Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

ISO 27017 Certification Malaysia | Get Certified with SCS

Learn about ISO 27017 certification in Malaysia, cloud security requirements, Malaysian laws, key industries, locations and certification with SCS.

  1. Home
  2. Knowledge Centre
  3. ISO 27017 Certification Malaysia | Get Certified with SCS

ISO 27017 Cloud Security Certification in Malaysia – Malaysian Laws, Cloud Requirements & Get Certified with SCS

ISO 27017 Cloud Security Certification in Malaysia – Malaysian Laws, Cloud Requirements & Get Certified with SCS
Understand ISO 27017 cloud security certification in Malaysia, including Malaysian laws, cloud requirements, key industries, locations, implementation and certification considerations.

ISO 27017 Cloud Security Certification in Malaysia – Cloud Requirements, Malaysian Laws & Get Certified with SCS

SCS Certification – Malaysia Office

SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia

Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification

https://scscertification.com/contactus.php

Cloud services are now embedded in the operations of Malaysian businesses across financial services, technology, manufacturing, healthcare, telecommunications, logistics, e-commerce and government-facing digital services. As organizations move applications, databases and business processes to public, private and hybrid cloud environments, responsibility for information security becomes shared between the customer, cloud provider and other technology suppliers.

ISO/IEC 27017 provides cloud-specific information-security controls and guidance for organizations providing or using cloud services. The current international edition is ISO/IEC 27017:2026, which addresses information-security controls based on ISO/IEC 27002 for cloud services.

For Malaysian organizations, ISO 27017 can be considered alongside the Personal Data Protection Act 2010, Cyber Security Act 2024, National Cloud Computing Policy, sector-specific requirements and contractual security obligations.

ISO 27017 does not replace Malaysian law. Its value is in helping an organization establish a structured approach to managing security responsibilities within its cloud environment.

SCS Certification can help organizations understand the appropriate ISO 27017 scope, requirements and certification or assessment pathway.

What Is ISO 27017 Cloud Security Certification in Malaysia?

ISO/IEC 27017 is an international cloud-security standard designed to address information-security considerations that arise when organizations provide or use cloud services.

The standard is particularly relevant where security responsibilities are divided between different parties.

For example, a Malaysian SaaS company may develop and operate a business application while using a third-party cloud provider for infrastructure. The cloud provider may manage physical facilities, computing resources and certain network controls, while the SaaS company remains responsible for application security, customer access, data management and configuration.

ISO 27017 helps organizations establish clearer expectations around these responsibilities.

It can therefore be relevant to:

  • Cloud service providers

  • SaaS companies

  • Managed service providers

  • Data-centre and cloud infrastructure businesses

  • FinTech companies

  • Financial-sector organizations

  • Healthcare technology providers

  • Telecommunications businesses

  • E-commerce platforms

  • Manufacturing companies using cloud systems

  • Logistics and transportation businesses

  • Government technology suppliers

  • Organizations operating critical digital services

ISO/IEC 27017:2026 and Malaysian Businesses

Organizations developing a new ISO 27017 programme should consider the current edition of the standard.

ISO/IEC 27017:2026 is the current published edition, while ISO/IEC 27017:2015 has been withdrawn.

Businesses that previously used ISO/IEC 27017:2015 should review their current arrangements and confirm the applicable transition or reassessment requirements with their certification or assessment provider.

The 2026 edition remains focused on cloud-specific information-security controls and the responsibilities of cloud service providers and cloud service customers.

For Malaysian organizations, the first practical step is to define exactly which cloud services, information, processes and responsibilities are included within the intended scope.

ISO 27017 and ISO 27001 in Malaysia

ISO 27017 and ISO 27001 address different aspects of information security.

ISO 27001 specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System.

ISO 27017 provides cloud-specific controls and guidance that can complement an organization's broader information-security framework.

A Malaysian SaaS provider, for example, may establish an ISO 27001-based ISMS and then use ISO 27017 to address cloud-specific security responsibilities.

This distinction is important for businesses researching certification because ISO 27017 should not be presented as simply another name for ISO 27001.

Malaysia's National Cloud Computing Policy and ISO 27017

Malaysia's National Cloud Computing Policy provides a national framework for the development and adoption of cloud computing.

