ISO 27017 Cloud Security Certification in Malaysia – Cloud Requirements, Malaysian Laws & Get Certified with SCS
SCS Certification – Malaysia Office
SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia
Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification
https://scscertification.com/contactus.php
Cloud services are now embedded in the operations of Malaysian businesses across financial services, technology, manufacturing, healthcare, telecommunications, logistics, e-commerce and government-facing digital services. As organizations move applications, databases and business processes to public, private and hybrid cloud environments, responsibility for information security becomes shared between the customer, cloud provider and other technology suppliers.
ISO/IEC 27017 provides cloud-specific information-security controls and guidance for organizations providing or using cloud services. The current international edition is ISO/IEC 27017:2026, which addresses information-security controls based on ISO/IEC 27002 for cloud services.
For Malaysian organizations, ISO 27017 can be considered alongside the Personal Data Protection Act 2010, Cyber Security Act 2024, National Cloud Computing Policy, sector-specific requirements and contractual security obligations.
ISO 27017 does not replace Malaysian law. Its value is in helping an organization establish a structured approach to managing security responsibilities within its cloud environment.
SCS Certification can help organizations understand the appropriate ISO 27017 scope, requirements and certification or assessment pathway.
What Is ISO 27017 Cloud Security Certification in Malaysia?
ISO/IEC 27017 is an international cloud-security standard designed to address information-security considerations that arise when organizations provide or use cloud services.
The standard is particularly relevant where security responsibilities are divided between different parties.
For example, a Malaysian SaaS company may develop and operate a business application while using a third-party cloud provider for infrastructure. The cloud provider may manage physical facilities, computing resources and certain network controls, while the SaaS company remains responsible for application security, customer access, data management and configuration.
ISO 27017 helps organizations establish clearer expectations around these responsibilities.
It can therefore be relevant to:
-
Cloud service providers
-
SaaS companies
-
Managed service providers
-
Data-centre and cloud infrastructure businesses
-
FinTech companies
-
Financial-sector organizations
-
Healthcare technology providers
-
Telecommunications businesses
-
E-commerce platforms
-
Manufacturing companies using cloud systems
-
Logistics and transportation businesses
-
Government technology suppliers
-
Organizations operating critical digital services
ISO/IEC 27017:2026 and Malaysian Businesses
Organizations developing a new ISO 27017 programme should consider the current edition of the standard.
ISO/IEC 27017:2026 is the current published edition, while ISO/IEC 27017:2015 has been withdrawn.
Businesses that previously used ISO/IEC 27017:2015 should review their current arrangements and confirm the applicable transition or reassessment requirements with their certification or assessment provider.
The 2026 edition remains focused on cloud-specific information-security controls and the responsibilities of cloud service providers and cloud service customers.
For Malaysian organizations, the first practical step is to define exactly which cloud services, information, processes and responsibilities are included within the intended scope.
ISO 27017 and ISO 27001 in Malaysia
ISO 27017 and ISO 27001 address different aspects of information security.
ISO 27001 specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System.
ISO 27017 provides cloud-specific controls and guidance that can complement an organization's broader information-security framework.
A Malaysian SaaS provider, for example, may establish an ISO 27001-based ISMS and then use ISO 27017 to address cloud-specific security responsibilities.
This distinction is important for businesses researching certification because ISO 27017 should not be presented as simply another name for ISO 27001.
Malaysia's National Cloud Computing Policy and ISO 27017
Malaysia's National Cloud Computing Policy provides a national framework for the development and adoption of cloud computing.
The policy is relevant to organizations involved in Malaysia's cloud ecosystem, including cloud providers, government organizations, businesses and technology stakeholders.
ISO 27017 and the National Cloud Computing Policy have different roles.
The National Cloud Computing Policy is a Malaysian national policy framework, while ISO 27017 is an international cloud-security standard.
An organization should therefore determine which national policy expectations, legal obligations and sector requirements apply to its activities and then consider how ISO 27017 can support its cloud-security controls.
Malaysian Laws Relevant to Cloud Security
There is no general Malaysian law requiring every organization to obtain ISO 27017 certification.
However, organizations using or providing cloud services may have legal, regulatory or contractual responsibilities depending on the nature of their business and the information they process.
Relevant areas may include:
-
Personal Data Protection Act 2010
-
Personal Data Protection (Amendment) Act 2024
-
Cyber Security Act 2024
-
National Critical Information Infrastructure requirements
-
Bank Negara Malaysia requirements for regulated financial institutions
-
Sector-specific cybersecurity obligations
-
Government and enterprise procurement requirements
-
Customer contractual requirements
ISO 27017 should therefore be viewed as part of an organization's cloud-security and assurance framework rather than as a substitute for statutory compliance.
