customer: the provider should give information about the keys the service uses and the key management options available, including whether the customer may manage its own keys and how keys are protected and destroyed. The customer should decide who manages the keys for its cloud-hosted information and should keep management of keys it controls under its own key management policy.

What an assessor asks to see:
  • Key management arrangement per cloud service stating who holds keys
  • Provider documentation of key protection, rotation and destruction
  • Customer key management records for customer-managed keys
Where it usually falls short:
  • Keys held by the provider with no statement of who can access them
  • Customer-managed keys lost, making cloud-hosted data unrecoverable
Source: ISO/IEC 27017:2015
ISO/IEC 27017 11.2.7 Secure disposal or re-use of equipment

The provider should arrange for secure disposal or re-use of equipment that has held customer information, so that customer data cannot be recovered from storage that is retired or reassigned to another tenant, and should tell customers about the arrangement. The customer should confirm that the provider's disposal practice meets its requirements for the information it places in the service.

What an assessor asks to see:
  • Provider media sanitisation and disposal procedure
  • Disposal or destruction records
  • Customer review of the provider's disposal statement
Where it usually falls short:
  • Storage reassigned between tenants without sanitisation
  • Customer requirement for certified destruction not passed to the provider
Source: ISO/IEC 27017:2015
ISO/IEC 27017 12.3.1 Information backup

The provider should specify the backup capabilities it offers, including scope, frequency, retention, protection of the backups and how the customer may restore, and should state what it does not back up. The customer should decide which of its cloud-hosted information needs backup, whether to rely on the provider's backups or keep its own, and should test that restoration works.

What an assessor asks to see:
  • Provider backup specification for the service
  • Customer backup decision and arrangements per cloud service
  • Restore test records
Where it usually falls short:
  • Customer assumes the provider backs up its data when the service only replicates it
  • Backups held only inside the same cloud account they protect
Source: ISO/IEC 27017:2015
ISO/IEC 27017 12.6.1 Management of technical vulnerabilities

Technical vulnerabilities in a cloud service are divided between what the provider patches and what the customer patches, and the provider should give the customer information about how it manages vulnerabilities affecting the cloud service, including the parts the provider patches and the parts the customer must patch itself, and the notification it gives. The customer should manage vulnerabilities in the components it controls (its virtual machines, applications and configuration) and should track the provider's handling of the rest.

What an assessor asks to see:
  • Provider vulnerability management statement and notification channel
  • Customer vulnerability process covering cloud-hosted components it controls
  • Patch records for customer-managed cloud assets
Where it usually falls short:
  • Customer assumes the provider patches guest operating systems it actually leaves to the customer
  • No provider channel for vulnerability notification the customer monitors
Source: ISO/IEC 27017:2015
ISO/IEC 27017 14.2.1 Secure development policy

Where the customer develops applications on a cloud service, its secure development policy should address the cloud environment, including the provider's development tools and interfaces and the security of code and data in shared development resources. The provider should give customers information about the secure development practices and the interfaces it makes available.

What an assessor asks to see:
  • Customer secure development policy with a cloud section
  • Provider documentation of development interfaces and practices
  • Review of cloud-hosted development environments against the policy
Where it usually falls short:
  • Production credentials used in a cloud development environment
  • Customer developers using provider tooling with no security guidance
Source: ISO/IEC 27017:2015
ISO/IEC 27017 15.1.2 Addressing security within supplier agreements

The agreement between customer and provider should set out the information security requirements for the cloud service, including the responsibilities of each party, the provider's controls, handling of customer information, incident notification, the customer's rights to information and audit, and what happens at termination. The provider should offer terms that state these, and the customer should confirm the agreement covers its requirements before it uses the service.

What an assessor asks to see:
  • Cloud service agreement with the security provisions identified
  • Customer review of the agreement against its requirements
  • Record of negotiated security terms
Where it usually falls short:
  • Click-through terms accepted with no review of the security clauses
  • Agreement silent on incident notification or on return of data at termination
Source: ISO/IEC 27017:2015
ISO/IEC 27017 15.1.3 Information and communication technology supply chain

The provider should identify the peer cloud services and suppliers on which the cloud service depends and should tell the customer how information security requirements are passed to them, since a weakness in a sub-provider is a weakness in the service. The customer should ask for that information and should include the provider's supply chain in its own risk assessment.

What an assessor asks to see:
  • Provider disclosure of sub-providers and peer cloud services
  • Evidence of security requirements flowed down to sub-providers
  • Customer risk assessment covering the provider's supply chain
Where it usually falls short:
  • Customer discovers the service runs on another provider's infrastructure only during an outage
  • Provider's sub-provider agreements with no security clauses
Source: ISO/IEC 27017:2015
ISO/IEC 27017 16.1.2 Reporting information security events

The provider should give the customer a mechanism to report information security events it observes in the cloud service, and should report to the customer events and incidents affecting the customer's information within the agreed time. The customer should report to the provider events it detects that may affect the service, and should tell its own users how to report events involving cloud services.

