{
  "node_id": "iso-27017-2015-cloud-controls",
  "title": "ISO/IEC 27017:2015 - Code of Practice for Information Security Controls for Cloud Services",
  "domain": "Cloud & SaaS",
  "version": "1.0.0",
  "last_updated": "2026-04-17",
  "bluf": "This standard provides guidelines for information security controls applicable to the provision and use of cloud services, supplementing the guidance in ISO/IEC 27002. It introduces cloud-specific controls and implementation guidance for both cloud service providers and customers, focusing on clarifying roles and responsibilities as outlined in Clause 6.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "csa-ccm-v4-cloud-controls",
    "iso-27018-pii-cloud",
    "nist-sp-800-145-cloud-definition"
  ],
  "primary_citations_count": 6
}