Skip to product information
1 of 1

Information Security, Risk & Business ContinuityAGS-06-006

ISO-27017 Management System

ISO-27017 Management System

Cloud security stops being a shared assumption and becomes a shared responsibility that is written down, allocated and testable.

Regular price $790USD
Regular price USD Sale price $790USD
Taxes included.
Secure checkout American Express Apple Pay Diners ClubDiscoverGoogle Pay JCBMastercard Visa

Written by practising auditors with 20+ years in the field.

Preview free samples

View full details
75 ready-to-use documents 75 Word · 1 interactive HTML · plus the AGS license · 1 support file

By document type

Total 75
CategoryFiles
Manuals5
Policies2
Procedures & SOPs25
Forms & Records25
Checklists & Audit Tools10
Registers, Logs & Matrices1
Training & Awareness4
Guides & Work Instructions3

Key documents

ReferenceDocumentFormat
SYS-01ISMS System Manual Word
SCH-03Statement of Applicability Word
CHK-01ISO 27017 Requirementswise Audit Checklist Word
CHK-04Cloud Provider Customer Responsibility Checklist Word
CHK-05Server and Virtual Machine Hardening Checklist Word
F-IT-10Cloud Asset Identification and Classification Register Word

Overview

ISO/IEC 27017 is a code of practice giving guidelines for information security controls that apply to the provision and use of cloud services. It builds on ISO/IEC 27002, adding cloud-specific guidance to many of its controls and introducing further controls unique to the cloud. It addresses providers and customers alike, with the architects, auditors and procurement teams who must settle where one party's obligations end and the other's begin. It is not a standalone certifiable system: it is used alongside an ISO/IEC 27001 ISMS, and conformity is typically assessed as an extension of that certification, its scope explicitly naming the cloud controls.

The subject matter is practical: dividing security responsibilities between provider and customer, removal and return of assets on contract termination, segregation within virtualised environments, the operational security of cloud administrators, monitoring of cloud services, and alignment of the virtual network environment with the physical one. The documentation carries the ISMS spine those controls attach to, plus cloud security and acceptable use policies, shared responsibility guidance and a cloud asset register. ISO/IEC 27018 commonly accompanies it where public clouds hold personally identifiable information.

What this system covers

  • Shared responsibility: allocating each control and naming who evidences it
  • Virtualisation and segregation: hardening virtual machines, separating tenant environments
  • Cloud administrator operational security: privileged operations, monitoring and log review
  • Cloud asset identification and classification: bringing cloud instances into the register
  • Contract termination: return of assets, media disposal and withdrawal of access
  • Cloud vendor assessment and acceptable use: supplier evaluation and rules for users
  • Risk assessment, incident investigation and continuity testing in the underlying ISMS
  • Personnel security across the joiner, mover and leaver cycle, with role-based training

Who it's for

Intended for cloud providers answering customer due diligence, and for organisations whose critical workloads now sit on third-party platforms while their ISO/IEC 27001 scope has yet to catch up. The trigger is usually a client audit or a tender clause; the outcome is a control set with every cloud control assigned to a named party.

Everything you get

Every toolkit gives you a full set of working documents for your standard, ready to edit and use.

Editable Word and Excel

Native Microsoft files. Add your logo and adapt every document to how you work.

Instant download

Your full toolkit arrives as a ZIP the moment payment clears.

Unlimited users

One purchase covers everyone in your organisation. No per-seat fees.

Written by auditors

Built by people who run real audits, so the content matches what assessors check.

Yours to keep

One payment, perpetual licence for your organisation. No subscriptions, no renewals.

Refund guarantee

Full refund if your files are faulty, incomplete or not as described and we can't put it right

Frequently asked questions

What exactly do I receive?

A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.

Are the documents really editable?

Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.

Does this certify my organisation?

No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.

How is it delivered?

Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.

Do I get updates?

Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.

What is your refund policy?

These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.

Cannot find your standard?

Tell us which scheme you work to. We will point you to the right toolkit.

Request a toolkit