GxPlex

ISO/IEC 27017

ISO/IEC 27017 — Information security controls for cloud services

Document status what the publisher asserts

withdrawn

No status read is recorded for this entry — this record has not read a publisher surface for it, which is a fact about this record and not about the publisher. A status read is recorded for 7 of 132 tracked entries, 5 of which banked a passage.

Evidence state what this record holds

verified by a person — a person checked this entry against the primary source on a recorded day

Publisher: ISO/IEC Last checked: Last read:
How this status is recorded
Recorded
withdrawn — no as-of date is recorded
Established by
A person confirmed this entry on 1 August 2026. A further check by a person is asserted on this row and the verification log does not corroborate that further check, which counts toward no verified total.
Evidence
In Current status on this page.
Published at
This record names no separate surface for the status. The primary source it holds is the primary source (opens in new tab). This entry's record is published in machine form at /api/v1/instruments.json.

Evidence ladder#

What this record holds for this entry, rung by rung, each mark derived from a field, a count or a stored reading. Rungs in the order the record acquires them, from what an entry is to what has been checked about it. The order is fixed; a rung’s position says nothing about any entry.

  1. held. identity an address that describes this document rather than a list it sits in This record holds an address that describes this document, and the names it is published under.
  2. held. publisher the body that published it The publishing body is recorded as ISO/IEC.
  3. held. jurisdiction the jurisdiction the publishing body belongs to The jurisdiction is recorded as International.
  4. held. type the class the document calls itself, quoted from its own title The document’s own title states a class, quoted on this page with the address it was read from.
  5. nothing held. current edition a statement of which edition or revision this record holds No reading of an edition or revision statement is recorded for this entry.
  6. nothing held. publication date a date the publisher states for this document No reading of a publication date is recorded for this entry.
  7. nothing held. lifecycle signal a stage, step or status wording read from a publisher surface No read of a publisher surface for a stage or status wording is recorded for this entry.
  8. nothing held. publisher notices official notices the publisher issued about this document No collection of publisher notices has succeeded: of 2 declared sources, 2 have never been attempted. The store holds nothing for any entry.
  9. held. observation history a dated series of what the publisher’s address returned This record holds 109 dated records for this entry, and every one of them is of the document it names.
  10. held in part. text prose retained from the retrieved bytes, against which a quotation can be checked The text is not public by licence, so it is not retrieved, hashed or diffed here; what is retrieved is the publisher’s own metadata page.
  11. held in part. diff a comparison of two retrievals of this document 37 retrievals of this document carry a digest, and the store records no retrieval differing from the one before it.
  12. held. verification a person’s check of this entry against the primary source A person checked this entry against the primary source; the day is recorded above.

held — this record holds it, and the sentence beside it names what from · nothing held — no reading of this rung is recorded — nobody has looked, which is not the same as looking and finding nothing · held in part — part of it is held, or it is held under a limit the sentence states

No rung on this entry carries a measured absence. That is not the same as every rung being held: 4 of the 12 rungs are marked as holding nothing, which records that no reading has run rather than that a reading found nothing.

What the evidence states

  • This record holds an address that describes this document, and the names it is published under.
  • The publishing body is recorded as ISO/IEC.
  • The jurisdiction is recorded as International.
  • The document’s own title states a class, quoted on this page with the address it was read from.
  • This record holds 109 dated records for this entry, and every one of them is of the document it names.
  • A person checked this entry against the primary source; the day is recorded above.

What it does not state

  • No reading of an edition or revision statement is recorded for this entry.
  • No reading of a publication date is recorded for this entry.
  • No read of a publisher surface for a stage or status wording is recorded for this entry.
  • No collection of publisher notices has succeeded: of 2 declared sources, 2 have never been attempted. The store holds nothing for any entry.
  • The text is not public by licence, so it is not retrieved, hashed or diffed here; what is retrieved is the publisher’s own metadata page.
  • 37 retrievals of this document carry a digest, and the store records no retrieval differing from the one before it.

Coverage contract#

Each term states what this record does for this entry and what it does not, derived from the entry’s own fields and its own series. It is a record of coverage, not a finding about the document.

