INTERNATIONAL
STANDARD ISO/IEC
27017
First edition
2015-12-15
Information technology Security techniques Code
of practice for
information security controls based on ISO/IEC 27002
for cloud services
Technologies de I'information -Techniques de sécurité -Code de pratique
pour les contnδles de sécurité de I'information fondés sur
I'ISO/IEC 27002 pour les services du nuage
Copyrigh! Lnternalional Orga而zalio(l阳Slan由rdizalion
Provided by IHS under license wilh 1$0
No re阳oduC1ionOr闸阳αk;咱间 rmilledwithou lli曲n回"αnlHS壁 、
.FL·
-/gaE
t? /
T··
\
一Reference number
ISO/IEC 27017:2015(E)
" .. , ..…… . " . 。ISO/IEC2015
Nollor Resale , 1212512015四36:40MST ISO/IEC 27017:2015(E)
COPYRIGHT PROTECTED DOCUMENT
。ISO/lEC2015
AII rights reserved. Unless otherwise specili ed, no part 01 this publication may be reproduced or utilized otherwise in any lorm or by any means
, electronic or mechanical , including photocopying , or posting on the internet or an intranet, without prior written permission Permission can be requested Irom either ISO at the address below or ISO's member body in the country
01 the requeste r.
ISO copyright office Case postale 56. CH-
1211 Geneva 20 Te
l. +41227490111
Fax + 41227490947
E-mail
[email protected] Web www.iso.org Published in Switzerland
" .. ",..." ,.",,,....,,.,,.
Copyrigh! Lnternalional Orga由刷刷阳 Slan由rdizalion
Provided by IHS uoder license wilh 1 $0
No re阳oduC1ionOr闸阳αk;咱间 rmilledwithoulli 曲n回"αnlHS。ISOIIEC2015 -AII rights reserved
Nollor Resale, 12125120 15四36:40MST ISO/IEC 27017:2015(E)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO
or IEC pa时icipatein the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interes
t. Other international organizations , governmental and non-governmental
, in liaison with ISO and IEC , also take part in the work. In the field of information technology
, ISO and IEC have established a joint technical committee , ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given
in the ISO/IEC Directives , Part 2.
The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as
an International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some
of the elements of this document may be the subject of patent rights. I
SO and IEC shall not be held responsible for identifying any or all such patent rights
1··
···
····· ISO/IEC 27017 was prepared by Joint Technical Committee I SO/IEC JTC 1 , Information technology ,
Subcommittee SC 27 , IT Security techniques , in collaboration with ITU-T. The identical text is published as ITU-T. X.1631 (07/2015).
111
Nollor Resale, 1212512015四36:40MST 臼pyrigh!Lnternaliona l由2432ii几2JA751 ,onAl|rlghtS 『eserved
Provided by IHS under license wilh 1 $0
No re阳oduC1ionor闸阳αki咱间 rmilledwithoulli 曲n回IrαnlHSCopyrigh! Lnternalional Orga而zation阳Slan由rdization
Provided by IHS under license wilh 1 $0
No re阳oduC1ionor闸阳αk;咱间 rmilledwithoulli 曲n回"αnlHS Nollor Resale, 1212512015四36:40MST -International Telecomn 、unication Union
ITU-T
TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU X.1631
SERIES X: DATA NETWORKS , OPEN SYSTEM COMMUNICATIONS AND SECURITY Cloud computing security -Cloud computing security design
Information technology -Security techniques -Code
of practice for information security
controls based on ISO/IEC 27002 for cloud
servlces
Recommendation ITU-T X.1631
.n'l:.lI"n…..",.1
T.I…"'1ft ...阴ICJ.....oII
UnlGn
Copyri