Cloud Security Controls Consultants in Dubai, Abu Dhabi & Saudi Arabia
Nathan ISO Consulting implements and certifies ISO/IEC 27017 cloud security controls for cloud service providers and cloud customers across the UAE, Saudi Arabia and the wider GCC.
Almost every organisation in the region now runs critical workloads in the cloud, and almost every one of them has had the same uncomfortable conversation with a client or auditor: who is actually responsible for what. The shared responsibility model is well understood in principle and poorly documented in practice. ISO 27017 exists precisely to close that gap, setting out cloud-specific security controls for both sides of the provider-customer relationship.
What Is ISO/IEC 27017?
ISO/IEC 27017 is a code of practice providing cloud-specific information security controls. It supplements ISO/IEC 27002 with additional implementation guidance for cloud environments, plus seven controls that exist only in the cloud context.
Like ISO 27701, it is an extension rather than a standalone certifiable standard. Certification is achieved as an extension to an ISO/IEC 27001 certificate, with the cloud controls assessed alongside the ISMS. Providers offering standalone ISO 27017 certification are describing something an accredited body cannot issue.
Crucially, the standard addresses both roles. A cloud service provider implements controls to protect the services it offers. A cloud service customer implements controls to protect what it operates on top of those services. Most organisations in the region are both — consuming infrastructure from a hyperscaler while delivering services to their own customers on top of it.
| Cloud-specific control area | What it addresses |
|---|---|
| Shared roles and responsibilities | Documented allocation of security responsibility between provider and customer, agreed rather than assumed |
| Removal of cloud service customer assets | What happens to customer data and configurations on contract termination, including verified deletion |
| Segregation in virtual computing environments | Isolation between tenants sharing underlying infrastructure |
| Virtual machine hardening | Secure configuration of virtual instances, images and templates |
| Administrator operations security | Controls over privileged cloud administration, which carries disproportionate risk in cloud environments |
| Monitoring of cloud services | Customer capability to monitor their own use of the service, and provider capability to support it |
| Alignment of virtual and physical network security | Consistency between network controls in the virtual environment and the underlying physical network |
The most valuable output of an ISO 27017 implementation is rarely a technical control. It is a documented, agreed statement of who does what. In most organisations we assess, the assumption is that the cloud provider handles security — and in most contracts, the provider handles security of the cloud while the customer handles security in the cloud. Identity and access management, encryption key handling, network configuration, logging, data classification, patching of customer-managed instances and backup validation typically sit with the customer, and frequently sit with nobody in practice.
Auditors ask about this directly, and the answer reveals quickly whether an organisation has genuinely thought about its cloud posture or simply migrated workloads and assumed the risk moved with them.
Why ISO 27017 Certification Matters in the UAE and GCC
Regional cloud adoption accelerated rapidly, and hyperscaler regions now operate within the UAE and Saudi Arabia. Many organisations migrated workloads faster than they built the governance around them, leaving configuration, access and monitoring responsibilities informally allocated.
Regulatory expectations around where data physically resides affect financial services, healthcare, government suppliers and organisations subject to UAE or Saudi data protection law. ISO 27017 forces documentation of data location, transfer and provider obligations — which is exactly the evidence a regulator or client asks for.
Buyers evaluating SaaS and managed cloud providers increasingly ask specific cloud security questions that generic ISO 27001 certification does not fully answer. For a provider, ISO 27017 demonstrates that cloud-specific risks have been addressed rather than absorbed into a general security programme.
Where you host multiple customers on shared infrastructure, tenant segregation is the concern that keeps client security teams awake. Certified controls covering virtual environment segregation provide independently assessed assurance rather than an architectural assertion.
The removal of customer assets control addresses something most contracts handle poorly: what actually happens to your data when a cloud relationship ends. For customers, this is genuine commercial protection. For providers, being able to evidence a controlled exit process is a competitive advantage in enterprise negotiation.
