Icon Wolke mit Netzwerkverbindungen

ISO 27017 / ISO 27018


What are ISO 27017 / ISO 27018?

In conjunction with certification to ISO/IEC 27001, there is the option of having a supplementary conformity assessment carried out against further standards from the ISO 27000 family.

Well-known further standards besides ISO/IEC 27005 (risk management) are in particular:

  • ISO/IEC 27017 – Code of practice for information security controls based on ISO/IEC 27002 for cloud services
  • ISO/IEC 27018 – Code of practice for the protection of personally identifiable information (PII) in public clouds acting as PII processors

Both ISO/IEC 27017 and ISO/IEC 27018 give specific detail to requirements from ISO/IEC 27002 and are therefore to be regarded as extensions.

A conformity assessment to ISO/IEC 27017 and ISO/IEC 27018 is possible only in conjunction with a valid certificate to ISO/IEC 27001.


Benefits of a conformity assessment to ISO/IEC 27017 or ISO/IEC 27018

Improved perception of information security as an organisational attribute, both externally and internally

Additional evidence regarding your cloud security measures and/or the handling of personal data in your organisation

Competitive advantages and, at the same time, proof of trustworthiness and reliability

Proof of effectiveness of the security measures you have implemented, through an independent audit

Compliance – meeting legal and regulatory requirements

A stronger information security awareness and thus a higher level of information security in the organisation

Option of a combined audit with certification to ISO/IEC 27001


Process of a conformity assessment

An audit to ISO/IEC 27017 and ISO/IEC 27018 is generally carried out in line with the process for ISO/IEC 27001 certification, due to its link to a valid ISO/IEC 27001 certificate. The maximum validity of the conformity assessment is governed by the validity of your ISO/IEC certificate. The implemented measures are also monitored annually for their continued effectiveness.


Your path to an audit

  1. Submit an enquiry and optionally arrange an introductory meeting via video call at short notice
  2. Complete our basic data as a basis for an initial understanding of your organisation and for calculating the audit time required
  3. Place the order with RSM Certification GmbH and jointly coordinate the next steps (including scheduling)
  4. If carried out as part of an ISO/IEC 27001 certification:
    1. To gain a better understanding of your organisation and your ISMS: conducting the Stage 1 audit in a joint remote session and determining certification readiness
    2. Conducting the Stage 2 audit, the effectiveness review of your ISMS
    3. Technical review of the auditor(s)' documentation and the certification decision by RSM Certification GmbH
    4. Issuing of the ISO/IEC 27001 certificate and a confirmation of conformity
    5. Handover of the audit report, the certificate, the confirmation of conformity and the certification seal
    6. Reviewing the continuous development of the ISMS as part of the surveillance audits
  5. If carried out separately from an ISO/IEC 27001 certification:
    1. Conducting the document review, inspection and examination of your existing certificate and the audit documentation
    2. Effectiveness review of the implemented measures in accordance with the requirements of ISO/IEC 27017 or ISO/IEC 27018
    3. Technical review of the auditor(s)' documentation by RSM Certification GmbH
    4. Issuing of a confirmation of conformity
    5. Handover of the audit report, the confirmation of conformity and the conformity assessment seals
    6. Reviewing the continuous development of the ISMS in conjunction with ISO/IEC 27017 or ISO/IEC 27018 as part of the surveillance audits

Certification by RSM Certification GmbH

Would you like us to certify you? Feel free to get in touch with us without obligation.

info@rsm-certification.com
+49 211 540148 00


Get in touch without obligation

Please calculate 7 plus 8.

FAQ

How much does an audit to ISO/IEC 27017 and ISO/IEC 27018 cost?

The costs cannot be estimated in general terms, as they always depend on the organisation and in particular on its business purpose and assets. Both standards are elaborations of ISO/IEC 27002 for providers of cloud services. The audit effort is therefore not comparable with the scope of an ISO 27001 audit and is proportionally lower accordingly.

Both standards can also be audited as a combined audit with ISO/IEC 27001. Combined audits can reduce the total costs thanks to the resulting synergy effects.