ISO/IEC 27017 and ISO/IEC 27018 are codes of practice that take an ISMS into the cloud. Neither is certified on its own; both are audited as an extension of ISO/IEC 27001. This cloud security documentation set supplies the cloud-specific documents an ISMS does not already have.
On this page:
- Cloud documentation fails when it does not say who does what
- What is inside the cloud security documentation pack
- The shared responsibility matrix is the document auditors open first
- Who the cloud security documentation pack is written for
- What the cloud security documentation pack does not do
- Frequently asked questions
- Related toolkits
Cloud documentation fails when it does not say who does what
Every document here is marked as applying to the cloud service provider, the cloud service customer, or both, and a Cloud Service Role Determination Procedure settles which role you are in before anything else is written. Forty-eight documents apply to both sides, sixteen to providers including the whole ISO 27018 PII processor section, and three specifically to customers.
That marking is not cosmetic. The commonest failure in cloud security documentation is a control that both parties believe the other operates, and it is invisible until an incident or an audit surfaces it. Stating the side on the face of the document is the cheapest possible fix.
The 2026 second edition of ISO/IEC 27017 widened the picture considerably. It carries cloud guidance across the whole ISO/IEC 27002:2022 control set rather than a handful of cloud-only controls, and the pack follows it there: cryptography and key management, backup and restoration, continuity and resilience, personnel security, physical security of cloud facilities, vulnerability and patch management, secure development, and data masking and leakage prevention each get their own documents rather than a passing mention.
What is inside the cloud security documentation pack
67 templates in fourteen sections, ordered the way you would implement them, covering both editions of ISO/IEC 27017 and the full ISO 27018 control set.
- Foundation and scope – 6 documents, including the role determination that comes first.
- Shared responsibility – 6 documents, including the matrix an auditor asks for when your Statement of Applicability claims cloud coverage.
- Asset lifecycle and exit – 5 documents covering provisioning through to return and deletion of data.
- Virtualisation security – 6 documents, including virtual machine hardening and tenant separation.
- Cloud operations – 6 documents covering administrative operations and the operator access that concerns customers most.
- Monitoring and logging – 5 documents, including what a customer can and cannot see.
- Cloud network security – 4 documents.
- PII in public cloud – 10 documents, the ISO 27018 processor obligations in full.
- Cryptography and key management – covering who holds keys, which is the question customers ask first.
- Registers and matrices – 16 Excel tools, including the control mapping evidence that supports the Statement of Applicability claim.

The shared responsibility matrix is the document auditors open first
When an ISO 27001 Statement of Applicability claims that a control is implemented in a cloud service, the auditor will want to see how the responsibility is divided and what evidence supports your half of it. A matrix that says shared against every row answers nothing.
The matrix in this cloud security documentation breaks each control into the provider action, the customer action and the evidence each side holds, with the contractual basis noted where the division comes from the service agreement rather than from the standard. That is the version that survives an audit.
Neither standard is certified on its own, which is worth stating plainly because it is often implied otherwise. They are audited as extensions of ISO/IEC 27001, so the value here is the mapping evidence and the documents an ISMS genuinely does not contain, not a separate certificate.
Who the cloud security documentation pack is written for
- Cloud service providers, including SaaS vendors asked for ISO 27017 or 27018 alignment by customers.
- Cloud service customers whose ISMS scope now includes significant cloud estate.
- Organisations with an ISO 27001 certificate whose auditor has queried the cloud coverage in the Statement of Applicability.
- Processors handling personally identifiable information in public cloud, where ISO 27018 is the reference point.
What the cloud security documentation pack does not do
Neither standard certifies on its own. They are audited as extensions of ISO/IEC 27001, and cloud security documentation cannot change that.
It is not an ISMS. If you do not have one, start with ISO 27001 and add this.
It does not configure your cloud. The documents state what has to be true and what evidence proves it; the engineering is yours.
Frequently asked questions
Can we certify to ISO 27017 or ISO 27018?
Not on their own. Both are audited as extensions of an ISO/IEC 27001 certification, and any claim otherwise is worth checking closely.
Does it cover the 2026 second edition of ISO 27017?
Yes, and the withdrawn 2015 edition as well, because organisations mid-transition need both.
We are a customer, not a provider. Is most of it irrelevant?
No – 48 of the 67 documents apply to both sides, and 3 are customer-specific. The 16 provider-only documents are marked so you can set them aside.
What formats are the files in?
Native Microsoft Word and Excel, fully editable, with placeholders marked throughout.
Related toolkits
It extends the ISO 27001 toolkit, which is the prerequisite. Providers asked for attestation instead usually add the SOC 2 toolkit or the CSA STAR toolkit, and German-market providers the BSI C5:2026 toolkit. ISO publishes the standard at iso.org.
Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.
Delivery, format and licence
The cloud security documentation pack downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is locked, nothing is a PDF you cannot edit, and no add-on or portal login is needed to open it. Every organisation-specific value is marked as a placeholder so you can see what still has to be decided.
One payment, no subscription and no annual renewal. The source files behind the cloud security documentation pack are yours to adapt for your own organisation for as long as you need them, including future revisions of your own documents.




Reviews
There are no reviews yet.