Description
About the ISO 27017 Toolkit
The ISO 27017 Toolkit gives you the cloud half of an information security management system. ISO/IEC 27017 and ISO/IEC 27018 are the two codes of practice that take an ISMS into the cloud. Neither is certified on its own — both are audited as an extension of ISO/IEC 27001 — and that is exactly how this toolkit is built. It supplies the cloud-specific documents an ISMS does not already have, states in each one how it supplements the ISMS rather than replacing it, and gives you the mapping evidence an auditor asks for when your Statement of Applicability claims cloud coverage.
The ISO 27017 Toolkit contains 67 templates: 51 Word documents and 16 Excel registers, matrices and checklists. Every document is written to the control it implements, cross-referenced to the others, and editable in Microsoft Office.
What is included in the ISO 27017 Toolkit?
- 67 documentation templates — the ISO 27017 Toolkit covers the cloud controls of both editions of ISO/IEC 27017, the 2026 second edition and the withdrawn 2015 edition, and the full ISO 27018 privacy control set with policies, procedures, standards, registers, matrices and checklists
- All files in Microsoft Office format (.docx, .xlsx) — fully editable, with every organisation-specific value marked as a placeholder
- Instant download immediately after purchase
The 2026 edition carries cloud guidance across the whole ISO/IEC 27002:2022 control set, not just a handful of cloud-only controls, and the ISO 27017 Toolkit follows it there: cryptography and key management, backup and restoration, continuity and resilience, personnel security, physical security of cloud facilities, vulnerability and patch management, secure development, and data masking and leakage prevention each have their own documents rather than a passing mention.
Built for both sides of the cloud contract
Cloud security documentation fails when it does not say who does what. The ISO 27017 Toolkit is explicit about it: every document is marked as applying to the cloud service provider, the cloud service customer, or both, and the Cloud Service Role Determination Procedure settles which role you are in before anything else is written.
- 48 documents apply to both provider and customer
- 16 documents apply to cloud service providers, including the whole ISO 27018 PII processor section
- 3 documents apply specifically to cloud service customers
ISO 27017 Toolkit structure
The ISO 27017 Toolkit is organised into fourteen sections that follow the order you would implement them:
- Foundation and Scope — 6 documents
- Shared Responsibility — 6 documents
- Asset Lifecycle and Exit — 5 documents
- Virtualisation Security — 6 documents
- Cloud Operations — 6 documents
- Monitoring and Logging — 5 documents
- Cloud Network Security — 4 documents
- PII in Public Cloud — 10 documents
- Cryptography — 2 documents
- Resilience and Continuity — 2 documents
- Personnel and Physical — 2 documents
- Secure Development — 3 documents
- Mapping and Traceability — 5 documents
- Audit and Evidence — 5 documents
What the ISO 27017 Toolkit implements
ISO published a second edition, ISO/IEC 27017:2026, in July 2026, withdrawing the 2015 edition. It restructures the standard onto ISO/IEC 27002:2022, drops the old CLD numbering, and adds two cloud controls that did not exist before. The ISO 27017 Toolkit carries both editions, so it works whichever one your certification body audits against.
The 2026 cloud controls, and the documents that implement them:
- 5.38 — shared responsibilities between cloud service customer and provider *(was CLD.6.3.1)*
- 5.39 — responsibilities with other cloud partners: resellers, managed service providers, integrators and subcontractors *(new — no 2015 equivalent)*
- 8.35 — segregation in virtual computing environments *(was CLD.9.5.1)*
- 8.36 — detection and prevention of unauthorized use of cloud services, that is shadow cloud *(new — no 2015 equivalent)*
The four remaining 2015 controls — removal of customer assets, virtual machine hardening, administrator’s operational security and alignment of virtual and physical networks — are carried in the 2026 edition as cloud guidance on existing ISO/IEC 27002:2022 controls. Every document in the toolkit cites its 2026 reference and the 2015 identifier it replaces, and the applicability matrices and audit checklists carry a column for each.
A dedicated ISO 27017 Edition Transition Guide, included in the ISO 27017 Toolkit, sets out how to move an existing Statement of Applicability from 2015 references to 2026, which evidence carries across untouched, and which mappings are named in the source material versus inferred.
