Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

Comprehensive ISO 27017 Toolkit & ISO 27018 Cloud Pack – 67 Templates

ISO 27017 Toolkit delivers 67 ready-to-use Microsoft Office templates that extend a certified ISO 27001 ISMS into the cloud — covering the seven ISO 27017 CLD controls, shared responsibility with your provider, virtualisation and tenant isolation, cloud monitoring, and the ISO 27018 obligations that apply when you process personal information as a processor in a public cloud.

$99.00

✓ In stock — instant download after checkout

Instant downloadYour files are available immediately after checkout
Fully editableNative Microsoft Word & Excel templates
30-day money-back guaranteeNot satisfied? Request a refund within 30 days
🔒Secure checkoutEncrypted payment powered by Stripe

Description

About the ISO 27017 Toolkit

The ISO 27017 Toolkit gives you the cloud half of an information security management system. ISO/IEC 27017 and ISO/IEC 27018 are the two codes of practice that take an ISMS into the cloud. Neither is certified on its own — both are audited as an extension of ISO/IEC 27001 — and that is exactly how this toolkit is built. It supplies the cloud-specific documents an ISMS does not already have, states in each one how it supplements the ISMS rather than replacing it, and gives you the mapping evidence an auditor asks for when your Statement of Applicability claims cloud coverage.

The ISO 27017 Toolkit contains 67 templates: 51 Word documents and 16 Excel registers, matrices and checklists. Every document is written to the control it implements, cross-referenced to the others, and editable in Microsoft Office.

What is included in the ISO 27017 Toolkit?

  • 67 documentation templates — the ISO 27017 Toolkit covers the cloud controls of both editions of ISO/IEC 27017, the 2026 second edition and the withdrawn 2015 edition, and the full ISO 27018 privacy control set with policies, procedures, standards, registers, matrices and checklists
  • All files in Microsoft Office format (.docx, .xlsx) — fully editable, with every organisation-specific value marked as a placeholder
  • Instant download immediately after purchase

The 2026 edition carries cloud guidance across the whole ISO/IEC 27002:2022 control set, not just a handful of cloud-only controls, and the ISO 27017 Toolkit follows it there: cryptography and key management, backup and restoration, continuity and resilience, personnel security, physical security of cloud facilities, vulnerability and patch management, secure development, and data masking and leakage prevention each have their own documents rather than a passing mention.

Built for both sides of the cloud contract

Cloud security documentation fails when it does not say who does what. The ISO 27017 Toolkit is explicit about it: every document is marked as applying to the cloud service provider, the cloud service customer, or both, and the Cloud Service Role Determination Procedure settles which role you are in before anything else is written.

  • 48 documents apply to both provider and customer
  • 16 documents apply to cloud service providers, including the whole ISO 27018 PII processor section
  • 3 documents apply specifically to cloud service customers

ISO 27017 Toolkit structure

The ISO 27017 Toolkit is organised into fourteen sections that follow the order you would implement them:

  • Foundation and Scope — 6 documents
  • Shared Responsibility — 6 documents
  • Asset Lifecycle and Exit — 5 documents
  • Virtualisation Security — 6 documents
  • Cloud Operations — 6 documents
  • Monitoring and Logging — 5 documents
  • Cloud Network Security — 4 documents
  • PII in Public Cloud — 10 documents
  • Cryptography — 2 documents
  • Resilience and Continuity — 2 documents
  • Personnel and Physical — 2 documents
  • Secure Development — 3 documents
  • Mapping and Traceability — 5 documents
  • Audit and Evidence — 5 documents

What the ISO 27017 Toolkit implements

ISO published a second edition, ISO/IEC 27017:2026, in July 2026, withdrawing the 2015 edition. It restructures the standard onto ISO/IEC 27002:2022, drops the old CLD numbering, and adds two cloud controls that did not exist before. The ISO 27017 Toolkit carries both editions, so it works whichever one your certification body audits against.

The 2026 cloud controls, and the documents that implement them:

  • 5.38 — shared responsibilities between cloud service customer and provider *(was CLD.6.3.1)*
  • 5.39 — responsibilities with other cloud partners: resellers, managed service providers, integrators and subcontractors *(new — no 2015 equivalent)*
  • 8.35 — segregation in virtual computing environments *(was CLD.9.5.1)*
  • 8.36 — detection and prevention of unauthorized use of cloud services, that is shadow cloud *(new — no 2015 equivalent)*

The four remaining 2015 controls — removal of customer assets, virtual machine hardening, administrator’s operational security and alignment of virtual and physical networks — are carried in the 2026 edition as cloud guidance on existing ISO/IEC 27002:2022 controls. Every document in the toolkit cites its 2026 reference and the 2015 identifier it replaces, and the applicability matrices and audit checklists carry a column for each.