The policy is relevant to organizations involved in Malaysia's cloud ecosystem, including cloud providers, government organizations, businesses and technology stakeholders.

ISO 27017 and the National Cloud Computing Policy have different roles.

The National Cloud Computing Policy is a Malaysian national policy framework, while ISO 27017 is an international cloud-security standard.

An organization should therefore determine which national policy expectations, legal obligations and sector requirements apply to its activities and then consider how ISO 27017 can support its cloud-security controls.

Malaysian Laws Relevant to Cloud Security

There is no general Malaysian law requiring every organization to obtain ISO 27017 certification.

However, organizations using or providing cloud services may have legal, regulatory or contractual responsibilities depending on the nature of their business and the information they process.

Relevant areas may include:

  • Personal Data Protection Act 2010

  • Personal Data Protection (Amendment) Act 2024

  • Cyber Security Act 2024

  • National Critical Information Infrastructure requirements

  • Bank Negara Malaysia requirements for regulated financial institutions

  • Sector-specific cybersecurity obligations

  • Government and enterprise procurement requirements

  • Customer contractual requirements

ISO 27017 should therefore be viewed as part of an organization's cloud-security and assurance framework rather than as a substitute for statutory compliance.

ISO 27017 and Malaysia's Personal Data Protection Act

The Personal Data Protection Act 2010 regulates the processing of personal data in commercial transactions in Malaysia.

Cloud environments can make personal-data management more complex because information may pass between business applications, cloud platforms, service providers, subcontractors and support systems.

A Malaysian organization should understand where personal data is stored, who can access it, which providers process it, how access is controlled and how security incidents are managed.

ISO 27017 can support cloud-security controls around these activities, but certification does not automatically mean that an organization is compliant with the PDPA.

Privacy compliance and cloud-security assurance should be assessed separately.

ISO 27017 and the Cyber Security Act 2024

Malaysia's Cyber Security Act 2024 establishes a national cybersecurity framework that includes arrangements for National Critical Information Infrastructure.

NACSA identifies sectors including government, banking and finance, transportation, defence and national security, information and communications, healthcare, water, sewerage and waste management, energy, agriculture and plantation, trade and industry, and science, technology and innovation.

Organizations operating within relevant NCII environments should determine their specific obligations under the Act and associated requirements.

ISO 27017 can support cloud-security controls within such environments, but it does not replace obligations created by Malaysian cybersecurity legislation.

ISO 27017 for Cloud Service Providers in Malaysia

Cloud providers face security responsibilities that may differ from those of ordinary cloud customers.

A provider may be responsible for infrastructure, virtualization, networks, privileged administration, availability, monitoring and customer-environment separation.

A strong cloud-security programme should establish clear boundaries between the provider's responsibilities and those of customers.

Areas that may require attention include access management, administrative privileges, customer isolation, incident communication, supplier management, service continuity and changes to cloud infrastructure.

ISO 27017 can provide a structured basis for addressing these cloud-specific issues.

ISO 27017 for SaaS Companies in Malaysia

SaaS companies often depend on several technology layers.

The application may be controlled by the SaaS company while infrastructure, databases, identity services, monitoring or backup functions are supplied by other organizations.

This creates a shared-responsibility environment.

ISO 27017 can help Malaysian SaaS providers document security responsibilities and establish clearer controls for their cloud services.

This can also be useful when enterprise customers conduct supplier security assessments before purchasing a SaaS service.

The certification scope should describe the actual service and supporting activities instead of claiming coverage of every technology used by the company.

ISO 27017 for Malaysian Data Centres

Data centres and cloud infrastructure providers operate environments where availability, access control, physical protection, network security and logical separation may all be important.

A suitable ISO 27017 scope may include selected cloud infrastructure, managed services or supporting operations.

The scope should clearly identify the facilities, services and processes covered.

A company should avoid suggesting that all customer environments are certified when only a defined service or business unit falls within the assessed scope.

ISO 27017 for Banking and FinTech in Malaysia

Financial institutions and FinTech businesses can have complex technology environments involving customer information, payment systems, cloud applications and external technology suppliers.

Cloud-security controls should be considered alongside applicable financial-sector requirements.

ISO 27017 can help organizations structure cloud-specific controls relating to access, supplier responsibilities, operational security and information protection.