The ISO 27018 half of the ISO 27017 Toolkit implements the obligations that apply when you process personal information on a customer’s behalf: processing only on documented instruction, disclosure to authorities, sub-processor control, breach notification to the controller, data subject request support, and return or deletion at the end of the service.
List of Documentation Toolkit:
- ISO 27017 and ISO 27018 Scope and Applicability Statement.docx
- Cloud Service Role Determination Procedure.docx
- Cloud Security Extension Programme Charter.docx
- Cloud Services Inventory and Classification Register.xlsx
- Cloud Security Policy (ISO 27001 Extension).docx
- Toolkit Index and Deployment Guide.docx
- Shared Roles and Responsibilities Policy.docx
- Shared Responsibility Matrix Template.xlsx
- Cloud Service Agreement Security Schedule.docx
- Cloud Provider Security Capability Questionnaire.xlsx
- Cloud RACI and Authorities Matrix.xlsx
- Cloud Partner and Intermediary Responsibilities Procedure.docx
- Cloud Asset Management Procedure.docx
- Customer Asset Removal and Return Procedure.docx
- Cloud Exit and Portability Plan.docx
- Data Deletion and Sanitisation Certificate.docx
- Cloud Asset Register.xlsx
- Virtual Environment Segregation Policy.docx
- Multi-Tenancy Isolation Standard.docx
- Virtual Machine Hardening Standard.docx
- VM Baseline Configuration Checklist.xlsx
- Container and Orchestration Security Standard.docx
- Hypervisor Security Procedure.docx
- Cloud Administrator Operational Security Procedure.docx
- Privileged Access Management Standard – Cloud.docx
- Administrative Session Recording and Review Procedure.docx
- Cloud Change Management Procedure.docx
- Cloud Operations Runbook Template.docx
- Unauthorized Cloud Service Detection and Response Procedure.docx
- Cloud Monitoring and Logging Policy.docx
- Cloud Service Monitoring Specification.docx
- Log Retention and Protection Standard – Cloud.docx
- Cloud Incident Interface Procedure.docx
- Cloud Security Event Register.xlsx
- Virtual and Physical Network Alignment Standard.docx
- Cloud Network Segmentation Design.docx
- Cloud Network Security Configuration Checklist.xlsx
- Remote Access to Cloud Services Procedure.docx
- PII Processor Policy for Public Cloud.docx
- Purpose Limitation and Processing Instruction Procedure.docx
- PII Disclosure Notification Procedure.docx
- Sub-processor Management Procedure.docx
- Sub-processor Register.xlsx
- PII Return Transfer and Disposal Procedure.docx
- Data Subject Request Support Procedure.docx
- PII Breach Notification Procedure.docx
- Cloud PII Inventory and Data Flow Register.xlsx
- Confidentiality and Staff Access to PII Standard.docx
- Cloud Cryptography Policy.docx
- Cloud Key Management Procedure.docx
- Cloud Backup and Restoration Standard.docx
- Cloud Continuity and Resilience Plan.docx
- Cloud Personnel Security Standard.docx
- Cloud Facility Physical Security Standard.docx
- Cloud Vulnerability and Patch Management Procedure.docx
- Cloud Secure Development Standard.docx
- Data Masking and Leakage Prevention Standard.docx
- ISO 27017 Control Applicability Matrix.xlsx
- ISO 27018 Control Applicability Matrix.xlsx
- Crosswalk to ISO 27002:2022 and Toolkit Documents.xlsx
- Statement of Applicability Addendum – Cloud Extension.xlsx
- ISO 27017 Edition Transition Guide.docx
- Cloud Extension Audit Scope Supplement.docx
- ISO 27017 Audit Checklist.xlsx
- ISO 27018 Audit Checklist.xlsx
- Evidence Pack Index and Collection Guide.docx
- Management Review – Cloud Extension Input Pack.docx
ISO 27017 and ISO 27018 compliance
Because ISO/IEC 27017 and ISO/IEC 27018 are codes of practice rather than certifiable standards, conformity is demonstrated through your existing ISO/IEC 27001 certification. The ISO 27017 Toolkit includes a Statement of Applicability addendum, control applicability matrices for both standards, a crosswalk to ISO/IEC 27002:2022, and audit checklists — so the extension is visible to your auditor from the SoA rather than described separately. The documents are written in international English and are suitable for use in any jurisdiction. Our guide to ISO 27017 explains how the extension is scoped and audited, and what the second edition published in July 2026 changes.
