ISO 27001 vs. ISO 27017/27018 vs. CSA STAR: The Cloud-Vendor Controls Guide
ISO 27001, ISO 27017, ISO 27018, and CSA STAR often show up together on a vendor’s trust page. That makes buyers assume they compete for the same job. They don’t. ISO 27001 certifies the information security management system, or ISMS, itself.
ISO 27017 and ISO 27018 are cloud-specific extensions to that base control set. One covers security, the other covers privacy. CSA STAR is a separate cloud assurance program. It’s built on top of ISO 27001 or SOC 2 evidence, not a replacement for either.
Maybe you’re vetting a cloud vendor. Maybe you run one and need to know what credential to pursue next. Either way, this guide breaks down what each one actually proves.
ISO 27001, Recapped
It’s jointly published by ISO and the International Electrotechnical Commission (IEC). It sets requirements for building, running, and improving an ISMS. That includes assessing and treating information security risks. If you need this explained from scratch, see what ISO 27001 actually is.
An ISMS is not a piece of software or a single document. It’s the whole system of policies, risk processes, and controls an organization runs to protect its information. ISO 27001 is the standard you get certified against. The ISMS is the operating system that certificate attests is working.
Certification applies to a scope the organization defines, not automatically the whole company. That could be one business unit, one data center, or everything. The requirements themselves are written to fit organizations of any size or type.
That work happens across seven mandatory clauses:
- Clause 4: Context of the organization
- Clause 5: Leadership
- Clause 6: Planning, including risk assessment and treatment
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance evaluation
- Clause 10: Improvement
Clauses 4-10 set out what the ISMS has to do. Annex A lists which controls it has to consider.
ISO 27017: Cloud-Specific Security Controls
ISO/IEC 27017:2015 is not a standalone certification you audit an ISMS against the way you do with ISO 27001. It’s a cloud-specific extension to ISO/IEC 27002, the control catalog ISO 27001’s Annex A draws from.
ISO 27002 isn’t something you get certified against on its own. It’s the control catalog. ISO 27001 draws its Annex A controls from it. ISO 27017 extends that same catalog with cloud-specific guidance.
It adds cloud-specific guidance to existing controls. It also adds new controls for risks unique to cloud environments, including:
- Shared responsibility between provider and customer
- Virtual machine hardening
- Cloud service configuration
Shared responsibility means the cloud provider secures the infrastructure. The customer secures what they put on it. ISO 27017 gives providers a way to document exactly where that line sits, control by control.
For a buyer, this matters because ISO 27001 alone doesn’t guarantee cloud-specific practices were reviewed. ISO 27017 confirms an auditor specifically checked cloud controls, not just the general ISMS.
Microsoft’s own ISO 27017 certification shows this in practice. Microsoft is audited against it every year, alongside its base ISO 27001 certification, not instead of it.
If you’re vetting a vendor, ask for two things:
- Their ISO 27001 certificate scope
- ISO 27017 audited within that same scope, not claimed separately
| Standard | Protects | Applies To |
|---|---|---|
| ISO/IEC 27017:2015 | Systems and cloud security | Cloud service providers |
| ISO/IEC 27018:2019 | Personal data (PII) | Cloud providers acting as PII processors |
ISO 27018: Cloud-Specific Privacy Controls
ISO/IEC 27018:2019 works the same way as 27017, but it protects data instead of systems. It’s also a cloud-specific extension, aimed specifically at cloud providers acting as processors of personally identifiable information (PII). Where 27017 hardens the infrastructure, 27018 governs how a provider handles the personal data that infrastructure holds.
In practice, a processor handles personal data on someone else’s behalf, without deciding why it’s collected in the first place. A cloud vendor storing your customers’ records fits that role. ISO 27018 gives cloud processors a specific control set to prove they protect that PII appropriately.
This distinction matters for a buyer handling regulated personal data. ISO 27018 confirms an auditor checked how the provider handles PII specifically. That’s different from just checking general security hygiene.
A cloud vendor without ISO 27018 isn’t necessarily unsafe. It just means an auditor hasn’t specifically verified PII handling under that framework. Some vendors handle PII outside cloud services and don’t need it. Others simply haven’t pursued it yet.
Microsoft’s ISO 27018 certification is assessed during the same audit cycle as its ISO 27001 and ISO 27017 certifications. As with 27017, a vendor typically pursues 27018 alongside its base ISO 27001 certification, not as a substitute for it.
If personal data is part of what you’re handing over, ask the same question for ISO 27018. Was it audited within the certified scope? Or just claimed on a website?
How 27017 and 27018 Fit Onto a Base ISO 27001 Certificate
Think of ISO 27001 as the foundation. It’s the base ISMS certification a cloud vendor builds everything else on. ISO 27017 and ISO 27018 sit on top of it as extensions, not substitutes.
A vendor doesn’t choose ISO 27001 or ISO 27017. They typically hold ISO 27001 first, then add 27017 for cloud security, 27018 for cloud privacy, or both. None of the three exist as a standalone alternative to the others.