Nathan ISO Consulting’s ISO 27017 Services
Whether you are implementing as a cloud service provider, a cloud service customer, or both — which determines which controls apply and how they are evidenced. Scope covers the services, environments and customer relationships within the certificate.
A documented, service-by-service allocation of security responsibility between you and your providers, and between you and your customers where you deliver cloud services. This is the foundational artefact of the whole implementation.
Assessment of your cloud environments against the standard’s control expectations — identity and access management, network segmentation, encryption and key management, logging and monitoring, and instance hardening.
For providers, documenting and evidencing the isolation controls separating customer environments on shared infrastructure, including the testing that demonstrates they work.
Cloud administrator access carries disproportionate risk, since a single privileged credential can affect an entire environment. We design access control, approval, session monitoring and review arrangements proportionate to that exposure.
Where data resides, where it is replicated and backed up, which jurisdictions it transits, and what contractual and technical safeguards apply — supporting both ISO 27017 and any UAE or Saudi data protection obligations.
Documented processes for returning and verifiably deleting customer data and configurations on termination, with the evidence trail clients increasingly require contractually.
Capability for you to monitor your own cloud service usage, and where you are a provider, capability for customers to monitor theirs — including log retention, availability and integrity.
Assessment of your own cloud providers and any sub-providers, with contractual security clauses that genuinely support the commitments you make to your customers.
Where ISO 27001 is not already held, we implement both together and coordinate a combined certification audit. Where it is held, we implement ISO 27017 as an extension assessed at your next surveillance or recertification visit.
Our ISO 27017 Certification Process
Consultation and fixed proposal. Discussion of your cloud environments, provider relationships, customer commitments and ISO 27001 status, followed by a fixed written quotation.
Role and scope definition. Provider, customer or both, with services and environments in scope.
Cloud environment discovery. What you run, where, with which providers, and who currently manages each layer.
Shared responsibility matrix. Service-by-service allocation documented and agreed with the relevant parties.
Gap analysis against cloud controls. Assessment against the seven cloud-specific controls and the cloud implementation guidance for existing ISO 27002 controls.
Technical remediation support. Working with your engineering team or provider on access control, segregation, hardening, logging and encryption gaps.
Documentation development. Cloud security policy, configuration standards, administration procedures, exit and deletion processes.
Contractual review. Provider agreements and customer commitments reconciled against actual capability.
Training. Cloud security awareness for engineering and administration staff, plus internal auditor familiarity with cloud controls.
Internal audit and management review. Cloud controls included in the ISMS audit programme and management review.
Certification audit. Assessed as an extension to ISO 27001, combined where both are being implemented, with our consultant present.
Surveillance support. Nonconformity closure and ongoing support as environments and provider relationships evolve.
Why Choose Nathan ISO Consulting
The responsibility matrix comes first. It is the artefact that determines whether everything else is coherent, and the one auditors examine hardest.
Honest about the ISO 27001 dependency. ISO 27017 cannot be certified standalone. We tell you that upfront rather than selling a certificate that cannot be issued.
We work with your engineers, not around them. Cloud controls are implemented in configuration, not documentation. We support your technical team rather than producing policies describing controls nobody has built.
Provider-agnostic. We work across AWS, Azure, Google Cloud, Oracle and regional providers, and configure around the environments you actually run.
Data residency addressed explicitly. Regional regulatory expectations around data location make this consequential in the GCC in a way it is not everywhere.
Exit and deletion taken seriously. The customer asset removal control is genuine commercial protection, and most contracts handle it poorly.
Extension pathway to 27701 and 27018. Where privacy obligations also apply, we structure the work so the next extension builds on this one.
One dedicated lead consultant throughout. Continuity from discovery through surveillance audits.
Fixed written pricing. Agreed upfront with audit attendance included.
Independent of certification bodies. Certification is issued independently under ISO/IEC 17021.
Industries We Serve
SaaS and software providers. Multi-tenant platforms with customer data segregation and enterprise security assessment requirements.
