Cloud security
Clarify and implement cloud security responsibilities.
ISO/IEC 27017:2026 gives cloud-specific control guidance for service providers and customers. We help identify shared responsibilities, select proportionate controls, and document how cloud services are secured.
Our implementation focus
Make the requirements operational.
- 01
Map cloud services, tenants, data, and suppliers
- 02
Assign customer and provider responsibilities
- 03
Assess cloud-specific risks and control gaps
- 04
Implement configuration, access, monitoring, and incident practices
- 05
Connect evidence to the ISMS and customer assurance needs
ISO/IEC 27017 is cloud security guidance, not a standalone management system certification. Any external assessment is separate from Normstone advisory.
Questions we hear
Get the distinctions right.
Does ISO/IEC 27017 only cover public cloud?
No. ISO describes its use across public, private, and hybrid cloud deployments.
Can ISO/IEC 27017 replace ISO/IEC 27001?
No. ISO/IEC 27017 provides cloud control guidance. ISO/IEC 27001 sets requirements for an information security management system.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.