Information Security & Cybersecurity

Automate ISO 27017/18 certification readiness

ISO 27017/27018 · Cloud Security and Privacy Controls

Code of practice for information security controls and PII protection in public cloud computing environments, extending ISO 27002 with cloud-specific guidance.

62 controls24/7 continuous monitoring
ISO 27017/18 badgeISO 27017/18

What is ISO 27017/18?

Code of practice for information security controls and PII protection in public cloud computing environments, extending ISO 27002 with cloud-specific guidance.

Who it applies to

Cloud service providers and cloud customers asked to evidence cloud-specific controls. Commonly requested of SaaS vendors by enterprise procurement alongside ISO 27001 itself.

How the standard is organised

Two codes of practice rather than a management system: 27017 covers cloud security controls for providers and customers, 27018 covers protection of personal data in public cloud.

Framework names, marks and abbreviations (ISO, SOC 2, PCI DSS, TISAX, HIPAA, GDPR and others) are trademarks of their respective standards bodies and are used here only to describe what the Bitkosh Compliance Management Platform helps you track and prepare for. The badges shown are original Bitkosh artwork, not the official marks. Bitkosh Technologies is not affiliated with, sponsored by, or endorsed by ISO, AICPA, the PCI Security Standards Council, ENX/VDA, or any other framework owner, and using this platform does not by itself confer or guarantee certification — certification/attestation is granted only by the relevant accredited third-party body.

ISO 27017/18 on the Bitkosh platform

The 62 ISO 27017/18 controls sit in one workspace, evidence is collected from the systems you already run, and shared controls satisfy the equivalent requirement in the other 34 frameworks at the same time — so a second framework costs a fraction of the first.

How the platform works

Frequently Asked Questions

Who publishes ISO 27017/18, and who does it apply to?
ISO 27017/18 is published by ISO and IEC, jointly. Cloud service providers and cloud customers asked to evidence cloud-specific controls. Commonly requested of SaaS vendors by enterprise procurement alongside ISO 27001 itself.
How is ISO 27017/18 conformance demonstrated?
Certified as an extension to an existing ISO 27001 certificate. There is no certificate to obtain. Conformance is shown through mapped controls and retained evidence, and tested by a regulator or a counterparty rather than an auditor you appoint.
How is ISO 27017/18 structured?
Two codes of practice rather than a management system: 27017 covers cloud security controls for providers and customers, 27018 covers protection of personal data in public cloud. Bitkosh tracks 62 ISO 27017/18 controls against it, each with its own evidence requirements, owner and review cadence.
Let's build together

Ready to automate ISO 27017/18?

See how the Bitkosh Compliance Management Platform gets you audit-ready for ISO 27017/18 and 34 other frameworks from a single control library.