ISO 27017 Singapore — Cloud Security Certification (ISO 27001 Extension)
ISO/IEC 27017 is the international code of practice for cloud security controls — the standard Singapore SaaS companies, managed service providers and cloud-hosted businesses present when an enterprise buyer asks “how do you secure the cloud specifically?”. It is not a standalone certificate: it certifies as an extension of your ISO 27001 ISMS, audited by the same certification body, and can often be added at your next surveillance audit. Sage Shield prepares the cloud-control extension end to end — shared-responsibility mapping, the seven additional CLD controls, evidence and audit coordination. We are an independent consultancy — we prepare your organisation; a SAC-accredited certification body certifies. We take no referral fees and do not lock you to any single auditor.
What is ISO 27017?
ISO/IEC 27017 (Code of practice for information security controls based on ISO/IEC 27002 for cloud services) does two things. First, it gives cloud-specific implementation guidance for the familiar ISO 27002 controls — what access control, cryptography, operations security and incident management actually mean when your infrastructure is AWS, Azure, Google Cloud or a SaaS stack rather than your own server room. Second, it adds seven controls that exist only in the cloud context — covering shared responsibilities, virtual machine hardening, segregation between tenants and monitoring of cloud services.
Uniquely, ISO 27017 addresses both sides of the cloud relationship: the cloud service provider (you sell a SaaS product or managed cloud service) and the cloud service customer (you run your business on cloud services and must govern them). Most Singapore SMEs are both at once.
ISO 27017 vs ISO 27018 vs ISO 27001 — which do you need?
| Standard | What it covers | Certifiable? | Best when… |
|---|---|---|---|
| ISO 27001 | The full Information Security Management System (ISMS) — risk assessment, Annex A controls, management review | Yes — the base certificate | You need the internationally recognised information-security certificate. Everything else builds on this. |
| ISO 27017 | Cloud security controls — for cloud providers and cloud customers | As an extension of ISO 27001 scope | Buyers ask specifically about cloud security, you sell SaaS/managed cloud, or your whole stack is cloud-hosted |
| ISO 27018 | Protection of personal data (PII) processed in public clouds | As an extension of ISO 27001 scope | Your cloud service processes customers’ personal data — see our ISO 27018 Singapore page |
Many cloud businesses add both 27017 and 27018 in the same audit cycle: 27017 answers the security question, 27018 answers the privacy question, and together they cover the two most common sections of an enterprise vendor-assessment questionnaire.
Who needs ISO 27017 certification in Singapore?
- SaaS companies — enterprise and MNC buyers increasingly ask for cloud-specific assurance on top of ISO 27001, especially in fintech, healthtech and HR-tech vendor assessments.
- Managed service providers and cloud resellers — you administer other companies’ cloud environments; 27017’s administrator and monitoring controls map directly to what your clients’ auditors ask about you.
- Companies hosting regulated workloads in the cloud — financial services outsourcing (MAS OSPAR ecosystems), government-adjacent suppliers and critical-vendor programmes reference cloud-control frameworks.
- Existing ISO 27001 holders being asked “but what about cloud?” — the extension is the lowest-cost way to answer, because your ISMS, internal audit and certification body relationship already exist.
How ISO 27017 certifies — an extension of ISO 27001, not a new audit programme
ISO 27017 is a code of practice, not a management-system standard, so a certification body does not issue a standalone “ISO 27017 certificate” the way it does for ISO 27001. Instead, the cloud controls are added to the scope of your ISO 27001 certification: your Statement of Applicability is extended with the cloud-specific guidance and the seven CLD controls, and the certification body audits them alongside your ISMS, then reflects ISO 27017 on your certificate or issues a statement of conformity.
The practical consequences are why the extension is attractive:
- Already ISO 27001 certified? The extension can typically be assessed at your next surveillance audit with a modest scope extension — no separate Stage 1/Stage 2 cycle.
- Going for ISO 27001 now? Building 27017 into the initial certification adds cloud controls to the same audit — one project, one audit, both outcomes.
- One management system. No new policy stack: the cloud controls plug into the risk assessment, SoA, internal audit and management review you already run.
The seven additional ISO 27017 cloud controls
Beyond cloud-specific guidance on the standard ISO 27002 control set, ISO 27017 introduces seven controls of its own:
- CLD.6.3.1 — Shared roles and responsibilities: a documented split of security responsibilities between you and your cloud provider (the shared-responsibility matrix auditors and enterprise customers now expect to see).
- CLD.8.1.5 — Removal of cloud service customer assets: assurance that customer data and assets are returned or removed when the service ends.
- CLD.9.5.1 — Segregation in virtual computing environments: tenant isolation — your data and environments are separated from other customers’.
- CLD.9.5.2 — Virtual machine hardening: baseline configuration standards for VMs and cloud workloads.
- CLD.12.1.5 — Administrator’s operational security: controls over privileged cloud administration — the highest-risk activity in any cloud estate.
- CLD.12.4.5 — Monitoring of cloud services: the customer’s ability to monitor what happens in the cloud service they consume.
