ISO 27017
International code of practice for cloud security controls
SAMA CSF
Saudi regulatory framework for financial cybersecurity
Quick Verdict
ISO 27017 provides cloud-specific security guidance for global ISMS, while SAMA CSF mandates comprehensive cybersecurity maturity for Saudi financial firms. Organizations adopt ISO 27017 for cloud assurance in ISO 27001 audits; SAMA CSF ensures regulatory compliance and resilience.
ISO 27017
ISO/IEC 27017:2015 Code of practice for cloud security controls
Key Features
- Clarifies shared responsibilities between CSPs and customers
- Adds seven cloud-specific security controls
- Provides guidance for 37 ISO 27002 controls in cloud
- Ensures multi-tenant segregation and VM hardening
- Mandates secure asset removal and monitoring
SAMA CSF
SAMA Cyber Security Framework Version 1.0
Key Features
- Six-level maturity model with Level 3 baseline
- Four core domains covering governance to third-parties
- Principle-based controls aligned with NIST/ISO
- Board oversight and independent CISO mandate
- Mandatory self-assessments and SAMA audits
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
ISO 27017 Details
What It Is
ISO/IEC 27017:2015 is a code of practice extending ISO/IEC 27002 with cloud-specific information security controls. It provides implementation guidance for cloud services, focusing on shared responsibilities between cloud service providers (CSPs) and customers (CSCs) in a risk-based approach within an ISO 27001 ISMS.
Key Components
- Guidance on 37 ISO 27002 controls adapted for cloud.
- Seven additional CLD controls for multi-tenancy, VM hardening, asset lifecycle, monitoring, and admin operations.
- Built on ISO 27001 framework; not standalone certification.
- Dual perspective for CSPs and CSCs.
Why Organizations Use It
- Addresses cloud risks like isolation and shared duties.
- Enhances regulatory compliance (e.g., GDPR via overlaps).
- Builds trust in multi-cloud procurement.
- Provides competitive edge for CSPs; due diligence for CSCs.
- Reduces incidents through mature controls.
Implementation Overview
- Integrate into existing ISO 27001 ISMS via risk assessment.
- Map controls, update SoA, implement technical measures (e.g., logging, segregation).
- Applies to all sizes using cloud (IaaS/PaaS/SaaS); global scope.
- Audited as extension in ISO 27001 certification (9-12 months joint).
SAMA CSF Details
What It Is
The Saudi Arabian Monetary Authority Cyber Security Framework (SAMA CSF) Version 1.0 (May 2017) is a mandatory regulatory framework for SAMA-regulated financial institutions in Saudi Arabia. It prescribes governance, controls, and a maturity model to detect, resist, respond, and recover from cyber threats, using a principle-based, risk-oriented approach.
Key Components
- Four domains: Cyber Security Leadership & Governance, Risk Management & Compliance, Operations & Technology, Third-Party Security
- Subdomains with principles, objectives, control considerations (114+ subcontrols)
- Six-level Maturity Model (minimum Level 3: Structured/Formalized)
- Aligned with NIST CSF, ISO 27001, PCI-DSS
- Self-assessment and SAMA audits for compliance
Why Organizations Use It
- Mandatory compliance avoids fines, scrutiny
- Builds resilience, reduces incidents/downtime
- Enables efficiency, partnerships, competitive differentiation
- Enhances risk intelligence, stakeholder trust
Implementation Overview
- Phased: Initiation/Gap Analysis, Risk Assessment, Design/Roadmap, Deployment, Operate/Monitor, Audit/Improve
- Targets SAMA entities (banks, insurers); all sizes
- Risk-based, iterative; no certification but regulatory review (179 words)
Key Differences
| Aspect | ISO 27017 | SAMA CSF |
|---|---|---|
| Scope | Cloud-specific security controls for ISMS | Comprehensive cybersecurity for financial sector |
| Industry | All industries, cloud users/providers globally | Saudi financial institutions only |
| Nature | Voluntary code of practice, no standalone cert | Mandatory regulatory framework with maturity model |
| Testing | Integrated into ISO 27001 audits | Periodic self-assessments and SAMA audits |
| Penalties | Loss of ISO 27001 certification | Fines, license suspension, regulatory action |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about ISO 27017 and SAMA CSF
ISO 27017 FAQ
SAMA CSF FAQ
You Might also be Interested in These Articles...

One Step at a Time - a 6 Month Plan to Live and Breath DORA
Achieve DORA compliance in 6 months with our detailed plan. Learn implementation sequence, starting steps, pitfalls to avoid, and accelerators for success. Toug

CMMC Level 3 Implementation Guide: Integrating NIST SP 800-172 Enhanced Controls for APT Defense
Step-by-step CMMC Level 3 guide for DIB contractors. Implement 24 NIST SP 800-172 controls on Level 2. Prep for DIBCAC, C3PAO scoping & 180-day POA&Ms. Boost cy

The Service-Oriented SOC: Leveraging Maturity Assessments to Guarantee SLOs and Operational Predictability
Transform your SOC into a service provider using maturity assessments to standardize workflows, guarantee SLOs, and ensure predictability amid turnover and risi
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
CMMI vs ISO 13485
Discover CMMI vs ISO 13485: CMMI drives IT/software process maturity (Levels 1-5), ISO 13485 ensures med device QMS compliance. Compare for optimal gains now!
COPPA vs HITRUST CSF
Compare COPPA vs HITRUST CSF: Kids' privacy law meets certifiable security standards. Avoid $170M fines, master compliance gaps. Secure your data now!
HIPAA vs TOGAF
Compare HIPAA vs TOGAF: HIPAA safeguards health data privacy & security; TOGAF drives enterprise architecture governance. Master compliance, risks & integration strategies now!