// Information Security
ISO/IEC 27017 Cloud Security Controls Compliance Software
Code of practice for information security controls for cloud services.
Framework at a glance
Short name
ISO 27017
Version
—
Category
Information Security
Controls
37
What ISO 27017 covers
37 controls across 28 domains — every one tracked, owned and evidenced in Cyber Horizon.
Policy
2 controls- 5.1 Policies for cloud info security
- 10.1.1 Policy on cryptography in cloud
Governance
3 controls- 6.1.1 Info security roles in cloud
- CLD.6.3.1 Shared roles and responsibilities
- CLD.16.1.3 Responsibility for cloud incidents
SLAs
2 controls- CLD.6.3.2 Notification of change by cloud provider
- CLD.17.2.1 Availability in cloud contracts
HR
1 controls- 7.1 Prior to cloud engagement - screening
Admin Security
2 controls- CLD.7.5.1 Customer admin activities in cloud
- CLD.12.1.5 Administrator operational security
Asset Management
3 controls- 8.1.1 Inventory of cloud assets
- CLD.8.1.3 Handling of cloud service customer assets
- CLD.8.1.5 Removal of cloud service customer assets
Network Access
1 controls- 9.1.2 Access to cloud networks
Network
2 controls- CLD.9.1.2 Access control in virtual networks
- CLD.13.1.4 Alignment of security management for virtual and physical networks
Identity
1 controls- 9.2.2 Cloud account provisioning
Application
1 controls- 9.4.1 Cloud information access restriction
Multi-tenancy
1 controls- CLD.9.5.1 Segregation in virtual environments
Hardening
1 controls- CLD.9.5.2 Virtual machine hardening
Cloud Provider
1 controls- 11.1.1 Physical security of cloud infrastructure
Procedures
1 controls- 12.1.1 Documented cloud operating procedures
Malware
1 controls- 12.2.1 Controls against malware in cloud
Backup
1 controls- 12.3.1 Cloud backup
Logging
1 controls- 12.4.1 Event logging in cloud
Audit
1 controls- CLD.12.4.3 Administrator and operator logs
Monitoring
2 controls- CLD.12.4.5 Monitoring of cloud services
- 15.2.1 Monitoring cloud service delivery
Vulnerability Management
1 controls- 12.6.1 Management of vulnerabilities in cloud
Controls
1 controls- 13.1.1 Network controls for cloud
Data Transfer
1 controls- 13.2.1 Information transfer policies for cloud
Requirements
1 controls- 14.1.1 Cloud security requirements analysis
Architecture
1 controls- 14.2.5 Secure system engineering in cloud
Third-Party
1 controls- 15.1.1 Cloud supply chain security
Response
1 controls- 16.1.1 Cloud incident management
BCM
1 controls- 17.1.1 Cloud business continuity
Legal
1 controls- 18.1.1 Cloud compliance
How Cyber Horizon automates ISO 27017
Every ISO 27017 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO/IEC 27017 Cloud Security Controls?
Code of practice for information security controls for cloud services.
How many controls does ISO/IEC 27017 Cloud Security Controls have?
ISO/IEC 27017 Cloud Security Controls has 37 controls in Cyber Horizon's catalogue, organised across 28 domains.
How does Cyber Horizon help with ISO/IEC 27017 Cloud Security Controls?
Cyber Horizon maps ISO/IEC 27017 Cloud Security Controls into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27017 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Information Security frameworks
See ISO 27017 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27017 in Cyber Horizon.