Course Overview
Look in depth at what it takes to manage information security in Cloud services based on the ISO 27017:2015 standard. Build on your understanding of how to implement and audit an ISMS, and dive into the details of implementing and auditing security controls for systems in the Cloud based on ISO 27017. Learn a robust and thorough way to implement and audit controls for any Cloud-based components of your ISMS. You know about creating an ISMS from the ISO 27017 perspective, you’ve refined that for cyber security with ISO 27002, and now you can take this one step further with Cloud security controls. Deepen your cyber security knowledge with this course plus exam package.
Course Content
ISO 27017 builds upon ISO 27001, specifically addressing cloud computing security. It provides guidelines for both cloud service providers and cloud service customers. This training will cover the following topics:
- The roles and relationships between Cloud service customers and cloud service providers
- The scope of ISO/IEC 27017 and its compliance aspects
- Extending ISO 27002 to cover policies for Cloud service providers
- Extending ISO 27002 Clause 6 to cover relationships between parties including authorities
- The requirements of Clause 7.2.2 to include training on and awareness of Cloud security issues
- Identifying security risks and the relevant mitigating controls.
- The security boundaries of SaaS, PaaS and IaaS
- Extending controls 8–12 of ISO 27002 to include relevant parties in Cloud services
Course Benefits
By attending this course, you will deepen your understanding to use Cloud security terminology confidently, analysing environments, contracts, and processes with authority
Assessment
Certified ISO 27017 CIS CCS Cloud Controls Specialist (CIS CCS) exam
Candidates take the CIS CCS exam set by IBITGQ (International Board for IT Governance Qualifications) at the end of the course.
Delivery method: Online
Duration: 60 minutes
Questions: 40
Format: Multiple choice
There is no extra charge for this exam.
Prerequisites
You will need an advanced understanding of ISO/IEC 27002:2013 and a practical understanding of how to implement and audit an ISMS. Ideally, you will have trained as an ISO 27001 Lead Auditor or Lead Implementer.
We recommend purchasing and reading the following standard before attending the course:
ISO 27001/ISO 27002 - A guide to information security management systems
Next Steps
If you are interested in taking the course online, please register your interest through the ‘Register Interest’ button on the right hand side of this page, and we will contact you with the information you need to start your on-line training journey