Course Overview
Learn about implementing the data privacy security controls in public Clouds as per the ISO 27018:2019 standard, which concerns the protection of PII (personally identifiable information) in public Clouds for those acting as PII processors. This course looks in-depth at how data protection and data privacy are secured in Cloud environments.
Course Content
ISO 27018 narrows its focus to the protection of personally identifiable information (PII) in public cloud environments. It provides a code of practice for cloud service providers processing PII. This training will cover the following topics:
- Key EU, UK and other privacy regulations and laws
- The roles and responsibilities of data processors and controllers
- Key terminology and concepts as used in different standards and regulations
- Risk scenarios and the limits of mitigating controls
- How ISO 27002 applies to cover PII in the public Cloud
- The detailed obligations of a public Cloud PII processor
- Relevant access control, access management and cryptography operations
- Protection of data at rest including backup and restoration
- Incident management for PII in the Cloud
- Performing information security reviews via audit services and other means
Course Benefits
By attending this course, you will deepen your understanding so you can use the terminology of data privacy and data protection confidently, analysing environments, contracts and processes with confidence.
Assessment
Certified ISO 27018:2019 CIS CPS Cloud Privacy Specialist (CIS CPS) exam
Candidates take the CIS CCS exam set by IBITGQ (International Board for IT Governance Qualifications) at the end of the course.
Delivery method: Online
Duration: 60 minutes
Questions: 40
Format: Multiple choice
There is no extra charge for this exam.
Prerequisites
You will need an advanced understanding of ISO/IEC 27002:2013 and a practical understanding of how to implement and audit an ISMS. Ideally, you will have trained as an ISO 27001 Lead Auditor or Lead Implementer.
We recommend purchasing and reading the following standard before attending the course:
The EU Data Protection Code of Conduct for Cloud Service Providers – A guide to compliance
Next Steps
If you are interested in taking the course online, please register your interest through the ‘Register Interest’ button on the right hand side of this page, and we will contact you with the information you need to start your on-line training journey.