Cloud security

Clarify and implement cloud security responsibilities.

ISO/IEC 27017:2026 gives cloud-specific control guidance for service providers and customers. We help identify shared responsibilities, select proportionate controls, and document how cloud services are secured.

Our implementation focus

Make the requirements operational.

  1. 01

    Map cloud services, tenants, data, and suppliers

  2. 02

    Assign customer and provider responsibilities

  3. 03

    Assess cloud-specific risks and control gaps

  4. 04

    Implement configuration, access, monitoring, and incident practices

  5. 05

    Connect evidence to the ISMS and customer assurance needs

Independent assessment

ISO/IEC 27017 is cloud security guidance, not a standalone management system certification. Any external assessment is separate from Normstone advisory.

Questions we hear

Get the distinctions right.

Does ISO/IEC 27017 only cover public cloud?

No. ISO describes its use across public, private, and hybrid cloud deployments.

Can ISO/IEC 27017 replace ISO/IEC 27001?

No. ISO/IEC 27017 provides cloud control guidance. ISO/IEC 27001 sets requirements for an information security management system.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation