ISO 27017 / ISO 27018
On this page
What are ISO 27017 / ISO 27018?
In conjunction with certification to ISO/IEC 27001, there is the option of having a supplementary conformity assessment carried out against further standards from the ISO 27000 family.
Well-known further standards besides ISO/IEC 27005 (risk management) are in particular:
- ISO/IEC 27017 – Code of practice for information security controls based on ISO/IEC 27002 for cloud services
- ISO/IEC 27018 – Code of practice for the protection of personally identifiable information (PII) in public clouds acting as PII processors
Both ISO/IEC 27017 and ISO/IEC 27018 give specific detail to requirements from ISO/IEC 27002 and are therefore to be regarded as extensions.
A conformity assessment to ISO/IEC 27017 and ISO/IEC 27018 is possible only in conjunction with a valid certificate to ISO/IEC 27001.
Benefits of a conformity assessment to ISO/IEC 27017 or ISO/IEC 27018
Process of a conformity assessment
An audit to ISO/IEC 27017 and ISO/IEC 27018 is generally carried out in line with the process for ISO/IEC 27001 certification, due to its link to a valid ISO/IEC 27001 certificate. The maximum validity of the conformity assessment is governed by the validity of your ISO/IEC certificate. The implemented measures are also monitored annually for their continued effectiveness.
Your path to an audit
- Submit an enquiry and optionally arrange an introductory meeting via video call at short notice
- Complete our basic data as a basis for an initial understanding of your organisation and for calculating the audit time required
- Place the order with RSM Certification GmbH and jointly coordinate the next steps (including scheduling)
- If carried out as part of an ISO/IEC 27001 certification:
- To gain a better understanding of your organisation and your ISMS: conducting the Stage 1 audit in a joint remote session and determining certification readiness
- Conducting the Stage 2 audit, the effectiveness review of your ISMS
- Technical review of the auditor(s)' documentation and the certification decision by RSM Certification GmbH
- Issuing of the ISO/IEC 27001 certificate and a confirmation of conformity
- Handover of the audit report, the certificate, the confirmation of conformity and the certification seal
- Reviewing the continuous development of the ISMS as part of the surveillance audits
- If carried out separately from an ISO/IEC 27001 certification:
- Conducting the document review, inspection and examination of your existing certificate and the audit documentation
- Effectiveness review of the implemented measures in accordance with the requirements of ISO/IEC 27017 or ISO/IEC 27018
- Technical review of the auditor(s)' documentation by RSM Certification GmbH
- Issuing of a confirmation of conformity
- Handover of the audit report, the confirmation of conformity and the conformity assessment seals
- Reviewing the continuous development of the ISMS in conjunction with ISO/IEC 27017 or ISO/IEC 27018 as part of the surveillance audits
Certification by RSM Certification GmbH
Would you like us to certify you? Feel free to get in touch with us without obligation.
Get in touch without obligation
FAQ
The costs cannot be estimated in general terms, as they always depend on the organisation and in particular on its business purpose and assets. Both standards are elaborations of ISO/IEC 27002 for providers of cloud services. The audit effort is therefore not comparable with the scope of an ISO 27001 audit and is proportionally lower accordingly.
Both standards can also be audited as a combined audit with ISO/IEC 27001. Combined audits can reduce the total costs thanks to the resulting synergy effects.