What an assessor asks to see:
  • Provider reporting channel and notification commitment
  • Customer procedure for reporting events to the provider
  • Records of events reported in each direction
Where it usually falls short:
  • Incident notification obligation in the contract with no working contact behind it
  • Customer users unaware that cloud service events should be reported
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.6.3.1 Shared roles and responsibilities within a cloud computing environment

Responsibilities for information security in the use of a cloud service are shared, and the standard requires that they be allocated to identified parties, documented, communicated and implemented by both the cloud service customer and the cloud service provider. The provider should document and publish the responsibilities it takes on and those it leaves with the customer; the customer should record the allocation, assign owners inside its organisation, and act on its share.

What an assessor asks to see:
  • Shared responsibility document for each cloud service, agreed by both parties
  • Communication of the allocation to the customer's users and the provider's staff
  • Evidence the customer performs its allocated responsibilities
Where it usually falls short:
  • A published provider responsibility model that the customer never mapped to its own roles
  • Allocation that names organisations but no individuals
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.8.1.5 Removal of cloud service customer assets

Assets of the cloud service customer that are on the cloud service provider's premises are to be removed, and returned where necessary, in a timely manner when the cloud service agreement ends. The provider should describe how customer assets are returned and deleted at termination, in what form and within what time; the customer should plan for termination from the start, including retrieval of its data in a usable format and confirmation of deletion.

What an assessor asks to see:
  • Provider termination and data return procedure with timescales
  • Customer exit plan for the cloud service
  • Confirmation of deletion after termination
Where it usually falls short:
  • Data return window shorter than the customer's migration takes
  • Provider deletes customer data with no confirmation, or keeps it in backups indefinitely
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.9.5.1 Segregation in virtual computing environments

A customer's virtual environment running on a cloud service is to be protected from other customers of the service and from unauthorised persons. The provider should enforce logical segregation between tenants across compute, storage and network, should segregate its own management environment from customer environments, and should describe the segregation to customers; the customer relies on that segregation and should verify the description before placing sensitive information in the service.

What an assessor asks to see:
  • Provider description of tenant segregation across compute, storage and network
  • Independent assurance covering tenant isolation
  • Customer review of the segregation before onboarding
Where it usually falls short:
  • Isolation claimed at the hypervisor with shared storage that is not segregated
  • Provider management plane reachable from a customer network
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.9.5.2 Virtual machine hardening

Virtual machines in a cloud computing environment are to be hardened to meet business needs. Whichever party configures a virtual machine should apply hardening: only needed ports, protocols and services enabled, unnecessary components removed, and technical controls such as anti-malware and logging appropriate to the workload; the customer hardens the machines it controls and the provider those it operates, including the images it offers to customers.

What an assessor asks to see:
  • Hardening standard for cloud virtual machines
  • Configuration evidence or scan results for a sample of machines
  • Provider statement on hardening of provided images
Where it usually falls short:
  • Provider default images deployed unchanged with all services enabled
  • Customer hardening standard written for physical servers and never applied to cloud images
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.12.1.5 Administrator's operational security

Procedures for administrative operations of a cloud computing environment are to be defined, documented and monitored. The provider should document how its administrators operate the service and monitor their activity; the customer should document the administrative procedures for its own use of the service, covering critical operations such as configuration changes, backup and restore, and access management, and should monitor that they are followed, because a mistaken administrative action in a cloud console can affect the whole tenancy.

What an assessor asks to see:
  • Documented administrative procedures for the cloud environment on each side
  • Monitoring records of administrative activity
  • Provider description of its administrative practice
Where it usually falls short:
  • Cloud console administration done ad hoc with no procedure for high-impact actions
  • Administrative activity logged but never monitored
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.12.4.5 Monitoring of cloud services

The cloud service customer is to have the capability to monitor specified aspects of the operation of the cloud services it uses. The provider should give customers the means to monitor the aspects relevant to their security, such as service availability, security events and the use of their resources, and should describe those capabilities; the customer should decide which aspects it needs to monitor and should use the capabilities provided, supplementing them where the provider's monitoring is not enough.

What an assessor asks to see:
  • Provider description of monitoring capabilities offered to customers
  • Customer monitoring configuration for the cloud service
  • Evidence the monitoring output is reviewed and acted on
Where it usually falls short:
  • Monitoring capability offered but never enabled by the customer
  • Customer security monitoring that stops at its own network edge
Source: ISO/IEC 27017:2015
ISO/IEC 27017 CLD.13.1.4 Alignment of security management for virtual and physical networks

When virtual networks are configured, the consistency of configurations between virtual and physical networks is to be verified against the provider's network security policy. The provider should apply the same network security policy to the virtual networks it provides as to its physical networks, should verify the two stay consistent when virtual networks are created or changed, and should describe the arrangement to customers; the customer should confirm the description meets its requirements for the virtual networks it uses.

What an assessor asks to see:
  • Provider network security policy covering virtual and physical networks
  • Verification records when virtual networks are configured
  • Customer review of the provider's virtual network security statement
Where it usually falls short:
  • Virtual network rules that permit traffic the physical firewall policy forbids
  • Virtual networks created by automation with no policy check
Source: ISO/IEC 27017:2015