Expert Advice Community

Guest

Question about ISO 27001 and ISO 27017

  Quote
Guest
Guest user Created:   Nov 16, 2020 Last commented:   Nov 16, 2020

Question about ISO 27001 and ISO 27017

Does a company have to have ISO27001 as well as ISO27017 or can it have just ISO27017?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 16, 2020

Please note that ISO 27017 is a supporting standard, providing guidance and recommendations for the implementation of cloud-related controls, and it does not have the requirements for a management system.
 
Considering that, if you are considering implementing an Information Security Management System, then you need ISO 27001 (it is enough to cover cloud security requirements, and you will only need ISO 27017 if you have specific legal requirements demanding the use of ISO 27017).
 
Now, if you are considering only adopting specific cloud-related controls, without using the support of a management system, then you can use only ISO 27017.  

These articles will provide you a further explanation about ISO 27001 and ISO 27017:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 16, 2020

Nov 16, 2020

Suggested Topics

Guest user Created:   Nov 13, 2020 ISO 27001 & 22301
Replies: 1
2 0

Finding ISO 27017/18 content

Guest user Created:   May 21, 2020 ISO 27001 & 22301
Replies: 1
0 0

Project Plan