Standards, Regulations & Certifications
To help you with compliance and reporting, we share information, best practices, and easy access to documentation. Our products regularly undergo independent verification of security, privacy, and compliance controls, achieving certifications against global standards to earn your trust. We’re constantly working to expand our coverage.
ISO 27017
Controlling cloud-based information security.
The International Organization for Standardization (ISO) is an independent, non-governmental international organization with a membership of 163 national standards bodies.
The ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:
- Additional implementation guidance for relevant controls specified in ISO/IEC 27002
- Additional controls with implementation guidance that specifically relate to cloud services
This standard provides controls and implementation guidance for both cloud service providers (like Google) and our cloud service customers.
ISO 27017 provides cloud-based guidance on 37 of the controls in ISO 27002 but also features seven new cloud controls that address the following:
- Who is responsible for what between the cloud service provider and the cloud customer
- The removal/return of assets when a contract is terminated
- Protection and separation of the customer’s virtual environment
- Virtual machine configuration
- Administrative operations and procedures associated with the cloud environment
- Cloud customer monitoring of activity within the cloud
- Virtual and cloud network environment alignment
Google Cloud Platform and G Suite are certified as ISO 27017 compliant.
Google Cloud services that are in scope for ISO 27017:
Google Cloud Platform:
- Access Context Manager
- App Engine
- App Engine Flexible Environment
- BigQuery
- BigQuery Data Transfer Service
- Cloud Armor
- Cloud Bigtable
- Cloud Billing API
- Google Cloud CDN (Content Delivery Network)
- Cloud Console
- Cloud Console Mobile App
- Cloud Dataflow
- Cloud Datalab
- Cloud Dataproc
- Cloud Datastore
- Cloud Deployment Manager
- Cloud DNS (Domain Name System)
- Cloud Endpoints
- Cloud Firestore
- Cloud Functions
- Cloud Healthcare API
- Cloud Identity & Access Management
- Cloud Identity-Aware Proxy
- Cloud Interconnect
- Cloud IoT Core
- Cloud Job Discovery
- Cloud Key Management Service
- GCP Marketplace
- Cloud Load Balancing
- Cloud Machine Learning Engine
- Cloud Natural Language API
- Cloud Pub/Sub
- Cloud Resource Manager
- Cloud Router
- Cloud SDK
- Cloud Security Scanner
- Cloud Shell
- Cloud Source Repositories
- Cloud Spanner
- Cloud Speech-to-Text
- Cloud SQL
- Cloud Storage
- Cloud Storage Transfer Service
- Cloud Translation API
- Cloud Video Intelligence API
- Cloud Vision API
- Cloud VPN
- Compute Engine
- Cloud Build
- Container Registry
- Data Loss Prevention API
- Dialogflow Enterprise Edition
- Genomics
- Google Service Control
- Kubernetes Engine
- Orbitera
- Persistent Disk
- Service Consumer Management API
- Service Management API
- Stackdriver Debugger
- Stackdriver Error Reporting
- Stackdriver Logging
- Stackdriver Profiler
- Stackdriver Trace
- Virtual Private Cloud (VPC)
G Suite:
- Calendar
- Classic Sites
- Classroom (Only for G Suite for Education)
- Chrome Sync (Only for G Suite for Education)
- Cloud Search
- Contacts
- Docs
- Drive
- Forms
- Gmail
- Google+
- Groups
- Hangouts
- Hangouts Meet
- Hangouts Meet
- Jamboard
- Keep
- Sheets
- Sites
- Slides
- Talk
- Vault
Additional Google Products:
- Admin Console
- App Maker
- Cloud Identity
- Google Apps Script
- Google Earth
- Google Now
- Google Translate
- Hire
- Inbox by Gmail
- Mobile Device Management
- Tasks
- Voice
Google Product APIs:
- Apps Activity API
- Calendar API
- Contacts API
- Drive Rest API
- Gmail Rest API
- Sheets API
- Sites API
- Tasks API
G Suite Admin SDK:
- Admin Settings API
- Apps Email Audit API
- Domain Shared Contacts API
- Directory API
- Email Settings API
- Enterprise License Manager API
- Groups Migration API
- Groups Settings API
- Reports API
- SAML-based SSO API
- Reseller API
Service / Dependency :
- Gmail Delivery
- Gmail Frontend / Middleware
- Gmail Medley
- Gmail Spam