Skip to content
Cyber Horizon
All frameworks

// Information Security

ISO/IEC 27017 Cloud Security Controls Compliance Software

Code of practice for information security controls for cloud services.

Framework at a glance

Short name

ISO 27017

Version

Category

Information Security

Controls

37

What ISO 27017 covers

37 controls across 28 domains — every one tracked, owned and evidenced in Cyber Horizon.

Policy

2 controls
  • 5.1 Policies for cloud info security
  • 10.1.1 Policy on cryptography in cloud

Governance

3 controls
  • 6.1.1 Info security roles in cloud
  • CLD.6.3.1 Shared roles and responsibilities
  • CLD.16.1.3 Responsibility for cloud incidents

SLAs

2 controls
  • CLD.6.3.2 Notification of change by cloud provider
  • CLD.17.2.1 Availability in cloud contracts

HR

1 controls
  • 7.1 Prior to cloud engagement - screening

Admin Security

2 controls
  • CLD.7.5.1 Customer admin activities in cloud
  • CLD.12.1.5 Administrator operational security

Asset Management

3 controls
  • 8.1.1 Inventory of cloud assets
  • CLD.8.1.3 Handling of cloud service customer assets
  • CLD.8.1.5 Removal of cloud service customer assets

Network Access

1 controls
  • 9.1.2 Access to cloud networks

Network

2 controls
  • CLD.9.1.2 Access control in virtual networks
  • CLD.13.1.4 Alignment of security management for virtual and physical networks

Identity

1 controls
  • 9.2.2 Cloud account provisioning

Application

1 controls
  • 9.4.1 Cloud information access restriction

Multi-tenancy

1 controls
  • CLD.9.5.1 Segregation in virtual environments

Hardening

1 controls
  • CLD.9.5.2 Virtual machine hardening

Cloud Provider

1 controls
  • 11.1.1 Physical security of cloud infrastructure

Procedures

1 controls
  • 12.1.1 Documented cloud operating procedures

Malware

1 controls
  • 12.2.1 Controls against malware in cloud

Backup

1 controls
  • 12.3.1 Cloud backup

Logging

1 controls
  • 12.4.1 Event logging in cloud

Audit

1 controls
  • CLD.12.4.3 Administrator and operator logs

Monitoring

2 controls
  • CLD.12.4.5 Monitoring of cloud services
  • 15.2.1 Monitoring cloud service delivery

Vulnerability Management

1 controls
  • 12.6.1 Management of vulnerabilities in cloud

Controls

1 controls
  • 13.1.1 Network controls for cloud

Data Transfer

1 controls
  • 13.2.1 Information transfer policies for cloud

Requirements

1 controls
  • 14.1.1 Cloud security requirements analysis

Architecture

1 controls
  • 14.2.5 Secure system engineering in cloud

Third-Party

1 controls
  • 15.1.1 Cloud supply chain security

Response

1 controls
  • 16.1.1 Cloud incident management

BCM

1 controls
  • 17.1.1 Cloud business continuity

Legal

1 controls
  • 18.1.1 Cloud compliance

How Cyber Horizon automates ISO 27017

Every ISO 27017 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO/IEC 27017 Cloud Security Controls?

Code of practice for information security controls for cloud services.

How many controls does ISO/IEC 27017 Cloud Security Controls have?

ISO/IEC 27017 Cloud Security Controls has 37 controls in Cyber Horizon's catalogue, organised across 28 domains.

How does Cyber Horizon help with ISO/IEC 27017 Cloud Security Controls?

Cyber Horizon maps ISO/IEC 27017 Cloud Security Controls into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27017 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 27017 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27017 in Cyber Horizon.