SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO certifications for cloud computing

  Quote
Guest
Guest user Created:   Jan 02, 2019 Last commented:   Jan 02, 2019

ISO certifications for cloud computing

Could you please guide me on what are the ISO specific certifications (similar to 27001 for ISMS) that are required for Cloud Computing (for service providers and consumers)?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 02, 2019

I was checking ISO/IEC 27017:2015, and wondering if I'm missing something.

Answer:

There is no specific ISO certifications for cloud computing. What you can consider is the implementation of specific controls of ISO 27017 in an ISMS (ISO 27001 already cover the general controls to also protect cloud services), if you have specific requirements (e.g., laws, regulations or contracts) demanding security controls for cloud environments.

Additionally, I suggest you to consider ISO 27018, ISO standard related to protection of Personal Identifiable Information (PII), to fulfill potential requirements you have regarding the protection of customers privacy.

These articles will provide you further explanation about ISO 27017 and ISO 27018:
- ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
- ISO 27001 vs. ISO 27018 – Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 02, 2019

Jan 02, 2019

Suggested Topics