This matters when you’re reading a vendor’s compliance page. If you see “ISO 27017 certified” with no mention of ISO 27001, ask why. The extension can’t stand on its own the way the base standard can.
A base ISO 27001 certificate has its own requirements before a vendor can add these extensions. Our certification requirements guide covers what that actually takes.
A cloud service provider working toward this stack should also understand the underlying management system, not just the certificate. What an ISMS actually is explains the operating system behind the paperwork.
CSA STAR: A Separate Assurance Program, Not a Third Competitor
CSA STAR is different from the other two. It’s not an ISO standard at all. The Cloud Security Alliance (CSA), a nonprofit focused on cloud security best practices, runs it as its own assurance program.
At the center of STAR is the Cloud Controls Matrix (CCM), CSA’s meta-framework. The CCM doesn’t replace ISO 27001, ISO 27017, SOC 2, or NIST. It maps to all of them.
CSA STAR comes in three levels:
| STAR Level | What It Involves | Cost | Built On |
|---|---|---|---|
| Level 1: Self-Assessment | Provider publishes a completed CAIQ to the public STAR Registry | Free | No external audit required |
| Level 2: Certification/Attestation | Independent audit by an accredited body or CPA firm | Paid, third-party audit | ISO 27001 base (Certification) or SOC 2 base (Attestation) |
| Level 3: Continuous Auditing | Near-real-time, ongoing control monitoring | Paid, ongoing | Layered on top of Level 2 |
Level 1 is the easy entry point. Any provider can complete the questionnaire and publish it. It’s a useful first signal, but it’s self-reported, not independently verified.
Level 2 is where third-party verification comes in. A vendor that already holds ISO 27001 typically pursues STAR Certification. It’s often audited in the same engagement as their ISO 27001 renewal. One that holds SOC 2 instead pursues STAR Attestation.
Level 3 is for large, high-risk cloud providers running continuous monitoring rather than periodic snapshots. Most small and mid-size vendors won’t have it, and most buyers don’t need to require it.
What Each Credential Actually Tells You
Not every cloud vendor needs every credential. Not every buyer needs to require every credential. What matters depends on your risk profile.

- You’re storing regulated personal data. Look for ISO 27018 specifically, not just a general privacy policy.
- You’re running workloads in someone else’s cloud infrastructure. ISO 27017 tells you cloud-specific security controls were reviewed, not just general IT security.
- You want independent, third-party verification, not a self-report. That rules out CSA STAR Level 1 on its own. Look for Level 2 or higher.
- Your contract or industry expects a US-market credential instead. SOC 2 may matter more than ISO 27001 in that case. See ISO 27001 vs SOC 2 for how the two base certifications actually differ.
None of these credentials tell you a vendor is risk-free. They tell you an independent party checked specific things, and which things those were. A vendor with none of them isn’t automatically unsafe, but you’re taking their word for it instead of an auditor’s.
If you’re not sure which of these matters for your situation, contact us and we’ll walk through it.
See Where You Stand
Wondering how your own environment would hold up under an ISO 27001 audit? Take the free 2-minute ISO 27001 Risk-Check: 8 plain-English questions, your readiness level, and the gaps to close first. No sign-up required to see your result.
Take the free 2-minute ISO 27001 Risk-Check
Related Guides
- What Is ISO 27001? The Plain-English Guide to ISMS Certification
- What Is an ISMS? The Plain-English Guide
- ISO 27001 vs SOC 2: What’s the Real Difference?
- ISO 27001 Certification Requirements: What You Actually Need
Frequently Asked Questions
No. ISO 27017 is a cloud-specific extension to the control catalog ISO 27001’s Annex A draws from, not a standalone certification. A vendor still needs a base ISO 27001 certificate. ISO 27017 adds cloud-specific security guidance on top of it.
Not necessarily. ISO 27018 is aimed specifically at cloud providers acting as processors of personally identifiable information. If a vendor’s service genuinely doesn’t touch PII, the certification is less relevant to your risk profile.
Level 1 is a free self-assessment. The provider publishes a completed questionnaire to CSA’s public registry with no external auditor involved. Level 2 requires an independent audit by an accredited certification body or CPA firm. It’s built on either an ISO 27001 or SOC 2 base.
Yes, through the Attestation path. STAR Level 2 comes in two forms. Certification is built on an ISO 27001 base. Attestation is built on a SOC 2 base instead. A vendor can reach Level 2 through either underlying framework.
Ask for the certificate scope. Confirm the extension was audited within that same scope, in the same audit cycle as the base ISO 27001 certification. A claim with no certificate reference or audit date attached is worth following up on. Don’t take it at face value.
It depends on your market and contract requirements. ISO 27001 is the internationally recognized standard and often expected outside the US. SOC 2 is an American framework and the more commonly requested credential in the US SaaS market. Many vendors hold both.
Ready to Build Toward ISO 27001 Yourself?
If you’re the cloud provider in this conversation, not just the buyer, a certifiable ISMS takes more than paperwork. LeadingIT helps Chicagoland businesses build and evidence those technical controls. See LeadingIT’s ISO 27001 compliance support for the done-for-you technical path.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