ISO 27017 and Malaysia's Personal Data Protection Act
The Personal Data Protection Act 2010 regulates the processing of personal data in commercial transactions in Malaysia.
Cloud environments can make personal-data management more complex because information may pass between business applications, cloud platforms, service providers, subcontractors and support systems.
A Malaysian organization should understand where personal data is stored, who can access it, which providers process it, how access is controlled and how security incidents are managed.
ISO 27017 can support cloud-security controls around these activities, but certification does not automatically mean that an organization is compliant with the PDPA.
Privacy compliance and cloud-security assurance should be assessed separately.
ISO 27017 and the Cyber Security Act 2024
Malaysia's Cyber Security Act 2024 establishes a national cybersecurity framework that includes arrangements for National Critical Information Infrastructure.
NACSA identifies sectors including government, banking and finance, transportation, defence and national security, information and communications, healthcare, water, sewerage and waste management, energy, agriculture and plantation, trade and industry, and science, technology and innovation.
Organizations operating within relevant NCII environments should determine their specific obligations under the Act and associated requirements.
ISO 27017 can support cloud-security controls within such environments, but it does not replace obligations created by Malaysian cybersecurity legislation.
ISO 27017 for Cloud Service Providers in Malaysia
Cloud providers face security responsibilities that may differ from those of ordinary cloud customers.
A provider may be responsible for infrastructure, virtualization, networks, privileged administration, availability, monitoring and customer-environment separation.
A strong cloud-security programme should establish clear boundaries between the provider's responsibilities and those of customers.
Areas that may require attention include access management, administrative privileges, customer isolation, incident communication, supplier management, service continuity and changes to cloud infrastructure.
ISO 27017 can provide a structured basis for addressing these cloud-specific issues.
ISO 27017 for SaaS Companies in Malaysia
SaaS companies often depend on several technology layers.
The application may be controlled by the SaaS company while infrastructure, databases, identity services, monitoring or backup functions are supplied by other organizations.
This creates a shared-responsibility environment.
ISO 27017 can help Malaysian SaaS providers document security responsibilities and establish clearer controls for their cloud services.
This can also be useful when enterprise customers conduct supplier security assessments before purchasing a SaaS service.
The certification scope should describe the actual service and supporting activities instead of claiming coverage of every technology used by the company.
ISO 27017 for Malaysian Data Centres
Data centres and cloud infrastructure providers operate environments where availability, access control, physical protection, network security and logical separation may all be important.
A suitable ISO 27017 scope may include selected cloud infrastructure, managed services or supporting operations.
The scope should clearly identify the facilities, services and processes covered.
A company should avoid suggesting that all customer environments are certified when only a defined service or business unit falls within the assessed scope.
ISO 27017 for Banking and FinTech in Malaysia
Financial institutions and FinTech businesses can have complex technology environments involving customer information, payment systems, cloud applications and external technology suppliers.
Cloud-security controls should be considered alongside applicable financial-sector requirements.
ISO 27017 can help organizations structure cloud-specific controls relating to access, supplier responsibilities, operational security and information protection.
For regulated financial institutions, ISO 27017 does not replace Bank Negara Malaysia requirements.
The organization should map its cloud environment against all applicable regulatory and contractual requirements.
ISO 27017 for Healthcare and Digital Health
Healthcare providers and digital-health businesses may use cloud systems for electronic records, appointment platforms, laboratory applications, telemedicine and analytics.
These environments can involve sensitive information and multiple technology providers.
ISO 27017 can help organizations examine how cloud security responsibilities are divided between healthcare organizations, cloud providers and technology suppliers.
Applicable Malaysian privacy, cybersecurity and healthcare requirements must still be considered separately.
ISO 27017 for Telecommunications and Digital Services
Telecommunications companies and digital-service providers can operate complex environments involving customer platforms, networks, applications and cloud infrastructure.
Where cloud services form part of those operations, ISO 27017 can support structured management of cloud-specific information-security controls.
The scope should reflect the actual service being assessed and should distinguish cloud operations from unrelated telecommunications activities.
ISO 27017 for Manufacturing and Industrial Companies
Manufacturing organizations increasingly use cloud applications for enterprise resource planning, production analytics, engineering collaboration, supplier management and connected operations.
