SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO 27017 and ISO 27018 implementation

  Quote
Guest
Guest user Created:   Dec 02, 2016 Last commented:   Dec 02, 2016

ISO 27017 and ISO 27018 implementation

If our company develops software and provide SaaS service to customers( by hosting software in an cloud service provider). Also it got a development environment in xxx- developers connect to xxx and use tools for development . Is it recommended to implement - ISO 27017 OR 27018 or both ?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 02, 2016

I mean company just develop and deploy our software in cloud and give access to our different customers. We are NOT a cloud hosting company like xxx or xxx.

Answer: As you said, you provide the SaaS service to your customers, it does not matter if you use a third party infrastructure to do that. If their contractual relationship is with you, any problem your customers have caused by the cloud service provider you selected, they will charge from you. So, I would recommend you to implement both ISO 27017 and ISO 27018, so you have means to ensure that cloud service provider you use to provide your SaaS service properly protects both its cloud infrastructure and your customers data.

This article will provide you further explanation about supplier managem ent:
- 6-step process for handling supplier security according to ISO 27001 https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/

This article will provide you further explanation about ISO 27017 and ISO 27018:
- ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
- ISO 27001 vs. ISO 27018 – Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/

These materials will also help you regarding supplier management:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your
Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 02, 2016

Dec 02, 2016

Suggested Topics