This standard is part of the ISO 27000 series of standards for Information Security. ISO 27017: 2015 is based on ISO 27002 for cloud services. The standard provides procedures specifically around cloud computing and is used by organisations that use cloud services and by cloud service providers. As this is a risk assessment-based standard selecting the controls and measures can depend on any legal, contractual, regulatory or other cloud-sector specific information security requirements.