A manufacturer does not need to be a cloud provider to have cloud-security responsibilities.
The organization should identify which cloud services process business or production information, who administers those services and how external providers are controlled.
ISO 27017 can be incorporated into the security governance of those cloud-dependent operations.
ISO 27017 for Logistics and Transportation
Logistics companies may use cloud platforms for fleet management, shipment tracking, warehouse management, customer portals and operational analytics.
A security incident affecting one of these systems could disrupt business operations even if the company does not own the underlying cloud infrastructure.
ISO 27017 can help organizations define responsibilities for cloud access, monitoring, suppliers, incident handling and service continuity.
Transportation organizations should also determine whether additional requirements apply because of their role in critical infrastructure or regulated services.
ISO 27017 for E-Commerce and Digital Platforms
E-commerce companies can operate cloud environments containing customer accounts, order information, application data and business analytics.
Security responsibilities may be divided among the platform owner, cloud provider, payment-service provider and other technology suppliers.
An ISO 27017 implementation can help clarify those relationships and strengthen the organization's cloud-security framework.
The scope should remain specific to the relevant services and information systems.
ISO 27017 Cloud Security Requirements for Malaysian Organizations
A practical ISO 27017 programme should be built around the organization's real cloud environment.
Define Cloud Responsibilities
The organization should identify which security responsibilities are handled internally and which are delegated to cloud providers or other suppliers.
Establish Cloud-Service Agreements
Contracts should clearly address relevant security responsibilities, access, incident communication, service expectations and applicable obligations.
Manage Privileged Access
Administrative accounts should be controlled through appropriate authorization, authentication, monitoring and periodic review.
Protect Cloud Environments
The organization should understand how workloads, applications and customer information are logically separated and protected.
Manage Cloud Changes
Changes to applications, infrastructure and configurations should follow defined change-management controls.
Monitor Cloud Services
Monitoring should be appropriate to the importance and risk profile of the cloud service.
Control Suppliers
Cloud providers, subcontractors and technology suppliers should be assessed according to their relevance to the organization's security requirements.
Prepare for Cloud Incidents
Incident responsibilities should be agreed between the organization and relevant providers before an incident occurs.
Address Cloud Continuity
Critical services should have appropriate availability, backup and continuity arrangements based on business requirements.
Protect Cloud Information
Organizations should establish appropriate controls for information classification, access, retention, deletion and transfer.
ISO 27017 Certification Scope in Malaysia
The certification or assessment scope should describe the actual cloud service being evaluated.
Possible scopes include:
-
A SaaS platform
-
Cloud infrastructure services
-
Managed cloud services
-
A data-centre operation
-
A defined business unit
-
Selected cloud applications
-
Cloud-related support services
-
A specific customer-facing digital platform
A narrow scope is not automatically better. If important cloud activities are excluded, the resulting certification may provide limited assurance to customers.
The scope should be practical, transparent and consistent with the organization's actual operations.
How to Implement ISO 27017 in Malaysia
1. Identify the Cloud Environment
Document the cloud platforms, applications, services and external providers used within the proposed scope.
2. Establish the Security Boundary
Determine which controls are operated by the organization and which are managed by cloud providers.
3. Identify Cloud Risks
Assess risks involving confidentiality, integrity, availability, access, supplier dependency and service continuity.
4. Review Existing Controls
Compare existing practices against applicable ISO 27017 controls and business requirements.
5. Close Identified Gaps
Improve policies, procedures, contracts and technical controls where required.
6. Maintain Objective Evidence
Keep records demonstrating that controls have been implemented and are operating effectively.
7. Conduct Internal Review
Evaluate readiness before the external certification or assessment process.
8. Complete the External Assessment
The applicable certification or assessment process will depend on the scope, scheme and conformity-assessment arrangements.
ISO 27017 Certification Process in Malaysia
The process normally begins with defining the proposed cloud-security scope.
The organization then reviews its existing security controls and identifies areas requiring improvement.
Where ISO 27001 is already implemented, ISO 27017 controls can often be integrated into the existing information-security management framework.
The organization prepares the required documentation and objective evidence before the assessment.
Any findings are addressed through the applicable corrective-action process.
The overall timeframe depends on the organization's readiness, cloud architecture, number of services, locations and assessment requirements.
ISO 27017 Certification Cost in Malaysia
ISO 27017 certification cost varies between organizations.
