Skip to Content

Security & Compliance

Lynx Compliance - ISO/IEC 27017 + 27018 (Cloud)

The two cloud extensions to ISO 27002 in one add-on - 27017 cloud services security including the seven CLD controls, and 27018 protection of personal data in public cloud.

lynx_compliance_iso_cloud · v19.0.1.0.0 · Add-on Beta

What this solves

Lynx Compliance - ISO/IEC 27017 + 27018 (Cloud)

Two frameworks, one add-on, because they are bought and audited together. An organisation running a public cloud service that handles personal data needs both, and holding one without the other leaves a gap an auditor finds immediately.

Neither is independently certifiable. Both are codes of practice extending ISO 27002, certified as an extension to an ISO 27001 certificate. That shapes how this pack is built: every control carries an ISO 27001:2022 Annex A reference wherever a genuine underlying control exists, so an organisation already certified to 27001 carries those assessments across through the crosswalk instead of answering the same question twice.

ISO 27017 is where the shared responsibility model stops being a diagram and becomes an assessable control. The seven cloud-only CLD controls keep their published identifiers; the extended-guidance controls are coded against the ISO 27002:2013 clause numbering that 27017 itself uses, so a reader can find the source text without a mapping table.

ISO 27018 binds the processor specifically. Its obligations are the ones a controller cannot discharge on your behalf: purpose limitation on the processor's own use of customer data, disclosure notification, and the geography of where personal data actually sits.

Key Features

  • 64 controls across two frameworks - 41 for ISO 27017 including all seven CLD controls, 23 for the ISO 27018 Annex A set.

  • ISO 27001 Annex A references throughout - both standards extend 27002, so a 27001 assessment propagates rather than being repeated.

  • SOC 2 trust services references on 27017 - the same cloud controls a SOC 2 Type II already tests, cross-referenced so the evidence is reused.

  • The shared responsibility split treated as the control it is - assessed per service rather than per provider, because the line moves between the managed database and the virtual machine on the same account.

  • Location assessed against real transfer records - 27018 A.11 is evidenced from <code>lynx.data.transfer</code> and the subprocessor map, including support access from another country, which is where most location claims break.

  • Privacy principles that add no controls are not invented - A.3, A.6 and A.8 of ISO 29100 add nothing in the 2019 edition and so appear in no category, rather than being padded.

Integrates With

  • lynx_compliance_certification - the ISO 27001 Annex A controls both frameworks reference.

  • lynx_compliance_privacy - DSAR, processing activity and transfer registers evidence most of 27018.

  • lynx_compliance_subprocessor_map - subprocessor disclosure and location are 27018 A.7 and A.11.

  • lynx_compliance_vendor_posture - provider-side controls you rely on but cannot test.

Try Lynx Compliance - ISO/IEC 27017 + 27018 (Cloud) on your team.

Free trial, no credit card. Talk to sales when you're ready.