What it is
What ISO 27017 is
ISO/IEC 27017 is a code of practice for information security in cloud services. It does two things: it gives cloud-specific implementation guidance for controls you already know from ISO 27002, and it adds controls that only exist because the service is cloud - segregation in virtual environments, administrator operations, monitoring, and the return or removal of assets when a contract ends.
It is written for both sides. A cloud service customer and a cloud service provider read the same control and each has their own part of it, which is the point of the standard.
The shared responsibility boundary is the whole exercise
Most cloud security findings are not a control that failed. They are a control that both parties assumed the other one owned. ISO 27017 exists to make that boundary explicit, and the useful output of applying it is a documented division of responsibility you can show an auditor and hand to a customer.
It is guidance, not a certification
There is no standalone ISO 27017 certificate. It extends an ISO 27001 ISMS, and the controls you adopt from it become part of your Statement of Applicability.
The controls that only exist because it is cloud
Alongside the cloud-specific guidance on familiar controls, ISO 27017 adds a small set that has no on-premises equivalent. They cover the shared roles and responsibilities between customer and provider, the removal or return of customer assets when a service ends, the separation of customers in a shared virtual environment, hardening of virtual machines, administrator operations that could affect many customers at once, monitoring that the customer can actually see, and alignment of the virtual and physical networks.
Read as a group, they are a list of the things that go wrong specifically because a service is multi-tenant and someone else runs it. That is a useful way to approach them: not extra paperwork, but the failure modes the model introduces.