Overview
While ISO 27017 focuses generally on the security of cloud services, ISO 27018 specifically concentrates on the privacy of personal data in the cloud.
Here's a direct comparison:
|
Feature |
ISO 27017 (Security) |
ISO 27018 (Privacy) |
|
Focus |
General IT security controls for cloud services. |
Protection of personally identifiable information (PII) in the public cloud. |
|
Objective |
Risk minimization for providers and customers (e.g., access rights, monitoring). |
Compliance with data protection regulations (e.g., purpose limitation, retention periods). |
|
User |
Cloud service providers (CSPs) and cloud service providers (CSCs). |
Primarily for cloud providers acting as data processors. |
|
Content |
Supplements ISO 27001 with cloud-specific controls. |
Supplements ISO 27001 with specific PII protection measures. |
|
Key message |
"The cloud infrastructure is securely configured." |
"Customer data is not misused or shared." |
In short: ISO 27017 ensures that the cloud "is not hacked," while ISO 27018 ensures that the private data stored therein "is not misused."
Under what conditions is a combined ISO 27017 and ISO 27018 certification possible?
Without an existing (or simultaneously implemented) Information Security Management System (ISMS) according to ISO 27001, certification for 27017 or 27018 is not possible. These "add-ons" simply extend Annex A of ISO 27001 with specific cloud and data protection controls.
- Extended controls: You must implement additional security measures, such as the clear separation of data in multi-tenant environments and the definition of interfaces between the cloud provider and the customer.
- Role Clarity: It must be documented who is responsible for which security aspects (Shared Responsibility Model).
- Purpose Limitation: Proof that data is not used for marketing or advertising unless the customer has explicitly consented.
- Transparency: You must disclose where the data is stored and which subcontractors (sub-processors) are involved.
- Data Subject Rights: Processes for the deletion, correction, and return of data must be established.
- Scope Definition: The scope of your ISMS must explicitly include cloud services.
- Statement of Applicability (SoA): Your applicability document must be extended to include the specific controls of ISO/IEC 27017 and ISO/IEC 27018.
- Risk Assessment: The risk analysis must consider cloud-specific threats and data protection risks for PII in detail.
The advantage: Since many requirements overlap (e.g., encryption or backup), a combined audit saves considerable time and costs compared to individual certifications.