A dedicated ISO 27017 Edition Transition Guide, included in the ISO 27017 Toolkit, sets out how to move an existing Statement of Applicability from 2015 references to 2026, which evidence carries across untouched, and which mappings are named in the source material versus inferred.

The ISO 27018 half of the ISO 27017 Toolkit implements the obligations that apply when you process personal information on a customer’s behalf: processing only on documented instruction, disclosure to authorities, sub-processor control, breach notification to the controller, data subject request support, and return or deletion at the end of the service.

List of Documentation Toolkit:

  1. ISO 27017 and ISO 27018 Scope and Applicability Statement.docx
  2. Cloud Service Role Determination Procedure.docx
  3. Cloud Security Extension Programme Charter.docx
  4. Cloud Services Inventory and Classification Register.xlsx
  5. Cloud Security Policy (ISO 27001 Extension).docx
  6. Toolkit Index and Deployment Guide.docx
  7. Shared Roles and Responsibilities Policy.docx
  8. Shared Responsibility Matrix Template.xlsx
  9. Cloud Service Agreement Security Schedule.docx
  10. Cloud Provider Security Capability Questionnaire.xlsx
  11. Cloud RACI and Authorities Matrix.xlsx
  12. Cloud Partner and Intermediary Responsibilities Procedure.docx
  13. Cloud Asset Management Procedure.docx
  14. Customer Asset Removal and Return Procedure.docx
  15. Cloud Exit and Portability Plan.docx
  16. Data Deletion and Sanitisation Certificate.docx
  17. Cloud Asset Register.xlsx
  18. Virtual Environment Segregation Policy.docx
  19. Multi-Tenancy Isolation Standard.docx
  20. Virtual Machine Hardening Standard.docx
  21. VM Baseline Configuration Checklist.xlsx
  22. Container and Orchestration Security Standard.docx
  23. Hypervisor Security Procedure.docx
  24. Cloud Administrator Operational Security Procedure.docx
  25. Privileged Access Management Standard – Cloud.docx
  26. Administrative Session Recording and Review Procedure.docx
  27. Cloud Change Management Procedure.docx
  28. Cloud Operations Runbook Template.docx
  29. Unauthorized Cloud Service Detection and Response Procedure.docx
  30. Cloud Monitoring and Logging Policy.docx
  31. Cloud Service Monitoring Specification.docx
  32. Log Retention and Protection Standard – Cloud.docx
  33. Cloud Incident Interface Procedure.docx
  34. Cloud Security Event Register.xlsx
  35. Virtual and Physical Network Alignment Standard.docx
  36. Cloud Network Segmentation Design.docx
  37. Cloud Network Security Configuration Checklist.xlsx
  38. Remote Access to Cloud Services Procedure.docx
  39. PII Processor Policy for Public Cloud.docx
  40. Purpose Limitation and Processing Instruction Procedure.docx
  41. PII Disclosure Notification Procedure.docx
  42. Sub-processor Management Procedure.docx
  43. Sub-processor Register.xlsx
  44. PII Return Transfer and Disposal Procedure.docx
  45. Data Subject Request Support Procedure.docx
  46. PII Breach Notification Procedure.docx
  47. Cloud PII Inventory and Data Flow Register.xlsx
  48. Confidentiality and Staff Access to PII Standard.docx
  49. Cloud Cryptography Policy.docx
  50. Cloud Key Management Procedure.docx
  51. Cloud Backup and Restoration Standard.docx
  52. Cloud Continuity and Resilience Plan.docx
  53. Cloud Personnel Security Standard.docx
  54. Cloud Facility Physical Security Standard.docx
  55. Cloud Vulnerability and Patch Management Procedure.docx
  56. Cloud Secure Development Standard.docx
  57. Data Masking and Leakage Prevention Standard.docx
  58. ISO 27017 Control Applicability Matrix.xlsx
  59. ISO 27018 Control Applicability Matrix.xlsx
  60. Crosswalk to ISO 27002:2022 and Toolkit Documents.xlsx
  61. Statement of Applicability Addendum – Cloud Extension.xlsx
  62. ISO 27017 Edition Transition Guide.docx
  63. Cloud Extension Audit Scope Supplement.docx
  64. ISO 27017 Audit Checklist.xlsx
  65. ISO 27018 Audit Checklist.xlsx
  66. Evidence Pack Index and Collection Guide.docx
  67. Management Review – Cloud Extension Input Pack.docx

