By document type
| Category | Files |
|---|---|
| Manuals | 5 |
| Policies | 2 |
| Procedures & SOPs | 25 |
| Forms & Records | 25 |
| Checklists & Audit Tools | 10 |
| Registers, Logs & Matrices | 1 |
| Training & Awareness | 4 |
| Guides & Work Instructions | 3 |
Key documents
| Reference | Document | Format |
|---|---|---|
| SYS-01 | ISMS System Manual | Word |
| SCH-03 | Statement of Applicability | Word |
| CHK-01 | ISO 27017 Requirementswise Audit Checklist | Word |
| CHK-04 | Cloud Provider Customer Responsibility Checklist | Word |
| CHK-05 | Server and Virtual Machine Hardening Checklist | Word |
| F-IT-10 | Cloud Asset Identification and Classification Register | Word |
- Need the complete document list? Request it — same day
- Want to check the quality first? Preview free samples
Overview
ISO/IEC 27017 is a code of practice giving guidelines for information security controls that apply to the provision and use of cloud services. It builds on ISO/IEC 27002, adding cloud-specific guidance to many of its controls and introducing further controls unique to the cloud. It addresses providers and customers alike, with the architects, auditors and procurement teams who must settle where one party's obligations end and the other's begin. It is not a standalone certifiable system: it is used alongside an ISO/IEC 27001 ISMS, and conformity is typically assessed as an extension of that certification, its scope explicitly naming the cloud controls.
The subject matter is practical: dividing security responsibilities between provider and customer, removal and return of assets on contract termination, segregation within virtualised environments, the operational security of cloud administrators, monitoring of cloud services, and alignment of the virtual network environment with the physical one. The documentation carries the ISMS spine those controls attach to, plus cloud security and acceptable use policies, shared responsibility guidance and a cloud asset register. ISO/IEC 27018 commonly accompanies it where public clouds hold personally identifiable information.
What this system covers
- Shared responsibility: allocating each control and naming who evidences it
- Virtualisation and segregation: hardening virtual machines, separating tenant environments
- Cloud administrator operational security: privileged operations, monitoring and log review
- Cloud asset identification and classification: bringing cloud instances into the register
- Contract termination: return of assets, media disposal and withdrawal of access
- Cloud vendor assessment and acceptable use: supplier evaluation and rules for users
- Risk assessment, incident investigation and continuity testing in the underlying ISMS
- Personnel security across the joiner, mover and leaver cycle, with role-based training
Who it's for
Intended for cloud providers answering customer due diligence, and for organisations whose critical workloads now sit on third-party platforms while their ISO/IEC 27001 scope has yet to catch up. The trigger is usually a client audit or a tender clause; the outcome is a control set with every cloud control assigned to a named party.
Everything you get
Every toolkit gives you a full set of working documents for your standard, ready to edit and use.
Native Microsoft files. Add your logo and adapt every document to how you work.
Your full toolkit arrives as a ZIP the moment payment clears.
One purchase covers everyone in your organisation. No per-seat fees.
Built by people who run real audits, so the content matches what assessors check.
One payment, perpetual licence for your organisation. No subscriptions, no renewals.
Full refund if your files are faulty, incomplete or not as described and we can't put it right
Frequently asked questions
What exactly do I receive?
A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.
Are the documents really editable?
Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.
Does this certify my organisation?
No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.
How is it delivered?
Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.
Do I get updates?
Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.
What is your refund policy?
These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.
Cannot find your standard?
Tell us which scheme you work to. We will point you to the right toolkit.