Factors that can affect cost include:
-
Organization size
-
Number of employees
-
Cloud-service scope
-
Number of cloud platforms
-
Number of locations
-
Technical complexity
-
Existing ISO 27001 implementation
-
Documentation readiness
-
Assessment requirements
-
Number of business processes included
Businesses should obtain a scope-based quotation rather than relying on a generic certification price.
ISO 27017 in Kuala Lumpur, Selangor and Cyberjaya
Malaysia's major technology and business centres contain a wide range of organizations that may benefit from cloud-security assurance.
Relevant locations include Kuala Lumpur, Petaling Jaya, Shah Alam, Subang Jaya, Cyberjaya and Putrajaya.
Technology companies, SaaS providers, financial businesses, government technology suppliers and professional-service organizations in these areas may use cloud platforms as part of their core operations.
ISO 27017 is also relevant outside the Klang Valley.
ISO 27017 in Penang and Bayan Lepas
Penang has a significant technology and manufacturing ecosystem.
Organizations in George Town, Bayan Lepas and surrounding industrial areas may use cloud systems for enterprise applications, engineering information, production analytics, supplier management and digital services.
The relevant ISO 27017 scope should be based on the organization's cloud operations rather than geographic location.
ISO 27017 in Johor Bahru and Iskandar Malaysia
Johor's business, manufacturing, logistics and technology ecosystem creates demand for secure digital infrastructure.
Organizations in Johor Bahru, Iskandar Puteri, Pasir Gudang and Senai can consider ISO 27017 where cloud services support business-critical applications or customer-facing platforms.
ISO 27017 in Melaka, Ipoh and Other Malaysian Locations
Cloud-security requirements are not limited to Kuala Lumpur or established technology hubs.
Organizations in Melaka, Ipoh, Kuching, Kota Kinabalu and other Malaysian locations can pursue an appropriate cloud-security programme where their business model and customer requirements justify it.
Certification scope is determined by the organization's activities and controls, not by its city.
ISO 27017 vs ISO 27701 and ISO 27018
These standards have different purposes.
ISO 27001 focuses on the Information Security Management System.
ISO 27017 addresses cloud-specific information-security controls.
ISO 27701 focuses on privacy information management.
ISO 27018 addresses protection of personally identifiable information in applicable public-cloud environments.
A Malaysian organization may use more than one standard where its business and customer requirements justify a combined approach.
ISO 27017 vs CSA STAR
CSA STAR is associated with the Cloud Security Alliance's cloud-assurance programme and Cloud Controls Matrix.
ISO 27017 is an ISO/IEC standard focused on information-security controls and guidance for cloud services.
The two should not be presented as identical certifications.
A cloud provider should select an assurance approach according to customer expectations, contracts, market requirements and its overall security strategy.
Business Benefits of ISO 27017 Certification in Malaysia
The commercial value of ISO 27017 depends on the organization's actual requirements.
For a SaaS company, the main benefit may be stronger customer assurance during enterprise procurement.
For a cloud provider, the priority may be clearer allocation of provider and customer security responsibilities.
For a manufacturing or logistics company, the objective may be better control over cloud-dependent operational systems.
Potential business benefits include:
-
Clearer cloud-security responsibilities
-
Improved supplier governance
-
Better cloud-risk management
-
Stronger customer assurance
-
More structured security documentation
-
Better preparation for security questionnaires
-
Improved consistency across cloud services
-
Support for enterprise procurement discussions
Why Choose SCS for ISO 27017 in Malaysia?
Organizations considering ISO 27017 should begin with the actual cloud environment rather than a generic checklist.
The discussion should consider the proposed scope, cloud platform, information handled, provider responsibilities, customer responsibilities, existing ISO 27001 controls and applicable Malaysian legal or contractual requirements.
SCS Certification can discuss the proposed scope and the applicable ISO 27017 certification or assessment requirements with Malaysian organizations.
Get ISO 27017 Cloud Security Certification in Malaysia with SCS
If your organization operates a SaaS platform, cloud service, data centre, managed service, FinTech platform or another cloud-dependent business, the first step is to establish what needs to be covered.
SCS can help you discuss the proposed ISO 27017 scope, applicable requirements and the next steps for your organization.
Get Certified with SCS and strengthen your approach to cloud-security assurance in Malaysia.
Get Certified with SCS and discuss your Malaysia-specific cloud-security requirements.
https://scscertification.com/contactus.php
|
UAE |
Saudi Arabia |
UK |
Canada |
India |
|
SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE. |
SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia |
SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ. |
SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada. |
Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India. Bangalore: Bangalore, Karnataka, India. |
Need ISO Certification for Your Business?
Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.