
ISO 27017
ISO/IEC 27017 extends ISO 27001 with security controls written for cloud services. It clarifies what a cloud provider is responsible for versus what the customer controls. Sledge is not certified, and holds ISO 27001 first — 27017 builds on it.
ISO 27017 is on the Sledge roadmap. There is no report or assessment to share yet, and this page will say so until there is.
Why ISO 27017 is on the roadmap
ISO 27017 removes the ambiguity about who secures what in a shared cloud environment, which is usually the first question an enterprise security review asks.
Clear shared responsibility
States what Sledge secures and what stays in your control, with no grey areas.
Separation between customers
Cloud-specific controls for keeping one company’s data apart from another’s.
Cloud key management
Requirements for encryption and key handling built for cloud environments.
Cloud activity monitoring
Logging and monitoring tuned to how cloud services actually operate.
What it covers
ISO 27017 adds cloud-specific safeguards on top of ISO 27001:
Run your back office on software you can vouch for
Independently assessed. No contracts. No setup fees.