ISO/IEC 27017 provides guidance on information security controls for cloud services based on ISO/IEC 27002. It offers additional guidance and controls to address security issues specific to the cloud computing environment.
ISO/IEC 27017 is applicable to both cloud service providers and cloud clients. It assists organizations in implementing a secure cloud computing information security management system.
SITE Cloud has achieved ISO/IEC 27017 certification for its implementation of cloud-specific information security controls.
The SITE Cloud ISO/IEC 27017 certificate validates compliance with key controls for cloud security.
Clients can leverage SITE Cloud's ISO/IEC 27017 certification to support compliance for workloads and data stored on the SITE Cloud.
The SITE Cloud ISO/IEC 27017 certification applies to the following in-scope cloud services:
ISO/IEC 27017 provides guidance for both cloud providers and cloud clients. It assists organizations in implementing secure cloud computing environments.
Audit certificates is available through the SITE Cloud Support Portal.
Yes, SITE Cloud's certification can be used to demonstrate compliance for client workloads hosted on the platform. However, clients are responsible for compliance of their own cloud implementation and internal controls.