Cloud certifications ISO 27017 and 27018 compared

Overview

While ISO 27017 focuses generally on the security of cloud services, ISO 27018 specifically concentrates on the privacy of personal data in the cloud.

Here's a direct comparison:

Feature

ISO 27017 (Security)

ISO 27018 (Privacy)

Focus

General IT security controls for cloud services.

Protection of personally identifiable information (PII) in the public cloud.

Objective

Risk minimization for providers and customers (e.g., access rights, monitoring).

Compliance with data protection regulations (e.g., purpose limitation, retention periods).

User

Cloud service providers (CSPs) and cloud service providers (CSCs).

Primarily for cloud providers acting as data processors.

Content

Supplements ISO 27001 with cloud-specific controls.

Supplements ISO 27001 with specific PII protection measures.

Key message

"The cloud infrastructure is securely configured."

"Customer data is not misused or shared."

In short: ISO 27017 ensures that the cloud "is not hacked," while ISO 27018 ensures that the private data stored therein "is not misused."

  

Under what conditions is a combined ISO 27017 and ISO 27018 certification possible?

1. The foundation: ISO/IEC 27001 certification

Without an existing (or simultaneously implemented) Information Security Management System (ISMS) according to ISO 27001, certification for 27017 or 27018 is not possible. These "add-ons" simply extend Annex A of ISO 27001 with specific cloud and data protection controls.

2. ISO/IEC 27017 (Cloud Security)
Here, the focus is on the secure provision and use of cloud services.
  • Extended controls: You must implement additional security measures, such as the clear separation of data in multi-tenant environments and the definition of interfaces between the cloud provider and the customer.
  • Role Clarity: It must be documented who is responsible for which security aspects (Shared Responsibility Model).
3. ISO/IEC 27018 (Protection of Personal Data in the Cloud)
This standard is specific to public cloud providers that process personal data (PII).
  • Purpose Limitation: Proof that data is not used for marketing or advertising unless the customer has explicitly consented.
  • Transparency: You must disclose where the data is stored and which subcontractors (sub-processors) are involved.
  • Data Subject Rights: Processes for the deletion, correction, and return of data must be established.
4. Integrated Audit Process
  • Scope Definition: The scope of your ISMS must explicitly include cloud services.
  • Statement of Applicability (SoA): Your applicability document must be extended to include the specific controls of ISO/IEC 27017 and ISO/IEC 27018.
  • Risk Assessment: The risk analysis must consider cloud-specific threats and data protection risks for PII in detail.

The advantage: Since many requirements overlap (e.g., encryption or backup), a combined audit saves considerable time and costs compared to individual certifications.

No module Published on Offcanvas position