Managed service and hosting providers. Cloud infrastructure and managed platform services delivered to multiple clients.
Data centres and colocation operators. Hybrid environments spanning physical facilities and cloud service delivery.
Banking, fintech and insurance. Cloud adoption under regulatory scrutiny, with data residency and outsourcing notification obligations.
Healthcare technology. Patient data in cloud environments alongside ADHICS and privacy obligations.
Government suppliers. Cloud services delivered to public sector clients with sovereignty and assurance requirements.
E-commerce and digital platforms. Customer and payment data in scalable cloud environments.
Oil, gas and industrial technology. Cloud-connected operational systems where IT and OT boundaries require careful control.
Enterprises as cloud customers. Organisations consuming cloud services who need to demonstrate governance of what they operate in the cloud.
Locations We Serve
ISO 27017 consultants across Dubai, with concentration in the technology and financial hubs — Dubai Internet City, Dubai Silicon Oasis, Dubai Media City, Dubai Production City, DMCC, JAFZA, DAFZA and DIFC — plus mainland technology companies in Business Bay and across the emirate.
Abu Dhabi city, Masdar City, Abu Dhabi Global Market, Hub71, KEZAD and Al Ain — including government technology suppliers, ADNOC digital initiatives and healthcare organisations operating cloud workloads under ADHICS requirements.
Sharjah city, Sharjah Publishing City, Hamriyah Free Zone and SAIF Zone; Ajman and Ajman Free Zone; Ras Al Khaimah and RAKEZ; Umm Al Quwain Free Trade Zone; Fujairah and Fujairah Free Zone.
Riyadh, Jeddah, Dammam, Al Khobar, Dhahran, Mecca and Medina — including King Abdullah Economic City, NEOM and organisations aligning cloud environments with NCA Essential Cybersecurity Controls, SAMA Cyber Security Framework and Saudi PDPL requirements.
Qatar — Doha, Lusail, Qatar Free Zones and the Qatar Financial Centre. Kuwait — Kuwait City and Shuwaikh. Oman — Muscat, Knowledge Oasis and Duqm. Bahrain — Manama, Seef and Bahrain Bay, a significant regional cloud hosting location.
What Determines the Cost of ISO 27017 Certification?
As an extension to ISO 27001, certification body fees are typically additional audit days on top of the ISMS assessment rather than a separate full audit. Where ISO 27001 and ISO 27017 are implemented together, the combined assessment costs materially less than sequencing them.
Our consultancy fee is separate and fixed in writing before engagement, driven by whether you implement as provider, customer or both, the number of cloud environments and providers involved, the complexity of your architecture and tenant model, the extent of technical remediation required, and whether ISO 27001 already exists. Where cloud configuration has grown organically without governance, the discovery and remediation phase is usually the longest part of the programme.
Get Started with ISO 27017 Certification
For ISO/IEC 27017 cloud security certification in Dubai, Abu Dhabi, Sharjah, Saudi Arabia, Qatar, Kuwait, Oman or Bahrain, call +971 50 258 5024, email info@nathanisoconsulting.com, or visit our contact page for a cloud security gap assessment and a fixed written proposal.
Frequently Asked Questions About ISO 27017 Certification
No. ISO 27017 is a code of practice extending ISO 27001 and ISO 27002, and certification is achieved as an extension to an ISO 27001 certificate. Standalone ISO 27017 certification is not something an accredited certification body can issue.
Both. The standard sets out controls for cloud service providers and for cloud service customers separately. Most organisations are both — consuming infrastructure from a hyperscaler while delivering services to their own customers on top of it — and implement the relevant controls for each role.
Their certification covers their infrastructure and their responsibilities. It says nothing about what you configure and operate on top of it — identity and access management, encryption key handling, network configuration, logging, data classification and backup validation typically remain yours. That division is exactly what ISO 27017 forces you to document.