For regulated financial institutions, ISO 27017 does not replace Bank Negara Malaysia requirements.

The organization should map its cloud environment against all applicable regulatory and contractual requirements.

ISO 27017 for Healthcare and Digital Health

Healthcare providers and digital-health businesses may use cloud systems for electronic records, appointment platforms, laboratory applications, telemedicine and analytics.

These environments can involve sensitive information and multiple technology providers.

ISO 27017 can help organizations examine how cloud security responsibilities are divided between healthcare organizations, cloud providers and technology suppliers.

Applicable Malaysian privacy, cybersecurity and healthcare requirements must still be considered separately.

ISO 27017 for Telecommunications and Digital Services

Telecommunications companies and digital-service providers can operate complex environments involving customer platforms, networks, applications and cloud infrastructure.

Where cloud services form part of those operations, ISO 27017 can support structured management of cloud-specific information-security controls.

The scope should reflect the actual service being assessed and should distinguish cloud operations from unrelated telecommunications activities.

ISO 27017 for Manufacturing and Industrial Companies

Manufacturing organizations increasingly use cloud applications for enterprise resource planning, production analytics, engineering collaboration, supplier management and connected operations.

A manufacturer does not need to be a cloud provider to have cloud-security responsibilities.

The organization should identify which cloud services process business or production information, who administers those services and how external providers are controlled.

ISO 27017 can be incorporated into the security governance of those cloud-dependent operations.

ISO 27017 for Logistics and Transportation

Logistics companies may use cloud platforms for fleet management, shipment tracking, warehouse management, customer portals and operational analytics.

A security incident affecting one of these systems could disrupt business operations even if the company does not own the underlying cloud infrastructure.

ISO 27017 can help organizations define responsibilities for cloud access, monitoring, suppliers, incident handling and service continuity.

Transportation organizations should also determine whether additional requirements apply because of their role in critical infrastructure or regulated services.

ISO 27017 for E-Commerce and Digital Platforms

E-commerce companies can operate cloud environments containing customer accounts, order information, application data and business analytics.

Security responsibilities may be divided among the platform owner, cloud provider, payment-service provider and other technology suppliers.

An ISO 27017 implementation can help clarify those relationships and strengthen the organization's cloud-security framework.

The scope should remain specific to the relevant services and information systems.

ISO 27017 Cloud Security Requirements for Malaysian Organizations

A practical ISO 27017 programme should be built around the organization's real cloud environment.

Define Cloud Responsibilities

The organization should identify which security responsibilities are handled internally and which are delegated to cloud providers or other suppliers.

Establish Cloud-Service Agreements

Contracts should clearly address relevant security responsibilities, access, incident communication, service expectations and applicable obligations.

Manage Privileged Access

Administrative accounts should be controlled through appropriate authorization, authentication, monitoring and periodic review.

Protect Cloud Environments

The organization should understand how workloads, applications and customer information are logically separated and protected.

Manage Cloud Changes

Changes to applications, infrastructure and configurations should follow defined change-management controls.

Monitor Cloud Services

Monitoring should be appropriate to the importance and risk profile of the cloud service.

Control Suppliers

Cloud providers, subcontractors and technology suppliers should be assessed according to their relevance to the organization's security requirements.

Prepare for Cloud Incidents

Incident responsibilities should be agreed between the organization and relevant providers before an incident occurs.

Address Cloud Continuity

Critical services should have appropriate availability, backup and continuity arrangements based on business requirements.

Protect Cloud Information

Organizations should establish appropriate controls for information classification, access, retention, deletion and transfer.

ISO 27017 Certification Scope in Malaysia

The certification or assessment scope should describe the actual cloud service being evaluated.

Possible scopes include:

  • A SaaS platform

  • Cloud infrastructure services

  • Managed cloud services

  • A data-centre operation

  • A defined business unit

  • Selected cloud applications

  • Cloud-related support services

  • A specific customer-facing digital platform

A narrow scope is not automatically better. If important cloud activities are excluded, the resulting certification may provide limited assurance to customers.

The scope should be practical, transparent and consistent with the organization's actual operations.

How to Implement ISO 27017 in Malaysia

1. Identify the Cloud Environment

Document the cloud platforms, applications, services and external providers used within the proposed scope.

