GRADUM
    FeaturesMaturity ModelsFor CreatorsPricingBlogCompareSupport
    DashboardSign Up Free
    Blog/Compare/ISO 27017 vs SAMA CSF
    Standards Comparison

    ISO 27017 vs SAMA CSF

    ISO 27017

    Voluntary
    2015

    International code of practice for cloud security controls

    VS

    SAMA CSF

    Mandatory
    2017

    Saudi regulatory framework for financial cybersecurity

    Quick Verdict

    ISO 27017 provides cloud-specific security guidance for global ISMS, while SAMA CSF mandates comprehensive cybersecurity maturity for Saudi financial firms. Organizations adopt ISO 27017 for cloud assurance in ISO 27001 audits; SAMA CSF ensures regulatory compliance and resilience.

    Cloud Security

    ISO 27017

    ISO/IEC 27017:2015 Code of practice for cloud security controls

    Cost
    €€€
    Complexity
    Medium
    Implementation Time
    6-12 months

    Key Features

    • Clarifies shared responsibilities between CSPs and customers
    • Adds seven cloud-specific security controls
    • Provides guidance for 37 ISO 27002 controls in cloud
    • Ensures multi-tenant segregation and VM hardening
    • Mandates secure asset removal and monitoring
    Cybersecurity

    SAMA CSF

    SAMA Cyber Security Framework Version 1.0

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Six-level maturity model with Level 3 baseline
    • Four core domains covering governance to third-parties
    • Principle-based controls aligned with NIST/ISO
    • Board oversight and independent CISO mandate
    • Mandatory self-assessments and SAMA audits

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    ISO 27017 Details

    What It Is

    ISO/IEC 27017:2015 is a code of practice extending ISO/IEC 27002 with cloud-specific information security controls. It provides implementation guidance for cloud services, focusing on shared responsibilities between cloud service providers (CSPs) and customers (CSCs) in a risk-based approach within an ISO 27001 ISMS.

    Key Components

    • Guidance on 37 ISO 27002 controls adapted for cloud.
    • Seven additional CLD controls for multi-tenancy, VM hardening, asset lifecycle, monitoring, and admin operations.
    • Built on ISO 27001 framework; not standalone certification.
    • Dual perspective for CSPs and CSCs.

    Why Organizations Use It

    • Addresses cloud risks like isolation and shared duties.
    • Enhances regulatory compliance (e.g., GDPR via overlaps).
    • Builds trust in multi-cloud procurement.
    • Provides competitive edge for CSPs; due diligence for CSCs.
    • Reduces incidents through mature controls.

    Implementation Overview

    • Integrate into existing ISO 27001 ISMS via risk assessment.
    • Map controls, update SoA, implement technical measures (e.g., logging, segregation).
    • Applies to all sizes using cloud (IaaS/PaaS/SaaS); global scope.
    • Audited as extension in ISO 27001 certification (9-12 months joint).

    SAMA CSF Details

    What It Is

    The Saudi Arabian Monetary Authority Cyber Security Framework (SAMA CSF) Version 1.0 (May 2017) is a mandatory regulatory framework for SAMA-regulated financial institutions in Saudi Arabia. It prescribes governance, controls, and a maturity model to detect, resist, respond, and recover from cyber threats, using a principle-based, risk-oriented approach.

    Key Components

    • Four domains: Cyber Security Leadership & Governance, Risk Management & Compliance, Operations & Technology, Third-Party Security
    • Subdomains with principles, objectives, control considerations (114+ subcontrols)
    • Six-level Maturity Model (minimum Level 3: Structured/Formalized)
    • Aligned with NIST CSF, ISO 27001, PCI-DSS
    • Self-assessment and SAMA audits for compliance

    Why Organizations Use It

    • Mandatory compliance avoids fines, scrutiny
    • Builds resilience, reduces incidents/downtime
    • Enables efficiency, partnerships, competitive differentiation
    • Enhances risk intelligence, stakeholder trust

