ISO 27017: What It Is & Why It Matters
ISO/IEC 27017 is a code of practice that adds cloud-specific security guidance on top of the broader information security controls, clarifying responsibilities between a cloud provider and its customer.
In this explainer
- Understand what ISO/IEC 27017 covers and how it relates to ISO 27002
- Learn the cloud-specific themes it addresses
- Understand shared responsibility in cloud environments
- See why cloud guidance matters when debtor data sits in the cloud
- Know what to ask a vendor and how Merion approaches it
7 min
What it is
ISO/IEC 27017 is a code of practice that provides additional guidance on information security controls for cloud services. It builds on the general controls described in ISO/IEC 27002 and adds cloud-specific implementation guidance, along with a number of controls written specifically for cloud environments. It speaks to both cloud service providers and the customers who use them.
The standard recognises that moving data and systems into a cloud service changes who does what. It does not replace the broader information security standards; instead it complements them, sharpening the guidance for the particular questions the cloud raises.
Key principles
The recurring theme of ISO 27017 is shared responsibility: in a cloud arrangement, some security obligations sit with the provider, some with the customer, and clarity about the boundary is essential. The guidance helps both sides understand and document who is responsible for what.
- Roles and responsibilities — making the split between provider and customer explicit.
- Segregation in shared environments — keeping one customer's data and activity separated from another's.
- Administration and monitoring of cloud services — how cloud operations are managed and observed.
- Return and removal of assets — what happens to data when a service ends.
Because cloud services are multi-tenant by nature, much of the guidance concerns making sure that sharing infrastructure does not mean sharing data, and that customers have the visibility they need.
Why it matters for debt recovery
Most modern providers, including debt-recovery providers, rely on cloud services to some degree. ISO 27017 matters because it addresses the precise risks that arise when debtor data is processed in shared, provider-operated infrastructure: how tenants are separated, who can administer the environment, and what happens to data when the relationship ends.
For a procurement team, the shared-responsibility lens is especially useful. It is not enough to know that a provider uses a reputable cloud platform; you also need to understand which security duties the provider performs itself and which it relies on the platform to perform. ISO 27017 gives a structured way to ask those questions.
What to ask a provider
Cloud-specific questions are worth asking explicitly:
- How is the shared-responsibility split documented between you and your cloud platforms?
- How is our data segregated from that of other customers?
- Who can administer the cloud environment, and how is that access controlled and logged?
- What happens to our data on termination, including return and secure removal?
A provider that has thought about cloud security can usually answer these without hesitation, and can explain where its own controls end and the platform's begin. Our sub-processors page describes how we think about the services that support our operations.
How Merion approaches it
Merion aligns with the principles of ISO 27017 in how it uses cloud services: we pay attention to the shared-responsibility boundary, segregation of data, controlled administration, and the return or removal of data at the end of a service.
This page is general information and not a claim that Merion holds any particular certification. Cloud arrangements and attestations change over time, so please verify a provider's current certifications and cloud controls directly when you assess them.
Key takeaways
- ISO 27017 adds cloud-specific guidance on top of general information security controls
- Its central theme is the shared responsibility between cloud provider and customer
- It addresses tenant segregation, administration, monitoring and data return
- Ask how responsibility is split and data is segregated, then verify current controls
Frequently asked questions
How is ISO 27017 different from ISO 27001?
ISO 27001 defines a certifiable information security management system. ISO 27017 is a code of practice that adds cloud-specific control guidance. They are often used together when cloud services are involved.
What is shared responsibility in the cloud?
It is the principle that security duties are divided between the cloud provider and the customer. Knowing exactly where the boundary sits is essential, because a gap on either side can leave data exposed.
Does using a reputable cloud platform make a provider secure?
Not on its own. The platform handles some controls, but the provider remains responsible for others, such as how it configures the service and manages access. That is why the shared-responsibility split matters.
Security and compliance you can verify
Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.