2. Establish the Security Boundary

Determine which controls are operated by the organization and which are managed by cloud providers.

3. Identify Cloud Risks

Assess risks involving confidentiality, integrity, availability, access, supplier dependency and service continuity.

4. Review Existing Controls

Compare existing practices against applicable ISO 27017 controls and business requirements.

5. Close Identified Gaps

Improve policies, procedures, contracts and technical controls where required.

6. Maintain Objective Evidence

Keep records demonstrating that controls have been implemented and are operating effectively.

7. Conduct Internal Review

Evaluate readiness before the external certification or assessment process.

8. Complete the External Assessment

The applicable certification or assessment process will depend on the scope, scheme and conformity-assessment arrangements.

ISO 27017 Certification Process in Malaysia

The process normally begins with defining the proposed cloud-security scope.

The organization then reviews its existing security controls and identifies areas requiring improvement.

Where ISO 27001 is already implemented, ISO 27017 controls can often be integrated into the existing information-security management framework.

The organization prepares the required documentation and objective evidence before the assessment.

Any findings are addressed through the applicable corrective-action process.

The overall timeframe depends on the organization's readiness, cloud architecture, number of services, locations and assessment requirements.

ISO 27017 Certification Cost in Malaysia

ISO 27017 certification cost varies between organizations.

Factors that can affect cost include:

  • Organization size

  • Number of employees

  • Cloud-service scope

  • Number of cloud platforms

  • Number of locations

  • Technical complexity

  • Existing ISO 27001 implementation

  • Documentation readiness

  • Assessment requirements

  • Number of business processes included

Businesses should obtain a scope-based quotation rather than relying on a generic certification price.

ISO 27017 in Kuala Lumpur, Selangor and Cyberjaya

Malaysia's major technology and business centres contain a wide range of organizations that may benefit from cloud-security assurance.

Relevant locations include Kuala Lumpur, Petaling Jaya, Shah Alam, Subang Jaya, Cyberjaya and Putrajaya.

Technology companies, SaaS providers, financial businesses, government technology suppliers and professional-service organizations in these areas may use cloud platforms as part of their core operations.

ISO 27017 is also relevant outside the Klang Valley.

ISO 27017 in Penang and Bayan Lepas

Penang has a significant technology and manufacturing ecosystem.

Organizations in George Town, Bayan Lepas and surrounding industrial areas may use cloud systems for enterprise applications, engineering information, production analytics, supplier management and digital services.

The relevant ISO 27017 scope should be based on the organization's cloud operations rather than geographic location.

ISO 27017 in Johor Bahru and Iskandar Malaysia

Johor's business, manufacturing, logistics and technology ecosystem creates demand for secure digital infrastructure.

Organizations in Johor Bahru, Iskandar Puteri, Pasir Gudang and Senai can consider ISO 27017 where cloud services support business-critical applications or customer-facing platforms.

ISO 27017 in Melaka, Ipoh and Other Malaysian Locations

Cloud-security requirements are not limited to Kuala Lumpur or established technology hubs.

Organizations in Melaka, Ipoh, Kuching, Kota Kinabalu and other Malaysian locations can pursue an appropriate cloud-security programme where their business model and customer requirements justify it.

Certification scope is determined by the organization's activities and controls, not by its city.

ISO 27017 vs ISO 27701 and ISO 27018

These standards have different purposes.

ISO 27001 focuses on the Information Security Management System.

ISO 27017 addresses cloud-specific information-security controls.

ISO 27701 focuses on privacy information management.

ISO 27018 addresses protection of personally identifiable information in applicable public-cloud environments.

A Malaysian organization may use more than one standard where its business and customer requirements justify a combined approach.

ISO 27017 vs CSA STAR

CSA STAR is associated with the Cloud Security Alliance's cloud-assurance programme and Cloud Controls Matrix.

ISO 27017 is an ISO/IEC standard focused on information-security controls and guidance for cloud services.

The two should not be presented as identical certifications.

A cloud provider should select an assurance approach according to customer expectations, contracts, market requirements and its overall security strategy.

Business Benefits of ISO 27017 Certification in Malaysia

The commercial value of ISO 27017 depends on the organization's actual requirements.

For a SaaS company, the main benefit may be stronger customer assurance during enterprise procurement.

