Industry
SECURITYFRAMEWORKISO 27017/27018

Pentesting for ISO 27017/27018

ISO 27017 and ISO 27018 extend ISO 27001 with guidance for cloud security and personal data in public clouds. They apply to cloud providers, customers, and PII processors such as SaaS platforms. Testing follows the shared-responsibility line: customers test the application and configuration layers they control. There are no separate penalties; evidence supports certification and customer trust.

The controls we cover

Requirement summary

Cloud-specific guidance assigns shared responsibility: the provider manages vulnerabilities across the service stack, while the customer manages vulnerabilities in its own hosted application layers, with PII processing systems secured under ISO 27018.

AISafe tests the application, API, identity, and configuration layers the customer controls, and records validated fixes to support the technical evidence.

Requirement summary

The testing control is extended so security testing covers the virtualized environment and services, and the applications the customer hosts, including PII processing systems under ISO 27018.

AISafe verifies cloud-hosted applications against security requirements before acceptance into production, on the layers the customer owns.

Quick facts

ApplicabilityCloud providers and customers, and PII processors in public clouds (such as SaaS platforms), under an ISO 27001 ISMS.
RequirementNo separate mandate; voluntary, driven by customers and contracts alongside ISO 27001.
CostScoped to the cloud layers you control (applications, identity, configuration), keeping cost proportional to size; automation lowers recurring cost.
CadenceAligned to ISO 27001; commonly yearly, plus after significant cloud or application changes.

AISafe Labs delivers on-demand, audit-ready evidence for ISO 27017/27018: testing the cloud application layers your organization controls, with findings mapped to technical vulnerability and security-testing evidence , in hours, where other vendors take weeks. AISafe Labs does not certify the ISMS or assess the cloud provider’s entire control environment.

Related frameworks

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.