Skip to content

ISO/IEC 27017

ISO/IEC 27017:2015 — Cloud-specific extensions. Run with --compliance=Iso27017 to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: CLD.6.3.1, CLD.8.1.5, CLD.9.5.1/2, CLD.12.1.5, CLD.12.4.5, CLD.13.1.4

Official text: ISO/IEC 27017:2015. A 2026 edition has since been published; this mapping follows the 2015 one.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Adds the CLD.* controls to ISO 27001. The base ISO 27001 controls are on the ISO 27001 page.

Control Title Where it appears
CLD.6.3.1 Shared roles and responsibilities in cloud HA, replication, single-node, NIC bond
CLD.8.1.5 Removal of cloud service customer assets (declared)
CLD.9.5.1 Segregation in virtual computing environments (declared)
CLD.9.5.2 Virtual machine hardening Patch and version consistency across nodes, PVE and OS end of life, CVE, CPU security flags, outdated machine type
CLD.12.1.5 Administrator’s operational security (declared)
CLD.12.4.5 Monitoring of cloud services Cluster log, task failures, NTP, services, metric server
CLD.13.1.4 Alignment of security for virtual and physical networks Firewall, duplicate MAC

How the mapping works, and its limits: Compliance overview.