For a cloud provider, the priority may be clearer allocation of provider and customer security responsibilities.

For a manufacturing or logistics company, the objective may be better control over cloud-dependent operational systems.

Potential business benefits include:

  • Clearer cloud-security responsibilities

  • Improved supplier governance

  • Better cloud-risk management

  • Stronger customer assurance

  • More structured security documentation

  • Better preparation for security questionnaires

  • Improved consistency across cloud services

  • Support for enterprise procurement discussions

Why Choose SCS for ISO 27017 in Malaysia?

Organizations considering ISO 27017 should begin with the actual cloud environment rather than a generic checklist.

The discussion should consider the proposed scope, cloud platform, information handled, provider responsibilities, customer responsibilities, existing ISO 27001 controls and applicable Malaysian legal or contractual requirements.

SCS Certification can discuss the proposed scope and the applicable ISO 27017 certification or assessment requirements with Malaysian organizations.

Get ISO 27017 Cloud Security Certification in Malaysia with SCS

If your organization operates a SaaS platform, cloud service, data centre, managed service, FinTech platform or another cloud-dependent business, the first step is to establish what needs to be covered.

SCS can help you discuss the proposed ISO 27017 scope, applicable requirements and the next steps for your organization.

Get Certified with SCS and strengthen your approach to cloud-security assurance in Malaysia.

Get Certified with SCS and discuss your Malaysia-specific cloud-security requirements.

https://scscertification.com/contactus.php

   UAE

Saudi Arabia

UK

Canada

India

SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE.

SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia

SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ.

SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada.

Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India.

Bangalore: Bangalore, Karnataka, India.