ISO 27017 and ISO 27018 compliance

Because ISO/IEC 27017 and ISO/IEC 27018 are codes of practice rather than certifiable standards, conformity is demonstrated through your existing ISO/IEC 27001 certification. The ISO 27017 Toolkit includes a Statement of Applicability addendum, control applicability matrices for both standards, a crosswalk to ISO/IEC 27002:2022, and audit checklists — so the extension is visible to your auditor from the SoA rather than described separately. The documents are written in international English and are suitable for use in any jurisdiction. Our guide to ISO 27017 explains how the extension is scoped and audited, and what the second edition published in July 2026 changes.

Simply add your organisation’s name and logo, replace the bracketed placeholder values with your own detail, and implement the documented policies and procedures within your operational framework.

Frequently Asked Questions (FAQ)

What is the ISO 27017 Toolkit?

The ISO 27017 Toolkit is a set of 67 ready-to-edit documentation templates that extend an ISO/IEC 27001 information security management system to cover cloud services. It implements the seven ISO/IEC 27017 CLD controls and the ISO/IEC 27018 obligations for organisations processing personal information in a public cloud, and includes the mapping and audit evidence documents that go with them.

Can I get certified to ISO 27017 or ISO 27018?

No, and any toolkit that says otherwise is wrong. Both are codes of practice, not management system standards, so there is no separate certificate. They are audited as an extension of your ISO/IEC 27001 certification scope, and the toolkit is built for exactly that — the Audit Scope Supplement and the SoA addendum explain how the extension is presented to your certification body.

Do I need to already hold ISO 27001 certification?

You do not need the certificate in hand, but you do need an ISMS. Every document in this toolkit states that it supplements ISO/IEC 27001 and does not replace it, so it works alongside a system you are building as well as one you have certified. If you are starting from nothing, begin with the ISO 27001 Toolkit and add this one. Our guide to cloud security certification explains how the two fit together.

Is the ISO 27017 Toolkit for cloud providers or cloud customers?

Both, and each document says which. 37 documents apply to either role, 15 are provider-specific — including the entire ISO 27018 PII processor section — and 3 are customer-specific. The Cloud Service Role Determination Procedure helps you decide which role applies to each service before you start editing.

What is the difference between ISO 27017 and ISO 27018?

ISO/IEC 27017 is about cloud security generally: tenant segregation, virtual machine hardening, administrator operations, monitoring, network alignment and the division of responsibility between provider and customer. ISO/IEC 27018 is narrower — it applies when you act as a processor of personally identifiable information in a public cloud, and covers processing instructions, disclosure requests, sub-processors, breach notification and deletion.

Which editions of ISO 27017 and ISO 27018 does this toolkit follow?

Both. The ISO 27017 Toolkit carries each edition side by side: every document leads with the ISO/IEC 27017:2026 control reference and shows the ISO/IEC 27017:2015 identifier it replaces underneath; the applicability matrices, crosswalk and audit checklists carry a column for each. That matters because ISO 27017 is not a certifiable standard, so there is no transition deadline and certification bodies will move to the second edition at their own pace — you may need to answer to either numbering for some time. The ISO 27017 Edition Transition Guide covers the move, including which mappings are named in the published material and which are our reading, so you can check them against your own copy. The privacy documents follow the current third edition, ISO/IEC 27018:2025.

What formats are the documents in?

The ISO 27017 Toolkit ships 51 Microsoft Word documents and 16 Microsoft Excel workbooks. The Word documents carry a table of contents, document control fields and a consistent structure; the workbooks include instruction sheets, controlled dropdown lists and validation checks. Nothing is locked and no password is required.

How long does implementation take?

That depends on how much of your ISMS is already in place and how many cloud services are in scope. Most buyers work through the ISO 27017 Toolkit section by section rather than all at once. Organisations with a working ISO 27001 system typically complete the extension in six to twelve weeks; the Toolkit Index and Deployment Guide sets out the order to work through the sections and which documents depend on which.

Can I use this toolkit for more than one organisation?

The licence covers use within your own organisation. Consultants who need to deploy the ISO 27017 Toolkit across multiple client engagements should contact us for a consultancy licence.

Related cloud toolkits

If your cloud programme goes beyond ISO 27017 and ISO 27018, these packs sit alongside it:

Find More Products:

Documentation Toolkits

All Products

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.

Reviews

There are no reviews yet

Add a review
Currently, we are not accepting new reviews