ISO/IEC 27017
Extend your ISO 27001 into the cloud
The cloud-security code of practice that extends ISO 27001/27002. Obligara adds the genuinely cloud-specific CLD controls — segregation in virtual computing, VM hardening, administrator operational security, monitoring of cloud services — each cross-mapped to the ISO 27001 control it builds on, so you extend rather than duplicate.
7
cloud CLD controls
ISO 27001
built on your ISMS
Mapped
to Annex A
- Cloud-specific CLD controls
- Extends, not duplicates
- Shared responsibility, made explicit
- One register, one audit trail

What’s in the module
The cloud extension, not a second ISMS
ISO 27017 layers cloud-specific controls onto ISO 27001. Obligara adds exactly those, mapped back to the ISMS you already operate.
- 01
Cloud-specific CLD controls
The additive controls ISO 27017 brings — shared roles, virtual-machine hardening, alignment of virtual and physical network security.
- 02
Extends, not duplicates
Each control links to the ISO 27001 clause it extends, so your existing ISMS evidence carries straight across.
- 03
Shared responsibility, made explicit
Clarifies which controls are the cloud customer’s and which are the provider’s — the split auditors ask about.
- 04
One register, one audit trail
Reads from the same controls, evidence and audit log as the rest of your workspace.
How it runs
One ISMS, extended for the cloud
The additive CLD controls only
Not a re-listing of the 93 Annex A controls — just the cloud-specific ones ISO 27017 adds, so the module is focused on what actually changes for the cloud.
Mapped to your ISMS
Each CLD control links to the ISO 27001 clause it extends, so your existing evidence is reused and the delta is obvious.
Shared responsibility, evidenced
Makes explicit which controls are the cloud customer’s and which are the provider’s — the split auditors always probe — and evidences your side.
See ISO 27017 on your ISMS
Already running ISO 27001? We’ll show the cloud controls it adds and how much your existing evidence already covers.