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

ISO/IEC 27017 is an international cloud-security standard providing cloud-specific information-security controls and guidance for cloud service providers and cloud service customers.
ISO 27017 is not a universal legal requirement for every Malaysian organization. It may become relevant because of customer requirements, contracts, sector expectations, regulatory environments or internal security objectives.
Yes. ISO/IEC 27017:2026 is the current published edition, while ISO/IEC 27017:2015 has been withdrawn.
No. ISO 27001 establishes requirements for an Information Security Management System, while ISO 27017 provides cloud-specific security controls and guidance.
Yes. Organizations can use ISO 27017 alongside ISO 27001 where cloud-specific controls need to be addressed within an existing or planned information-security management framework.
No. ISO 27017 does not replace Malaysia's Personal Data Protection Act or applicable privacy requirements.
No. The Cyber Security Act 2024 establishes statutory cybersecurity requirements. ISO 27017 addresses cloud-specific information-security controls and does not remove applicable legal obligations.
It can support cloud-security controls within an NCII environment, but organizations must separately determine their obligations under Malaysia's cybersecurity legislation and applicable NCII requirements.
SaaS companies can establish an ISO 27017 scope covering relevant cloud services and supporting processes, subject to the applicable certification or assessment arrangement.
Yes. Cloud providers can use ISO 27017 to address cloud-specific security responsibilities, including customer environments, access, supplier relationships and operational controls.
It can be relevant where a data-centre business provides or supports cloud services. The scope should identify the specific services and operations being assessed.
It can support cloud-security practices in financial organizations, but applicable Bank Negara Malaysia requirements and other financial-sector obligations must be addressed separately.
Yes. FinTech companies using cloud infrastructure can consider ISO 27017 for cloud-specific security controls while separately addressing applicable financial and regulatory requirements.
It can help healthcare and digital-health organizations manage cloud-specific information-security responsibilities, subject to applicable privacy, healthcare and cybersecurity requirements.
Yes. Manufacturing companies using cloud-based enterprise, engineering, analytics or operational systems can consider ISO 27017 where cloud-security risks are relevant.
Yes. Logistics organizations using cloud platforms for fleet management, shipment tracking, warehouse systems and customer applications can use cloud-security controls relevant to their environment.
Yes. Organizations in Kuala Lumpur can establish an ISO 27017 scope based on their cloud services, processes and information-security requirements.
Yes. SaaS, technology, digital-service and other cloud-dependent organizations in Cyberjaya can consider ISO 27017 where it is relevant to their business.
Yes. Companies in Penang, including technology and manufacturing organizations, can establish an appropriate ISO 27017 scope based on their cloud operations.
Yes. Organizations in Johor Bahru and surrounding business and industrial areas can consider ISO 27017 according to their cloud-security requirements.
Requirements and controls should be considered around cloud responsibilities, access management, information protection, supplier relationships, operational security, monitoring, incident management, continuity and other applicable cloud-security controls.
The first step is normally to define the cloud service, organizational scope, information involved, provider responsibilities and applicable legal, regulatory and contractual requirements.
Cost depends on factors such as organization size, cloud-service scope, number of locations, technical complexity, existing controls and assessment requirements.
The timeframe depends on the organization's readiness, cloud architecture, scope, number of services, documentation and assessment requirements.
Yes. Organizations with significant privacy-management requirements may consider ISO 27701 alongside ISO 27001 and ISO 27017, depending on their business needs.
ISO 27017 focuses on cloud-specific information-security controls, while ISO 27018 addresses protection of personally identifiable information in applicable public-cloud environments.
ISO 27017 is an ISO/IEC cloud-security standard, while CSA STAR is a Cloud Security Alliance assurance programme. They have different structures and purposes.
ISO 27017 can provide structured evidence of cloud-security controls and responsibilities, which may help organizations respond to relevant customer assurance requirements.
It can support customer assurance where prospective customers consider cloud-security controls during vendor selection, procurement or supplier assessment.
ISO 27017 addresses cloud services and cloud-specific information-security controls. Organizations should define their actual cloud environment and applicable scope before implementation.
Cloud-security controls can be considered for relevant private-cloud environments, subject to the organization's services, architecture and defined scope.
Organizations operating hybrid environments can consider ISO 27017 where cloud services and shared security responsibilities fall within the defined scope.
Cloud providers, SaaS companies, managed service providers and organizations with significant cloud-dependent operations may consider ISO 27017 when it supports their security, customer or regulatory objectives.
The appropriate relationship depends on the applicable certification or assessment arrangement and organizational objectives. Businesses should establish the intended scope and conformity-assessment requirements before deciding how to structure the implementation.
No standard can eliminate every cybersecurity risk. ISO 27017 provides structured controls and guidance that organizations can implement according to their cloud environment and risks.
No. Organizations must separately assess applicable Malaysian laws, regulations, contractual commitments and sector requirements.
Documentation depends on the scope but may include cloud-security policies, responsibilities, risk information, procedures, supplier controls, access controls, incident arrangements, operational records and objective evidence of implemented controls.
Yes. Clear allocation of security responsibilities between cloud providers and customers is an important consideration in cloud environments.
Yes. Managed service providers that operate or manage cloud environments can consider ISO 27017 for relevant cloud-security responsibilities.
Yes. Government-facing technology suppliers may consider ISO 27017 where cloud-security assurance is relevant to contractual, procurement or customer requirements.
Yes. E-commerce businesses using cloud platforms for customer accounts, applications, order information and other digital services can consider ISO 27017.
It can be relevant where telecommunications or digital-service operations include cloud services within the proposed security scope.
The scope should clearly identify relevant cloud services, systems, locations, processes, information, responsibilities and supporting activities.
Not necessarily. The scope should be based on business objectives, risks, customer requirements and the organization's actual cloud responsibilities.
It can support more structured management of cloud providers, subcontractors and other technology suppliers within the organization's security framework.
Yes. Cloud-security responsibilities and communication arrangements can be addressed as part of an organization's cloud-security controls and incident-management processes.
It can support consideration of availability and continuity controls appropriate to the organization's cloud services and business requirements.
Cloud services are used across technology, financial services, healthcare, manufacturing, logistics, telecommunications, retail, e-commerce, professional services and many other industries.
No. Any organization providing or using cloud services may consider relevant ISO 27017 controls depending on its business environment.
Yes. Organizations operating multiple cloud providers can consider cloud-specific security responsibilities across the relevant services within their defined scope.
Yes. Third-party and subcontracted cloud services can be considered within supplier and cloud-security controls where they fall within the organization's scope.
Organizations may consider it to strengthen cloud-security governance, clarify responsibilities, support customer assurance and improve the consistency of cloud-security controls.
SCS Certification can discuss the organization's cloud environment, proposed scope and applicable ISO 27017 certification or assessment requirements and help determine appropriate next steps.