Standards Comparison

    ISO 27017

    Voluntary
    2015

    International code of practice for cloud security controls

    VS

    SAMA CSF

    Mandatory
    2017

    Saudi regulatory framework for financial cybersecurity

    Quick Verdict

    ISO 27017 provides cloud-specific security guidance for global ISMS, while SAMA CSF mandates comprehensive cybersecurity maturity for Saudi financial firms. Organizations adopt ISO 27017 for cloud assurance in ISO 27001 audits; SAMA CSF ensures regulatory compliance and resilience.

    Cloud Security

    ISO 27017

    ISO/IEC 27017:2015 Code of practice for cloud security controls

    Cost
    €€€
    Complexity
    Medium
    Implementation Time
    6-12 months

    Key Features

    • Clarifies shared responsibilities between CSPs and customers
    • Adds seven cloud-specific security controls
    • Provides guidance for 37 ISO 27002 controls in cloud
    • Ensures multi-tenant segregation and VM hardening
    • Mandates secure asset removal and monitoring
    Cybersecurity

    SAMA CSF

    SAMA Cyber Security Framework Version 1.0

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Six-level maturity model with Level 3 baseline
    • Four core domains covering governance to third-parties
    • Principle-based controls aligned with NIST/ISO
    • Board oversight and independent CISO mandate
    • Mandatory self-assessments and SAMA audits

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    ISO 27017 Details

    What It Is

    ISO/IEC 27017:2015 is a code of practice extending ISO/IEC 27002 with cloud-specific information security controls. It provides implementation guidance for cloud services, focusing on shared responsibilities between cloud service providers (CSPs) and customers (CSCs) in a risk-based approach within an ISO 27001 ISMS.

    Key Components

    • Guidance on 37 ISO 27002 controls adapted for cloud.
    • Seven additional CLD controls for multi-tenancy, VM hardening, asset lifecycle, monitoring, and admin operations.
    • Built on ISO 27001 framework; not standalone certification.
    • Dual perspective for CSPs and CSCs.

    Why Organizations Use It

    • Addresses cloud risks like isolation and shared duties.
    • Enhances regulatory compliance (e.g., GDPR via overlaps).
    • Builds trust in multi-cloud procurement.
    • Provides competitive edge for CSPs; due diligence for CSCs.
    • Reduces incidents through mature controls.

    Implementation Overview

    • Integrate into existing ISO 27001 ISMS via risk assessment.
    • Map controls, update SoA, implement technical measures (e.g., logging, segregation).
    • Applies to all sizes using cloud (IaaS/PaaS/SaaS); global scope.
    • Audited as extension in ISO 27001 certification (9-12 months joint).

    SAMA CSF Details

    What It Is

    The Saudi Arabian Monetary Authority Cyber Security Framework (SAMA CSF) Version 1.0 (May 2017) is a mandatory regulatory framework for SAMA-regulated financial institutions in Saudi Arabia. It prescribes governance, controls, and a maturity model to detect, resist, respond, and recover from cyber threats, using a principle-based, risk-oriented approach.

    Key Components

    • Four domains: Cyber Security Leadership & Governance, Risk Management & Compliance, Operations & Technology, Third-Party Security
    • Subdomains with principles, objectives, control considerations (114+ subcontrols)
    • Six-level Maturity Model (minimum Level 3: Structured/Formalized)
    • Aligned with NIST CSF, ISO 27001, PCI-DSS
    • Self-assessment and SAMA audits for compliance

    Why Organizations Use It

    • Mandatory compliance avoids fines, scrutiny
    • Builds resilience, reduces incidents/downtime
    • Enables efficiency, partnerships, competitive differentiation
    • Enhances risk intelligence, stakeholder trust

    Implementation Overview

    • Phased: Initiation/Gap Analysis, Risk Assessment, Design/Roadmap, Deployment, Operate/Monitor, Audit/Improve
    • Targets SAMA entities (banks, insurers); all sizes
    • Risk-based, iterative; no certification but regulatory review (179 words)

    Key Differences

    Scope

    ISO 27017
    Cloud-specific security controls for ISMS
    SAMA CSF
    Comprehensive cybersecurity for financial sector

    Industry

    ISO 27017
    All industries, cloud users/providers globally
    SAMA CSF
    Saudi financial institutions only

    Nature

    ISO 27017
    Voluntary code of practice, no standalone cert
    SAMA CSF
    Mandatory regulatory framework with maturity model

    Testing

    ISO 27017
    Integrated into ISO 27001 audits
    SAMA CSF
    Periodic self-assessments and SAMA audits

    Penalties

    ISO 27017
    Loss of ISO 27001 certification
    SAMA CSF
    Fines, license suspension, regulatory action

    Frequently Asked Questions

    Common questions about ISO 27017 and SAMA CSF

    ISO 27017 FAQ

    SAMA CSF FAQ

    You Might also be Interested in These Articles...

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Check out these other Gradum.io Standards Comparison Pages