INTERNATIONAL STANDARD ISO/IEC 27017 First edition 2015-12-15 Information technology Security techniques Code of practice for information security controls based on ISO/IEC 27002 for cloud services Technologies de I'information -Techniques de sécurité -Code de pratique pour les contnδles de sécurité de I'information fondés sur I'ISO/IEC 27002 pour les services du nuage Copyrigh! Lnternalional Orga而zalio(l阳Slan由rdizalion Provided by IHS under license wilh 1$0 No re阳oduC1ionOr闸阳αk;咱间 rmilledwithou lli曲n回"αnlHS壁 、 .FL· -/gaE t? / T·· \ 一Reference number ISO/IEC 27017:2015(E) " .. , ..…… . " . 。ISO/IEC2015 Nollor Resale , 1212512015四36:40MST ISO/IEC 27017:2015(E) COPYRIGHT PROTECTED DOCUMENT 。ISO/lEC2015 AII rights reserved. Unless otherwise specili ed, no part 01 this publication may be reproduced or utilized otherwise in any lorm or by any means , electronic or mechanical , including photocopying , or posting on the internet or an intranet, without prior written permission Permission can be requested Irom either ISO at the address below or ISO's member body in the country 01 the requeste r. ISO copyright office Case postale 56. CH- 1211 Geneva 20 Te l. +41227490111 Fax + 41227490947 E-mail Web Published in Switzerland " .. ",..." ,.",,,....,,.,,. Copyrigh! Lnternalional Orga由刷刷阳 Slan由rdizalion Provided by IHS uoder license wilh 1 $0 No re阳oduC1ionOr闸阳αk;咱间 rmilledwithoulli 曲n回"αnlHS。ISOIIEC2015 -AII rights reserved Nollor Resale, 12125120 15四36:40MST ISO/IEC 27017:2015(E) Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC pa时icipatein the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interes t. Other international organizations , governmental and non-governmental , in liaison with ISO and IEC , also take part in the work. In the field of information technology , ISO and IEC have established a joint technical committee , ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives , Part 2. The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. I SO and IEC shall not be held responsible for identifying any or all such patent rights 1·· ··· ····· ISO/IEC 27017 was prepared by Joint Technical Committee I SO/IEC JTC 1 , Information technology , Subcommittee SC 27 , IT Security techniques , in collaboration with ITU-T. The identical text is published as ITU-T. X.1631 (07/2015). 111 Nollor Resale, 1212512015四36:40MST 臼pyrigh!Lnternaliona l由2432ii几2JA751 ,onAl|rlghtS 『eserved Provided by IHS under license wilh 1 $0 No re阳oduC1ionor闸阳αki咱间 rmilledwithoulli 曲n回IrαnlHSCopyrigh! Lnternalional Orga而zation阳Slan由rdization Provided by IHS under license wilh 1 $0 No re阳oduC1ionor闸阳αk;咱间 rmilledwithoulli 曲n回"αnlHS Nollor Resale, 1212512015四36:40MST -International Telecomn 、unication Union ITU-T TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU X.1631 SERIES X: DATA NETWORKS , OPEN SYSTEM COMMUNICATIONS AND SECURITY Cloud computing security -Cloud computing security design Information technology -Security techniques -Code of practice for information security controls based on ISO/IEC 27002 for cloud servlces Recommendation ITU-T X.1631 .n'l:.lI"n…..",.1 T.I…"'1ft ...阴ICJ.....oII UnlGn Copyri