The allocation of security responsibility between cloud provider and customer. Broadly, the provider secures the cloud infrastructure and the customer secures what they put in it, but the exact boundary shifts between infrastructure, platform and software service models. The most valuable output of an ISO 27017 implementation is usually a documented, agreed matrix rather than any single technical control.
ISO 27017 covers cloud security controls generally, for providers and customers. ISO 27018 is a code of practice specifically for protecting personally identifiable information in public cloud environments where the provider acts as a processor. They are complementary, and cloud providers handling personal data frequently implement both.
ISO 27017 addresses cloud security; ISO 27701 addresses privacy management across all processing, cloud or otherwise. Both extend ISO 27001. Organisations processing personal data in cloud environments frequently implement all three, with the ISMS as the foundation.
Two to four months as an extension where ISO 27001 is already certified and cloud environments are reasonably well governed. Where cloud configuration has grown organically and requires remediation, or where ISO 27001 must be implemented alongside, plan on six to nine months.
No. ISO 27017 requires you to document where data resides and what controls apply, not to host in any particular location. Data residency requirements come from regulation and contract — UAE and Saudi data protection law, sector regulators, and client requirements — and the standard helps you evidence compliance with whatever those requirements are.
Documented processes for returning and deleting customer data, configurations and virtual assets when a cloud service relationship ends, with verification that deletion actually occurred including in backups and replicas. For customers it is commercial protection; for providers it is an increasingly common contractual requirement.
Auditors examine the architecture and controls isolating customer environments on shared infrastructure — network segmentation, access controls, storage isolation, and the testing evidence demonstrating that isolation holds. Assertion of segregation without testing evidence is a common finding for multi-tenant providers.
Scope should cover the environments supporting services within your certificate. Shadow cloud usage — environments spun up by individual teams outside central governance — is a frequent discovery during implementation, and typically needs bringing under governance or decommissioning rather than being quietly excluded.
Privileged cloud administration carries disproportionate risk because a single credential can affect an entire environment. Expected controls include restricted privileged accounts, multi-factor authentication, just-in-time or approval-based elevation, session logging, and periodic access review. This is one of the areas assessors probe most consistently.
The standard is written technology-neutrally, so its principles apply to containerised and serverless architectures as they do to virtual machines — segregation, hardening, access control, logging and monitoring. Implementation guidance references virtual machines specifically because of when it was written, but auditors assess the control objective rather than the technology.
For the provider’s own responsibilities, yes — provider certifications, attestations and compliance reports are appropriate evidence of what they manage. For your responsibilities, you need your own evidence. Submitting a provider’s certification as evidence for customer-side controls is a common and easily identified gap.
Both frameworks include cloud and third-party security requirements. ISO 27017 controls and the shared responsibility documentation map onto significant portions of those requirements, reducing the evidence assembly burden considerably, though the regulatory frameworks remain separate obligations with their own assessment processes.
Look for accreditation from a recognised IAF member — EIAC, ENAS, GAC in Saudi Arabia, UKAS or ANAB — covering ISO 27001 with ISO 27017 extension capability. We are independent of all certification bodies and advise during scoping.
That you can monitor your own use of cloud services, and where you are a provider, that customers can monitor theirs. This includes log availability, retention appropriate to your obligations, protection of log integrity, and the ability to detect and investigate security events within your area of responsibility.
It touches on it, but service continuity is more fully addressed by ISO 22301 and IT service continuity within ISO 20000. Organisations with meaningful availability commitments to customers frequently implement ISO 27017 alongside one or both, since cloud architecture decisions affect security and continuity together.
Yes. Cloud security awareness and configuration workshops are included in our implementation programmes and available standalone. Because cloud controls live in configuration rather than documentation, engineering competence is what actually determines whether the controls hold.
By keeping the shared responsibility matrix current as services and providers change, bringing new environments under governance rather than outside it, reviewing configuration against your standards after major architectural changes, maintaining access reviews, and including cloud controls in your internal audit programme. Environments that drifted from documented configuration are the most common surveillance finding.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving