Standards, Regulations & Certifications

To help you with compliance and reporting, we share information, best practices, and easy access to documentation. Our products regularly undergo independent verification of security, privacy, and compliance controls, achieving certifications against global standards to earn your trust. We’re constantly working to expand our coverage.

Back ISO 27017 logo

ISO 27017

Controlling cloud-based information security.

The International Organization for Standardization (ISO) is an independent, non-governmental international organization with a membership of 163 national standards bodies.

The ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:

  • Additional implementation guidance for relevant controls specified in ISO/IEC 27002

  • Additional controls with implementation guidance that specifically relate to cloud services

This standard provides controls and implementation guidance for both cloud service providers (like Google) and our cloud service customers.

ISO 27017 provides cloud-based guidance on 37 of the controls in ISO 27002 but also features seven new cloud controls that address the following:

  • Who is responsible for what between the cloud service provider and the cloud customer

  • The removal/return of assets when a contract is terminated

  • Protection and separation of the customer’s virtual environment

  • Virtual machine configuration

  • Administrative operations and procedures associated with the cloud environment

  • Cloud customer monitoring of activity within the Cloud

  • Virtual and cloud network environment alignment

Google Cloud Platform and G Suite are are certified as ISO 27017 compliant.

Google Cloud services that are in scope for ISO 27017:

Expand all Collapse all
  • Google Cloud Platform

    Google App Engine, Google App Engine Flexible Environment, Google BigQuery, Google Cloud Bigtable, Google Billing API, Google Cloud CDN (Content Delivery Network) Google Cloud Console, Google Cloud Data Loss Prevention API, Google Cloud Dataflow, Google Cloud Datalab, Google Cloud Dataproc, Google Cloud Datastore, Google Cloud DNS, Google Cloud Endpoints, Google Cloud Functions, Google Cloud IAM (Identity & Access Management), Google Cloud Jobs API, Google Cloud Key Management Service, Google Cloud Launcher, Google Cloud Load Balancing, Google Cloud Machine Learning Engine, Google Cloud Mobile App, Google Cloud Natural Language API, Google Cloud Pub/Sub, Google Cloud Resource Manager, Google Cloud Router, Google Cloud SDK, Google Cloud Security Scanner, Google Cloud Shell, Google Cloud Source Repositories, Google Cloud Speech API, Google Cloud SQL, Google Cloud Storage, Google Cloud Translation API, Google Cloud Vision API, Google Cloud Virtual Network, Google Cloud VPN, Google Compute Engine, Google Container Builder, Google Container Engine, Google Container Registry, Google Deployment Manager, Google Genomics, Google Service Control, Google Stackdriver Debugger, Google Stackdriver Error Reporting, Google Stackdriver Logging, Google Stackdriver Trace

  • G Suite

    Calendar, Classroom (Only for G Suite for Education), Cloud Search, Contacts, Docs, Drive, Forms, Gmail, Google+, Groups, Hangouts, Hangouts Meet, Keep, Sites, Sheets, Classic Sites, Slides, Vault

  • Additional Google Products

    Admin Console, App Maker, Chrome Device Management, Chrome Sync, Cloud Identity, Apps Script, Google Now, Hangouts Chat, Inbox by Gmail, Jamboard, Talk, Tasks

  • Google Product APIs

    Apps Activity API, Calendar API, Contacts API, Drive Rest API, Gmail Rest API, Sheets API, Sites API, Tasks API

  • G Suite Admin SDK

    Admin Settings API, Calendar Resource API, Domain Shared Contacts API, Directory API, Email Audit API, Email Settings API, Enterprise License Manager API, Groups Migration API, Groups Settings API, Reports API, SAML-based SSO API, Reseller API

  • Google Cloud Platform:

    Google App Engine, Google App Engine Flexible Environment, Google BigQuery, Google Cloud Bigtable, Google Billing API, Google Cloud CDN (Content Delivery Network) Google Cloud Console, Google Cloud Data Loss Prevention API, Google Cloud Dataflow, Google Cloud Datalab, Google Cloud Dataproc, Google Cloud Datastore, Google Cloud DNS, Google Cloud Endpoints, Google Cloud Functions, Google Cloud IAM (Identity & Access Management), Google Cloud Jobs API, Google Cloud Key Management Service, Google Cloud Launcher, Google Cloud Load Balancing, Google Cloud Machine Learning Engine, Google Cloud Mobile App, Google Cloud Natural Language API, Google Cloud Pub/Sub, Google Cloud Resource Manager, Google Cloud Router, Google Cloud SDK, Google Cloud Security Scanner, Google Cloud Shell, Google Cloud Source Repositories, Google Cloud Speech API, Google Cloud SQL, Google Cloud Storage, Google Cloud Translation API, Google Cloud Vision API, Google Cloud Virtual Network, Google Cloud VPN, Google Compute Engine, Google Container Builder, Google Container Engine, Google Container Registry, Google Deployment Manager, Google Genomics, Google Service Control, Google Stackdriver Debugger, Google Stackdriver Error Reporting, Google Stackdriver Logging, Google Stackdriver Trace

  • G Suite:

    Calendar, Classroom (Only for G Suite for Education), Cloud Search, Contacts, Docs, Drive, Forms, Gmail, Google+, Groups, Hangouts, Hangouts Meet, Keep, Sites, Sheets, Classic Sites, Slides, Vault

  • Additional Google Products:

    Admin Console, App Maker, Chrome Device Management, Chrome Sync, Cloud Identity, Apps Script, Google Now, Hangouts Chat, Inbox by Gmail, Jamboard, Talk, Tasks

  • Google Product APIs:

    Apps Activity API, Calendar API, Contacts API, Drive Rest API, Gmail Rest API, Sheets API, Sites API, Tasks API

  • G Suite Admin SDK:

    Admin Settings API, Calendar Resource API, Domain Shared Contacts API, Directory API, Email Audit API, Email Settings API, Enterprise License Manager API, Groups Migration API, Groups Settings API, Reports API, SAML-based SSO API, Reseller API

Related Documentation

Additional Resources

Tags

Certification Africa Asia Pacific Europe USA Education Financial Services Gaming Government Healthcare/Life Sciences Media/Entertainment Retail
Back