Cybersecurity · 2025 · 08 months per client project
ISO 27017 & ISO 27018 Cloud Security & Privacy Implementation
"100% certification success across SaaS and cloud service providers."
Role
GRC Analyst & Project Manager
Industry
Cybersecurity, Tech, SaaS, Legal, Early-Stage Tech, EdTech
Tools
Shared responsibility matrices, Privacy controls, Evidence trackers
Overview
Led end-to-end consulting and implementation for ISO 27017 (Cloud Security Controls) and ISO 27018 (Protection of PII in Public Clouds) for SaaS and cloud service providers. The focus was designing, implementing and operationalising secure, privacy-focused cloud environments aligned to fast-paced SaaS release cycles.
Challenges
- Lack of cloud-specific security and privacy controls beyond baseline ISO 27001.
- Mapping and implementing additional ISO 27017 (~7 unique + 37 extended) and ISO 27018 (25 privacy) controls.
- Concurrent delivery across multiple clients with tight audit deadlines.
- Limited internal awareness of cloud risk, PII handling and audit evidence requirements.
Approach & Solution
- Conducted gap assessments, defined cloud and PII scopes, and tailored roadmaps.
- Supported risk identification, treatment planning and shared responsibility mapping.
- Developed full documentation suites including policies, procedures, SOPs, registers and privacy notices.
- Standardised templates and trackers to streamline evidence collection.
- Coordinated control implementation with cloud engineers, developers and compliance teams.
- Delivered practical security, cloud security and privacy awareness training.
Results
- All managed projects achieved successful ISO 27017 and ISO 27018 certification.
- Strong auditor feedback on control relevance, documentation clarity and SaaS operational fit.
- Clients gained competitive advantage and elevated security and privacy culture.
Next case study
Long-Term Client Delivery & SLA Management (UK Client)