Observed cadence how often this record has reached this entry’s address
Between consecutive days holding an observation the middle interval is 1 day and the longest is 2 days, between 2026-09-13 and 2026-09-15. The term this record declares for the entry is “weekly”.
Text: public, and retained whether the publisher’s text is public, and whether prose from it is kept here
The publisher’s text is restricted, and it is cited and linked rather than reproduced. Prose is retained from what was retrieved, and what was retrieved is a publisher surface about the document rather than the document: no text of the document itself is held here.
Hash what is digested for this entry, and of what
No digest here is of the document this entry names: its resolution is “metadata only”, which is the value that means no document is retrieved. Its series does carry 37 digest(s), of the publisher surface this entry fetches.
Status verification which check this record undertakes for the published status, and which it holds
This entry’s label asks for a person’s check, and its record is frozen, which takes it out of the queue that asks. A person’s confirmation is recorded, dated 2026-08-01.
Lifecycle tracked which lifecycle facts this record follows for this entry
This record follows no lifecycle fact for this entry: no effective date, no dated event, no archived version, no publisher stage record and no detected revision is held. That is what has been recorded here, not a reading of what exists. 36 of 132 tracked entries carry at least one such fact.
Known limits the limits this entry’s own record declares
3 of the 8 limits this record can record are set on this entry, and each is listed below with the field it was read from.

Why this entry is tracked#

The test an entry is admitted under is published in full, with its negative limb and its worked examples, at the inclusion rule. What this record holds about THIS entry's admission is below, each line naming the store it was read from.

Inclusion-rule limb which of the four limbs was applied
No field in this record names which limb an entry satisfies, so none is stated for this one. Membership was closed as a human judgment on 2026-08-11, and the four-limb test is applied by a person rather than by code. This entry’s own stated subject is not read as a limb: a title word standing in for a rule would be a classification this record authored.
Admission entry the dated act that added this entry
No admission entry is recorded for this entry. 21 of 132 tracked entries carry one, so an absence here is ordinary rather than a gap peculiar to this entry.
Declared tier-1 list a recorded judgement that this belongs
This entry is not a member of the declared tier-1 list. That list names 37 identifiers, of which 35 resolve to one of the 132 tracked entries, so most of the corpus sits outside it and non-membership says nothing about this entry on its own.
Admissions boundary the jurisdictions this record adds from
This entry’s jurisdiction is International. It is inside the admissions boundary ruled on 2026-08-16, which names 4 jurisdictions — EU · US · UK · International — and which is one of the two admission tests this record enforces in code. The other is that a candidate carry the publisher’s own address: a mention is not a citation.

Filed core. For that label this archive undertakes to put an entry's status to a person. The label records what this archive undertakes for a class of entries. It states no finding about this one, and it is not a ranking.

Frozen. The text is not public by licence, so it is not retrieved, hashed or diffed here. The publisher's own stage wording is quoted below, with the address it was read from. Why the text is not taken, and what is recorded instead.

Frozen does not mean abandoned. This entry is still fetched and hashed every day and its observation series continues; it is excluded only from the verification queue and from the unverified count, because a status that cannot be established is not outstanding work.

Access: robots.txt unreachable

Resolution: metadata only · no document resolved

What this archive can and cannot establish about this entry. The text is not public by licence. No document is hashed; the publisher page fetched for this row is hashed as part of the observation series; the publisher's own catalogue metadata is tracked instead.

Authority
ISO/IEC
Jurisdiction
International
Status
withdrawn
Effective date
Last changed
Last verified
Watch cadence
weekly
Crawlable
no
Text licence
restricted — cited and linked, never excerpted (paywalled standard)
Primary source
Primary source (opens in new tab) iso.org
Topics
security · information security

Current status#

Recorded as withdrawn against the primary source on 1 August 2026.

The text that supported that record, retrieved — by unknown:

Status : Withdrawn Stage : Withdrawal of International Standard [ 95.99 ]

What is not known#

The text of this document is published under a restrictive licence. It is cited and linked, never excerpted; change is reported by hash.

Cite this consensus standard

Each format carries the permalink and the date this consensus standard was observed. The observation date is part of the citation: the underlying source may have changed since.