- CLD.13.1.4 — Alignment of virtual and physical network security: consistent security management across virtual networks and the physical networks beneath them.
Implementation roadmap — adding ISO 27017 to your ISMS
Stage 1 — Cloud scoping and gap assessment
Inventory every cloud service in scope (IaaS, PaaS, SaaS — both what you consume and what you provide), map each against the 27017 guidance and the seven CLD controls, and identify the gaps.
Stage 2 — Shared-responsibility mapping
Build the responsibility matrix per cloud service: what AWS/Azure/Google or your upstream provider covers, what you cover, and what your customers must cover. This single artefact resolves most of CLD.6.3.1 and drives the rest of the work.
Stage 3 — Extend the Statement of Applicability and documentation
Extend your SoA with the cloud-specific guidance and CLD controls, update the risk assessment for cloud-specific risks (tenant segregation, provider lock-in, admin compromise, region/data-residency), and refresh the affected policies and procedures.
Stage 4 — Implement and evidence the cloud controls
Harden VM/workload baselines, tighten privileged-access management for cloud consoles, configure monitoring and logging, and document asset-return/removal arrangements in customer agreements.
Stage 5 — Internal audit and management review
Audit the extended scope internally, feed results into management review — the same cycle your ISMS already runs, now covering the cloud controls.
Stage 6 — Certification body audit
The extension is assessed at your surveillance audit (for existing certificate holders) or within the Stage 2 audit (for new certifications). We coordinate scope, dates and evidence with your certification body.
How Sage Shield delivers ISO 27017 consultancy
We run the extension as a compact project on top of your ISMS: cloud service inventory and gap assessment, the shared-responsibility matrix, SoA and risk-assessment extension, control implementation support, internal audit of the extended scope, and coordination with your certification body through to the audit. Where clients also process personal data in the cloud, we typically deliver ISO 27018 in the same engagement — the evidence overlaps heavily and the audit is combined. As with all our work, we prepare; a SAC-accredited certification body certifies.
ISO 27017 Singapore — frequently asked questions
Can I get ISO 27017 certified without ISO 27001?
No. ISO 27017 is a code of practice and is certified as an extension of an ISO 27001 ISMS. If you don’t yet hold ISO 27001, the efficient route is a single project that builds the ISMS with the cloud controls included, so one Stage 1/Stage 2 audit cycle delivers both.
Can ISO 27017 be added at my surveillance audit?
Usually yes. For existing ISO 27001 certificate holders, most certification bodies assess the 27017 extension during a scheduled surveillance audit with a scope-extension arrangement, which is significantly cheaper and faster than a new certification cycle. We confirm the mechanics with your specific certification body before the project starts.
How long does adding ISO 27017 take?
For an organisation with a healthy ISO 27001 ISMS, the extension is typically a matter of a few months’ preparation aligned to your next surveillance audit date — the work is the cloud inventory, responsibility matrix, SoA extension and evidence, not a new management system.
What is the difference between ISO 27017 and ISO 27018?
ISO 27017 covers cloud security controls for cloud providers and customers; ISO 27018 covers protection of personal data (PII) processed in public clouds. 27017 answers the security section of a vendor assessment; 27018 answers the privacy section. Cloud businesses that process personal data commonly certify both together.
Does ISO 27017 apply if we only use cloud services rather than provide them?
Yes. ISO 27017 is written for both cloud service providers and cloud service customers — the guidance tells the customer side what to demand and verify from providers, and how to govern its own cloud use. A company running entirely on AWS or Microsoft 365 has a real 27017 scope even if it sells nothing cloud-based.
Does Sage Shield issue the certificate?
No — Sage Shield is an independent consultancy. We prepare your cloud-control extension and coordinate the audit; the certificate (with the extended scope) is issued by a SAC-accredited or otherwise IAF-recognised certification body of your choice. We take no referral fees.
What does ISO 27017 consultancy cost in Singapore?
It depends on your cloud estate’s breadth and whether you’re extending an existing certificate or building it into a new ISO 27001 project. As an extension at surveillance, it is one of the most cost-efficient certifications available — the ISMS, audit relationship and most documentation already exist. Contact us for a scoped proposal.
Get started with ISO 27017
Speak to an independent consultant about extending your ISO 27001 certificate with cloud security controls — or building both into one certification project.
- Phone: +65 8332 8220
- Address: 261 Ponggol Seventeenth Avenue, Singapore 829711
- WhatsApp: wa.me/6593859592
Related Sage Shield resources
- ISO 27001 Certification Singapore — ISMS Consultancy
- ISO 27018 Singapore — PII Protection in the Cloud
- SOC 2 Compliance Singapore
- Cyber Trust Mark Singapore
- PDPA Compliance Singapore
Processing personal data in the cloud?
Pair ISO 27017 with ISO 27018 — PII protection in public clouds — one combined audit covers both the security and the privacy sections of your customers’ vendor assessments.
Related: ISO 27017 vs ISO 27018 — which cloud extension do you need?
