COURSE OBJECTIVE:
• Gain a comprehensive understanding of the concepts, approaches, methods, and techniques used for the implementation and effective management of a cloud security program
• Acknowledge the correlation between ISO/IEC 27017, ISO/IEC 27018, and other standards and regulatory frameworks
• Gain the ability to interpret the guidelines of ISO/IEC 27017 and ISO/IEC 27018 in the specific context of an organization
• Develop the necessary knowledge and competence to support an organization in effectively planning, implementing, managing, monitoring, and maintaining a cloud security program
• Acquire the practical knowledge to advise an organization in managing a cloud security program by following best practices
TARGET AUDIENCE:
• Cloud security and information security professionals seeking to manage a cloud security program
• Managers or consultants seeking to master cloud security best practices
• Individuals responsible for maintaining and managing a cloud security program
• Technical experts seeking to enhance their cloud security knowledge
• Cloud security expert advisors
COURSE PREREQUISITES:
• The main requirement for participating in this training course is having a fundamental understanding of ISO/IEC 27017 and ISO/IEC 27018 and a general knowledge of cloud computing concepts.
COURSE CONTENT:
Day 1: Introduction to ISO/IEC 27017 and ISO/IEC 27018 and the initiation of a cloud security program
• Training course objectives and structure
• Standards and regulatory frameworks
• Fundamental cloud computing concepts and principles
• Understanding the organization's cloud computing architecture
• Information security roles and responsibilities related to cloud computing
• Information security policy for cloud computing
Day 2: Cloud computing security risk management and cloud-specific controls
• Cloud computing security risk management
• Selection and design of cloud-specific controls
• Implementation of cloud-specific controls (part 1)
Day 3: Documented information management and cloud security awareness and training
• Implementation of cloud-specific controls (part 2)
• Documented information management in the cloud
• Cloud security awareness and training
Day 4: Cloud security incident management, testing, monitoring, and continual improvement
• Cloud security incident management
• Cloud security testing
• Monitoring, measurement, analysis, and evaluation
• Continual improvement
• Closing of the training course
FOLLOW ON COURSES:
Not available. Please contact.