ISO 27017 provides cloud-specific security controls for cloud service providers and users. Tavo Networks helps secure cloud environments and clarify shared responsibilities.
ISO/IEC 27017 provides guidelines for information security controls applicable to the provision and use of cloud services, offering additional implementation guidance for ISO/IEC 27002 in cloud environments.
Specialized controls for cloud computing environments
Security responsibilities vary by cloud service model
| Security Area | IaaS | PaaS | SaaS |
|---|---|---|---|
| Physical Security | CSP | CSP | CSP |
| Network Security | Shared | CSP | CSP |
| Application Security | Customer | Shared | CSP |
| Data Security | Customer | Customer | Shared |
| Identity Management | Customer | Shared | Shared |
ISO 27017 applies across all cloud deployment and service models
Virtualized computing resources over the internet
Development and deployment platform in the cloud
Cloud-hosted software applications
ISO 27017 provides guidance for securing multi-cloud and hybrid cloud environments, ensuring consistent security controls across different cloud providers.