As the use of cloud computing grows constantly, so does the need to ensure cloud security. Data breaches and other forms of attacks happen mainly as a result of poor security practices, complicated controls, and misconfigurations. This makes cloud security essential to the effective operation of cloud services.
Organisations adopting cloud technology must ensure that the level of security of their cloud systems meets their requirements and complies with the applicable laws and regulations.
This training course is designed to help participants acquire the knowledge and skills needed to support an organisation with this skill. It helps you with effectively planning, implementing, managing, monitoring, and maintaining a cloud security program based on ISO/IEC 27017 and ISO/IEC 27018. Training includes the following:
- Cloud computing concepts and principles;
- Cloud computing security risk management;
- Cloud-specific controls;
- Cloud security incident management; and
- Cloud security testing.
Fees
COURSE OUTLINES
Day 1: Introduction to ISO/IEC 27017 and ISO/IEC 27018, and the initiation of a cloud security program
- Training course objectives and structure
- Standards and regulatory frameworks
- Fundamental cloud computing concepts and principles
- Understanding the organisation’s cloud computing architecture
- Information security roles and responsibilities related to cloud computing
- Information security policy for cloud computing
Day 2: Cloud computing security risk management and cloud-specific controls
- Cloud computing security risk management
- Selection and design of cloud-specific controls
- Implementation of cloud-specific controls (part 1)
- Implementation of cloud-specific controls (part 2)
- Documented information management in the cloud
- Cloud security awareness and training
Day 4: Cloud security incident management, testing, monitoring, and continual improvement
- Cloud security incident management
- Cloud security testing
- Monitoring, measurement, analysis, and evaluation
- Continual improvement
- Closing of the training course
Domain 1: Fundamental principles and concepts of cloud computing
Domain 2: Information security policy for cloud computing and documented information management
Domain 3: Cloud computing security risk management
Domain 4: Cloud-specific controls based on ISO/IEC 27017 and ISO/IEC 27018 and best practices
Domain 5: Cloud security awareness, training, roles, and responsibilities
Domain 6: Cloud security incident management
Domain 7: Cloud security testing, monitoring, and continual improvement
COURSE DETAILS
- Participants will be provided with the training course material containing over 500 pages of explanatory information, examples, best practices, exercises, and quizzes.
- In case of exam failure, you can retake the exam within 12 months for free.
- Gain a comprehensive understanding of the concepts, approaches, methods, and techniques used for the implementation and effective management of a cloud security program.
- Acknowledge the correlation between ISO/IEC 27017, ISO/IEC 27018, and other standards and regulatory frameworks.
- Gain the ability to interpret the guidelines of ISO/IEC 27017 and ISO/IEC 27018 in the specific context of an organisation.
- Develop the necessary knowledge and competence to support an organisation in effectively planning, implementing, managing, monitoring, and maintaining a cloud security program.
- Acquire the practical knowledge to advise an organisation in managing a cloud security program by following best practices.
PREREQUISITES
The main requirement for participating in this training course is having a fundamental understanding of ISO/IEC 27017 and ISO/IEC 27018 and a general knowledge of cloud computing concepts.