Course Outline
Introduction to ISO 27017
- Overview of ISO/IEC 27017
- Relation to ISO 27001 and ISO 27002
- Importance of cloud security governance
Cloud Security Risks and Threats
- Common security risks in cloud environments
- Cloud-based attack vectors
- Risk assessment methodologies for cloud services
Key Information Security Controls in ISO 27017
- Additional cloud-specific controls
- Shared security responsibilities between CSPs and customers
- Data protection and encryption in the cloud
Implementing Cloud Security Policies
- Defining security policies for cloud adoption
- Access control and identity management
- Security incident management in the cloud
Compliance and Regulatory Considerations
- Legal and regulatory implications of cloud security
- Mapping ISO 27017 to GDPR, HIPAA, and other regulations
- Cloud compliance audits and certification processes
Best Practices for Cloud Security
- Security monitoring and threat detection
- Implementing continuous improvement in cloud security
- Ensuring resilience and disaster recovery
Hands-On Implementation and Case Studies
- Applying ISO 27017 controls in real-world scenarios
- Reviewing cloud security case studies
- Interactive exercises on cloud security strategy
Summary and Next Steps
Requirements
- Basic understanding of cloud computing
- Knowledge of general information security principles
- Familiarity with ISO 27001 or other cybersecurity frameworks
Audience
- Cloud security professionals
- IT security managers
- Compliance officers
- Cloud service providers
Testimonials (5)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
The quizzes to reinforce the reading and the ability to ask questions at any time
Jonathan
Course - ISO 9001 Lead Auditor
Speed of response and communication