Plain text

GxPlex. ISO/IEC 27017 — Information security controls for cloud services [consensus standard record]. Observed 19 September 2026. https://gxplex.com/r/iso-iec-27017 Primary source: https://www.iso.org/standard/43757.html

BibTeX

@misc{gxplexrisoiec27017,
  author       = {{GxPlex}},
  title        = {{ISO/IEC 27017 — Information security controls for cloud services}},
  year         = {2026},
  note         = {consensus standard record, observed 19 September 2026},
  howpublished = {\url{https://gxplex.com/r/iso-iec-27017}},
  urldate      = {2026-09-19},
  url          = {https://www.iso.org/standard/43757.html}
}

APA

GxPlex. (2026). ISO/IEC 27017 — Information security controls for cloud services [consensus standard record]. Retrieved 19 September 2026, from https://gxplex.com/r/iso-iec-27017

JSON

{
  "@context": "https://schema.org",
  "@type": "Dataset",
  "name": "ISO/IEC 27017 — Information security controls for cloud services",
  "publisher": "GxPlex",
  "url": "https://gxplex.com/r/iso-iec-27017",
  "temporalCoverage": "2026-09-19",
  "observation": {
    "url": "https://gxplex.com/observations/iso-iec-27017#obs-2026-09-19-1",
    "observedDate": "2026-09-19"
  },
  "isBasedOn": "https://www.iso.org/standard/43757.html"
}

observation.url addresses the single observation this citation rests on.

Every observation of this document is addressed and separately citable at the observation series.

Observation history#

Observed on 109 occasion(s) since 2026-07-31. 37 produced a content hash. No change to the retrieved text has been detected since observation began.

××···××××××××××××××·×××····××·×····×··××××··××××××··×××··×·×·××·××·××××××·×××××××××·×××·××·×·××····×·×·······

All 109 marks, one per observation, oldest first. · unchanged · ! content changed · ~ fetched but rendered client-side, no hash · × could not be fetched, no hash.

50 of 51 days from 2026-07-31 to 2026-09-19 hold an observation. 1 day holds none: 2026-09-14. A day with no observation is a day this record did not reach; it is not a statement about the publisher, and it is not counted as unchanged.

Each mark links to the single observation it stands for, at that observation’s own address. The whole series, with every address, is at /observations/iso-iec-27017. Any two of its retained observations can be set side by side at /compare/iso-iec-27017. The same evidence as a packet, with its refusals and its integrity reference, is at /packet/iso-iec-27017.

Every observation in this series is published, untruncated, at /api/v1/observations.json.

First observed
2026-07-31
Last observed
2026-09-19 (no response arrived)
Fetch method
withheld
Current hash
How this series is recorded
Recorded
observations: 109 · carrying a digest: 37 · changes detected: 0 · first observed: 2026-07-31
Method
resolution: metadata only · watch cadence: weekly · last fetch method: withheld
Evidence
The most recent record is addressed at 2026-09-19·1.
Published at
/observations/iso-iec-27017 — every record of this row, with its address. /api/v1/series.jsonl — the same records for every row, one line each. Each observation is addressed by this row’s identifier, the date it was observed, and its sequence within that date — the same key /api/v1/series.jsonl publishes as `sequence`, counted in the order the store recorded them.

Source health#

Counts and dates over a stated window. No figure here is a mark out of a hundred, no cell is ordered against another, and none of it is a statement about the publisher: a day this record did not reach is a fact about this record’s reach.

Fetch outcomes how the requests in the window answered
42 of 109 fetch records in the 90 calendar days ending carry no error. The 67 that carry one are recorded under blocked ×67. Of those, 37 produced a digest: a page that answers and is assembled in the browser answers without one.
Last fetched the most recent record in the whole series
— the latest day this record holds (). The method recorded is withheld. What that record returned is in Observation history above.
Address stability where the requests actually landed
34 record(s) in the window recorded the address that answered, across 1 distinct address(es). 75 further record(s) carry no answered address and say nothing either way. The most recent answered address is the one this entry declares.
Access posture what the publisher declares, and what the requests met
Declared: robots.txt unreachable · crawlable no . Met: 67 of 109 record(s) in the window were recorded as refused. A refusal is what one request of this record met on one day; it is not a policy the publisher stated.
Expected and observed cadence the declared term, the days held, and the days holding none
The term this record declares for this entry is weekly. Over its own window, to , 50 of 51 calendar days hold at least one observation. 1 hold none: 2026-09-14. Between consecutive days holding one, the middle interval is 1 and the longest is 2, counted in days — that longest one between 2026-09-13 and 2026-09-15. Both figures are stated and the difference between them is not adjudicated here.