Simply add your organisation’s name and logo, replace the bracketed placeholder values with your own detail, and implement the documented policies and procedures within your operational framework.
Frequently Asked Questions (FAQ)
What is the ISO 27017 Toolkit?
The ISO 27017 Toolkit is a set of 67 ready-to-edit documentation templates that extend an ISO/IEC 27001 information security management system to cover cloud services. It implements the seven ISO/IEC 27017 CLD controls and the ISO/IEC 27018 obligations for organisations processing personal information in a public cloud, and includes the mapping and audit evidence documents that go with them.
Can I get certified to ISO 27017 or ISO 27018?
No, and any toolkit that says otherwise is wrong. Both are codes of practice, not management system standards, so there is no separate certificate. They are audited as an extension of your ISO/IEC 27001 certification scope, and the toolkit is built for exactly that — the Audit Scope Supplement and the SoA addendum explain how the extension is presented to your certification body.
Do I need to already hold ISO 27001 certification?
You do not need the certificate in hand, but you do need an ISMS. Every document in this toolkit states that it supplements ISO/IEC 27001 and does not replace it, so it works alongside a system you are building as well as one you have certified. If you are starting from nothing, begin with the ISO 27001 Toolkit and add this one. Our guide to cloud security certification explains how the two fit together.
Is the ISO 27017 Toolkit for cloud providers or cloud customers?
Both, and each document says which. 37 documents apply to either role, 15 are provider-specific — including the entire ISO 27018 PII processor section — and 3 are customer-specific. The Cloud Service Role Determination Procedure helps you decide which role applies to each service before you start editing.
What is the difference between ISO 27017 and ISO 27018?
ISO/IEC 27017 is about cloud security generally: tenant segregation, virtual machine hardening, administrator operations, monitoring, network alignment and the division of responsibility between provider and customer. ISO/IEC 27018 is narrower — it applies when you act as a processor of personally identifiable information in a public cloud, and covers processing instructions, disclosure requests, sub-processors, breach notification and deletion.
Which editions of ISO 27017 and ISO 27018 does this toolkit follow?
Both. The ISO 27017 Toolkit carries each edition side by side: every document leads with the ISO/IEC 27017:2026 control reference and shows the ISO/IEC 27017:2015 identifier it replaces underneath; the applicability matrices, crosswalk and audit checklists carry a column for each. That matters because ISO 27017 is not a certifiable standard, so there is no transition deadline and certification bodies will move to the second edition at their own pace — you may need to answer to either numbering for some time. The ISO 27017 Edition Transition Guide covers the move, including which mappings are named in the published material and which are our reading, so you can check them against your own copy. The privacy documents follow the current third edition, ISO/IEC 27018:2025.
What formats are the documents in?
The ISO 27017 Toolkit ships 51 Microsoft Word documents and 16 Microsoft Excel workbooks. The Word documents carry a table of contents, document control fields and a consistent structure; the workbooks include instruction sheets, controlled dropdown lists and validation checks. Nothing is locked and no password is required.
How long does implementation take?
That depends on how much of your ISMS is already in place and how many cloud services are in scope. Most buyers work through the ISO 27017 Toolkit section by section rather than all at once. Organisations with a working ISO 27001 system typically complete the extension in six to twelve weeks; the Toolkit Index and Deployment Guide sets out the order to work through the sections and which documents depend on which.
Can I use this toolkit for more than one organisation?
The licence covers use within your own organisation. Consultants who need to deploy the ISO 27017 Toolkit across multiple client engagements should contact us for a consultancy licence.
Related cloud toolkits
If your cloud programme goes beyond ISO 27017 and ISO 27018, these packs sit alongside it:
- CSA STAR Cloud Security Toolkit — for the Cloud Controls Matrix and STAR registry submission
- BSI C5:2026 Cloud Toolkit — for German market C5 attestation
- ISO 27701 Toolkit — for a full privacy information management system
ISO 22000 Toolkit - Comprehensive 30 Templates
Comprehensive ISO 17025 Toolkit – 70 Laboratory Templates
ISO 27001 Assessment Tool – Premium Quality 




































Reviews
There are no reviews yet