Skedmia

Documentation kit

ISO/IEC 27017:2026 Complete Documentation Kit + Internal Auditor Training

In preparation — 67 documents for cloud information security controls, with a complete internal-auditor training pack.

ISO/IEC 27017:2026 — Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services

In preparation. This kit is being written now and is not yet available to download. Tell us you want it and we will send it to you the day it is released — and hold the current price for you.

Every document you need to implement Cloud Information Security Controls to ISO/IEC 27017:2026 and evidence it, written by our lead auditors and supplied as editable Microsoft Word files in an organised folder tree. Replace the highlighted placeholders with your own details and the system is yours — no blank pages, no guessing what an auditor expects.

What it will contain

  • 00 Read Me First — Kit guide and implementation roadmap, document master list, clause cross-reference matrix
  • 01 Manual — 5 manual documents covering every clause
  • 02 Policies — 3 policies
  • 03 Procedures — 21 procedures
  • 04 Forms, Registers & Templates — 18 forms and registers
  • 05 Plans & Programmes — 5 plans
  • 06 Checklists — 4 checklists including gap analysis and internal audit
  • 07 Internal Auditor Training Pack — 8 documents: handbook, trainer's guide, slides outline, exercises, 30-question exam and answer key, course forms

67 documents in total, as planned in the kit's document manifest.

How it is written

Each procedure states the steps, the responsible roles, the frequencies and the records produced, so it can be followed on the day you buy it. Every requirement of the standard is mapped to a document in the clause cross-reference matrix — so you can show an assessor where each requirement is met. Auditor notes flag what assessors look for and the nonconformities that come up most often.

Internal auditor training included

This edition adds a complete internal-auditor (IQA) training pack: a participant handbook covering the standard clause by clause from an auditor's viewpoint, a trainer's guide with a two-day agenda, a slide outline, exercises with model answers, a 30-question examination with its marking scheme, and the course records.

Licence

Supplied for the internal use of one organisation, with unlimited internal copies and edits. Not for resale or redistribution outside your organisation.

Please note

ISO/IEC 27017:2026 is the second edition, published 27 July 2026, which supersedes and withdraws ISO/IEC 27017:2015. It gives cloud-specific guidance for the ISO/IEC 27002:2022 controls, plus four extended cloud controls — the first edition was keyed to ISO/IEC 27002:2013 and carried seven. It carries no certificate of its own: conformity is demonstrated by certifying an ISO/IEC 27001 information security management system whose Statement of Applicability brings the cloud controls into scope. This kit is written as an extension pack for an existing or planned ISO/IEC 27001 system, not as a standalone management system.

More from the e-shop