Use current cloud guidance to divide customer and provider responsibilities and protect personal information processed in public cloud services.
Know which guidance applies
ISO/IEC 27017:2026 gives cloud-specific security control guidance for cloud service providers and customers across deployment models. ISO/IEC 27018:2025 focuses on protection of personally identifiable information in public clouds when the provider acts as a PII processor. Both build on ISO/IEC 27002 and can complement an ISO/IEC 27001 ISMS.
Check the current editions and the actual cloud service model before reusing older control mappings or making a public assurance claim.
Draw the shared-responsibility boundary
List who controls physical facilities, infrastructure configuration, identity, application changes, encryption, backups, logging, incident investigation, and deletion. A hyperscaler contract may allocate responsibilities broadly; translate those terms into named teams and evidence sources for the service being sold.
For a SaaS provider, cloud infrastructure evidence is not a substitute for its own application, access, change, and customer-support controls.
Handle PII processor duties deliberately
When the cloud provider processes personal information for a customer, clarify processing instructions, access, location, retention, deletion, subprocessor oversight, and incident communication in the contract and operations. ISO/IEC 27018 offers cloud-specific guidance; applicable privacy law and customer terms still need separate review.
Map the data flow from intake to deletion. Test one customer request or incident scenario to see whether provider and customer actions are coordinated.
Make assurance useful to buyers
Maintain a control matrix that names the owner, standard reference, implementation, evidence, and customer dependency. Explain exactly what a certificate or report covers and whether it reaches the contracted service. If a buyer also asks for SOC 2, map common operating evidence while preserving the distinct assurance scope.
Review the matrix when the cloud architecture or subcontractors change; responsibility rarely stays static.
Put it into practice
- Confirm the 2026 ISO/IEC 27017 and 2025 ISO/IEC 27018 editions.
- Build a control responsibility matrix for each cloud service.
- Trace PII handling and deletion through providers and subprocessors.
- Check buyer-facing assurance against the actual service boundary.
Primary sources
- ISO: ISO/IEC 27017:2026 cloud security controls
- ISO: ISO/IEC 27018:2025 public cloud PII guidance
- ISO: ISO/IEC 27001 information security management
Normstone resources are general information, not legal advice or an independent assessment.