How can I help with ISO 27017 and 27018?

Free AI guidance for cloud security and cloud privacy.

About the ISO 27017 and 27018 assistant

Seeded with ISO/IEC 27017:2026 and ISO/IEC 27018:2025 cloud concepts: how the 27017 controls and guidance build on ISO/IEC 27002 with cloud-specific implementation guidance and additional controls for cloud service customers and cloud service providers, across public, private, and hybrid deployments, and how the 27018 guidelines protect personally identifiable information (PII) when a public cloud provider acts as a PII processor, aligned with the ISO/IEC 27002:2022 control structure. It covers shared responsibility between cloud customers and providers, selecting cloud controls against risk and contractual requirements, transparency and sub-processor management, and how the two standards complement an ISO/IEC 27001 ISMS.

  • Map who is responsible for what between your organisation and your cloud providers, understand the cloud-specific guidance and additional controls for cloud service customers and cloud service providers, and see how those controls apply across public, private, and hybrid cloud deployments where responsibilities, infrastructure, and operations are divided between parties.
  • Assess cloud services against the ISO/IEC 27018 guidelines for protecting personally identifiable information (PII) when a public cloud provider acts as a PII processor, covering practices such as transparency with customers, handling disclosure requests, managing sub-processors, and returning or securely deleting personal data at the end of a contract, whether you are the provider or the customer outsourcing the processing.
  • Select and justify cloud-specific controls from both standards against your risk assessment and your legal, regulatory, and contractual requirements, extend an ISO/IEC 27001 ISMS to cover your cloud services, and prepare the evidence a certification body may ask for when auditing cloud security and cloud privacy.

It gives guidance to speed up your work. ISMS Copilot is not a certification body and cannot certify your cloud security or privacy controls; certification comes from an independent certification body after its own audit, and choosing an accredited body gives independent confirmation of its competence. This is not a certification service, and it is not legal advice.

Read the full ISO 27017 guide