Neighbourhood#

What sits around this entry, counted. Every figure below is drawn from a value already rendered elsewhere on this page; where a count has a list, the count is here and the list stays in the section holding its evidence.

The direct document, and the activity around it what this record’s observations of the document recorded inside a stated window, beside the official signals dated inside the same one
Each row is a window of calendar days ending , the day the source-health block above counts its own window to. Every column between the window and the official signals is drawn from the 109 observation(s) of the document this entry holds in total. An observation is counted here only where the class projection places it on the document this entry names.
Window Observations of the document Of those, carrying a digest Of those, carrying a change Direct document Official signals dated inside it
30 calendar days 44 13 0 no change in window 0 of 0
90 calendar days 109 37 0 no change in window 0 of 0
365 calendar days 109 37 0 no change in window 0 of 0

A window is marked changed where at least one observation of the document inside it recorded a change against the previous one; unchanged where the window holds at least one such observation, at least one of them carries a digest of the retrieved bytes, and none recorded a change; undigested where the window holds observations and none of them carries a digest, so no observation in it could be compared with another; and unmeasured where the window holds no observation at all. The word is shorthand for the three counts printed beside it and adds nothing to them. It is a statement about the window and never about the document outside it, which is why a window reaching back before the first observation says so underneath. A mark is derived from the observations a window holds and never from the days it spans; which days inside this entry’s own window hold none is stated by the coverage sentence in Observation history above.

The first observation of the document this entry names is . These windows reach back before it — 90 calendar days · 365 calendar days — so part of the span each names was never watched, and a window with no change inside it says nothing about the days before that first observation.

no change in window — this window holds observations of the document and none of them recorded a change — which is a statement about the window, not about the document outside it

No word is attached to the signal count beside it, and none will be. Any word for the size of a count needs either a threshold this record would have authored or a comparison against other entries that would rank the sources against one another; the count and its window are the whole claim. The document column beside it carries a word only because the rule reaching it is printed underneath and can be checked against the counts it stands for.

The last column holds no member on this entry. The zero it holds is named under “Around it” below.

Around it official signals naming this entry, by the class their publisher stated
The signal store holds no record for any entry, so nothing here is an absence measured on this one. The store’s own state is no source attempted, and what that state means for every count drawn from the store is stated at the signals index.
Related sources other entries reachable from this one by a relation a publisher states
This record publishes no relation from or to this entry. A relation is published only where a publisher states it, so this is the absence of a statement this record has read and not a claim that none exists.
Related standards which of those entries call themselves a standard, in their own publisher’s word
No published relation from this entry reaches an entry this record tracks, so there is nothing to place on this axis. That is a statement about what this record can read, not about what exists.
Topics the controlled identifiers this entry carries, and the voice each one is in
2 identifier(s), minted by the convention published at /conventions. The values themselves are not listed again here; what this adds is the identifier and the voice it is in. 2 come(s) from a term this document’s own publisher states about it, quoted with its citation lower on this page: topic.security · topic.information-security.
Before, now and next where the record’s day sits among the publisher-dated facts this entry holds
This entry holds no publisher-dated lifecycle fact, so no position can be derived. What is absent is a dated statement this record has read.

Next holds the publisher-dated facts this record already carries that fall after the day this record calls today — a stated effective date, a consultation close. Nothing is projected and no step is inferred from a lifecycle: where a publisher has stated no further date, the cell says so, and what is absent is a statement rather than a future.

Subject and class (as stated)

The words this document uses about itself, matched verbatim against its own title. Not a statement of scope, and not a judgment about which organisations or products fall under it: each value quotes the span it was read from and links to where that span was read.

Change history

Sources#

Listed primary first, then the further addresses this record holds for this entry, then the route it was found by, then dated third-party copies. Repeated URLs appear once, at their first position.

Last updated: