ISO/IEC 27017:2015
ISO/IEC 27017:2015 is an information security standard designed for cloud service environments, offering controls and best practices tailored to cloud computing. The standard provides security guidelines for both cloud service providers and customers, aiming to ensure adequate protection of information within the cloud environment. It addresses specific risks associated with cloud services, such as virtualization, resource sharing, and data segregation.
ISO/IEC 27017:2015 extends the framework of ISO/IEC 27001, focusing particularly on the unique security challenges of the cloud. It not only offers recommendations for the security responsibilities of cloud service providers but also helps cloud service users understand how to ensure the security of their data in the cloud. This enhances transparency and trust for businesses adopting cloud services.
After undergoing an independent third-party audit, Tuya has achieved ISO/IEC 27017:2015 certification.