• BS ISO/IEC 27017:2015

    Withdrawn A Withdrawn Standard is one, which is removed from sale, and its unique number can no longer be used. The Standard can be withdrawn and not replaced, or it can be withdrawn and replaced by a Standard with a different number.

    Information technology. Security techniques. Code of practice for information security controls based on ISO/IEC 27002 for cloud services

    Available format(s):  Hardcopy, PDF

    Withdrawn date:  02-02-2021

    Language(s):  English

    Published date:  31-12-2015

    Publisher:  British Standards Institution

    Add To Cart

    Table of Contents - (Show below) - (Hide below)

    1 Scope
    2 Normative references
    3 Definitions and abbreviations
    4 Cloud sector-specific concepts
    5 Information security policies
    6 Organization of information security
    7 Human resource security
    8 Asset management
    9 Access control
    10 Cryptography
    11 Physical and environmental
    12 Operations security
    13 Communications security
    14 System acquisition, development and maintenance
    15 Supplier relationships
    16 Information security incident management
    17 Information security aspects of business continuity
       management
    18 Compliance
    Annex A - Cloud service extended control set
    Annex B - References on information security risk related to
              cloud computing
    Bibliography

    Abstract - (Show below) - (Hide below)

    Provides guidelines for information security controls applicable to the provision and use of cloud services by providing: - additional implementation guidance for relevant controls specified in ISO/IEC 27002; and - additional controls with implementation guidance that specifically relate to cloud services.

    General Product Information - (Show below) - (Hide below)

    Committee IST/33
    Development Note Supersedes 15/30259619 DC. (12/2015)
    Document Type Standard
    Publisher British Standards Institution
    Status Withdrawn
    Supersedes

    Standards Referenced By This Book - (Show below) - (Hide below)

    17/30354571 DC : 0 BS 7799-3 - INFORMATION SECURITY MANAGEMENT SYSTEMS - PART 3: GUIDELINES FOR INFORMATION SECURITY RISK MANAGEMENT
    BS 7799-3:2017 Information security management systems Guidelines for information security risk management
    BS 8593:2017 Code of practice for the deployment and use of Body Worn Video (BWV)
    17/30345717 DC : 0 BS 8593 - CODE OF PRACTICE FOR THE DEPLOYMENT AND USE OF BODY WORN VIDEO (BWV)

    Standards Referencing This Book - (Show below) - (Hide below)

    ISO/IEC 27036-4:2016 Information technology Security techniques Information security for supplier relationships Part 4: Guidelines for security of cloud services
    ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems — Requirements
    ISO 31000:2009 Risk management Principles and guidelines
    ISO/IEC 27002:2013 Information technology Security techniques Code of practice for information security controls
    ISO/IEC 27018:2014 Information technology Security techniques Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
    ISO 19440:2007 Enterprise integration Constructs for enterprise modelling
    ISO/IEC 27036-3:2013 Information technology — Security techniques — Information security for supplier relationships — Part 3: Guidelines for information and communication technology supply chain security
    ISO/IEC 27005:2011 Information technology Security techniques Information security risk management
    ISO/IEC 17203:2017 Information technology — Open Virtualization Format (OVF) specification
    ISO/IEC 27036-1:2014 Information technology Security techniques Information security for supplier relationships Part 1: Overview and concepts
    ISO/IEC 27036-2:2014 Information technology Security techniques Information security for supplier relationships Part 2: Requirements
    ISO/IEC 27040:2015 Information technology — Security techniques — Storage security
    ISO/IEC 27000:2016 Information technology Security techniques Information security management systems Overview and vocabulary
    ISO/IEC 17789:2014 Information technology — Cloud computing — Reference architecture
    ISO/IEC 17788:2014 Information technology — Cloud computing — Overview and vocabulary
    • Access your standards online with a subscription

      Features

      • Simple online access to standards, technical information and regulations
      • Critical updates of standards and customisable alerts and notifications
      • Multi - user online standards collection: secure, flexibile and cost effective