    Implementation Overview

    • Phased: Initiation/Gap Analysis, Risk Assessment, Design/Roadmap, Deployment, Operate/Monitor, Audit/Improve
    • Targets SAMA entities (banks, insurers); all sizes
    • Risk-based, iterative; no certification but regulatory review (179 words)

    Key Differences

    AspectISO 27017SAMA CSF
    ScopeCloud-specific security controls for ISMSComprehensive cybersecurity for financial sector
    IndustryAll industries, cloud users/providers globallySaudi financial institutions only
    NatureVoluntary code of practice, no standalone certMandatory regulatory framework with maturity model
    TestingIntegrated into ISO 27001 auditsPeriodic self-assessments and SAMA audits
    PenaltiesLoss of ISO 27001 certificationFines, license suspension, regulatory action

    Scope

    ISO 27017
    Cloud-specific security controls for ISMS
    SAMA CSF
    Comprehensive cybersecurity for financial sector

    Industry

    ISO 27017
    All industries, cloud users/providers globally
    SAMA CSF
    Saudi financial institutions only

    Nature

    ISO 27017
    Voluntary code of practice, no standalone cert
    SAMA CSF
    Mandatory regulatory framework with maturity model

    Testing

    ISO 27017
    Integrated into ISO 27001 audits
    SAMA CSF
    Periodic self-assessments and SAMA audits

    Penalties

    ISO 27017
    Loss of ISO 27001 certification
    SAMA CSF
    Fines, license suspension, regulatory action

    Frequently Asked Questions

    Common questions about ISO 27017 and SAMA CSF

    ISO 27017 FAQ

    SAMA CSF FAQ

    You Might also be Interested in These Articles...

    CMMC Level 3 Implementation Guide: Integrating NIST SP 800-172 Enhanced Controls for APT Defense

    CMMC Level 3 Implementation Guide: Integrating NIST SP 800-172 Enhanced Controls for APT Defense

    Step-by-step CMMC Level 3 guide for DIB contractors. Implement 24 NIST SP 800-172 controls on Level 2. Prep for DIBCAC, C3PAO scoping & 180-day POA&Ms. Boost cy

    ISO 27701 Implementation Roadmap: Extending Your ISMS to PIMS in 12 Months or Less

    ISO 27701 Implementation Roadmap: Extending Your ISMS to PIMS in 12 Months or Less

    Extend ISO 27001 ISMS to ISO 27701 PIMS in 12 months with our phased roadmap. Templates, checklists & infographics for RoPA, DSARs & audit-ready privacy complia

    Top 10 Cost-Saving Hacks for CMMC Compliance: Budgeting Blueprints for Small DIB Suppliers

    Top 10 Cost-Saving Hacks for CMMC Compliance: Budgeting Blueprints for Small DIB Suppliers

    Slash CMMC costs 30-50% with top 10 hacks for small DIB suppliers. Enclave scoping, FedRAMP clouds, automation, POA&M tips & budgeting blueprints for Level 2 co

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Explore More Comparisons

    See how ISO 27017 and SAMA CSF compare against other standards

    Other ISO 27017 Comparisons

    • ISO/IEC 42001:2023 vs ISO 27017
    • ISO 27017 vs U.S. SEC Cybersecurity Rules
    • ISO 27017 vs MLPS 2.0 (Multi-Level Protection Scheme)
    • MLPS 2.0 (Multi-Level Protection Scheme) vs ISO 27017
    • EPA vs ISO 27017

    Other SAMA CSF Comparisons

    • ISO/IEC 42001:2023 vs SAMA CSF
    • SAMA CSF vs U.S. SEC Cybersecurity Rules
    • MLPS 2.0 (Multi-Level Protection Scheme) vs SAMA CSF
    • AEO vs SAMA CSF
    • ISO 14001 vs SAMA CSF
    GRADUM

    Transform your assessment process with collaborative, AI-powered maturity evaluations that deliver actionable insights.

    Navigation

    FeaturesMaturity ModelsFor CreatorsPricing

    Legal

    Terms and ConditionsPrivacy PolicyImprintCopyright PolicyCookie Policy

    © 2026 Gradum. All Rights Reserved