ISO 27017 - Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services
ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:
- Additional implementation guidance for relevant controls specified in ISO/IEC 27002.
- Additional controls with implementation guidance that specifically relate to cloud services.
This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers
- Develop a long-term strategy
- Increase transparency
- Reduce reputation risks
- Win customer trust
- Protects against fines - ensures that local regulations are complied with reducing the risk of fines for data breaches.
- Protects your brand reputation - reduces the risk of adverse publicity due to data breaches.