framework to address unique cloud risks such as multi-tenancy and shared responsibility. Linford & Company LLP Accessing the Standard Official ISO standards are copyright-protected products and are generally not available for legal "free download". iTeh Standards ISO/IEC 27017 - Compliance - Google Cloud
| Method | Details | |--------|---------| | | Some countries (e.g., via ANSI in the US, BSI in the UK) allow free read-only access at physical locations | | University/library access | Many academic institutions subscribe to ISO standards via Perinorm, TechStreet, or IHS | | Official ISO preview | ISO.org offers the foreword, introduction, and scope of 27017 for free | | Public summaries | Cloud Security Alliance (CSA) publishes free guidance mapping to 27017 |
ISO standards are commercial publications protected by copyright laws (ISO’s own copyright policy). Unauthorized distribution of PDFs is illegal and can result in penalties. Legitimate free downloads of the full standard do not exist.
It was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) to address the shared responsibility model between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs).
for cloud – e.g., how to handle asset management, access control, and cryptography in a multi-tenant environment.