Course description
This course provides detailed guidance on implementing ISO/IEC 27017:2015, the international standard for information security controls in cloud computing environments. As a security extension to ISO/IEC 27001 and ISO/IEC 27002, this standard offers additional controls and implementation advice specifically for cloud service providers (CSPs) and cloud service customers (CSCs). Participants will learn how to identify cloud-specific risks, implement appropriate controls, and manage shared responsibilities effectively in a cloud environment.
What You’ll Learn
By the end of the course, you will be able to:
-
Understand the purpose, structure, and scope of ISO/IEC 27017:2015.
-
Identify the differences and alignment with ISO/IEC 27001 and 27002.
-
Recognize the shared responsibility model in cloud computing.
-
Implement the 7 additional controls and 37 enhanced guidelines specific to cloud services.
-
Address cloud-specific risks including multi-tenancy, virtualization, and legal jurisdiction.
-
Develop clear roles and responsibilities between CSPs and CSCs.
-
Manage cloud service agreements, SLAs, and third-party assurance requirements.
-
Ensure compliance with data privacy, availability, and integrity expectations in the cloud.
-
Strengthen incident response, backup, and business continuity in cloud-based environments.
-
Prepare for audits or certifications that require cloud security assurances.
Who Should Attend
-
Information Security Managers and CISOs
-
Cloud Service Providers (IaaS, PaaS, SaaS)
-
IT Risk and Compliance Officers
-
Data Privacy and Governance Professionals
-
Cloud Architects and DevSecOps Teams
-
Consultants implementing ISO 27001 in cloud environments
Recommendations
-
Familiarity with cloud computing models and ISO/IEC 27001 is helpful
-
No prior experience with ISO 27017 is required
-
Ideal for organizations migrating to or managing cloud-based infrastructure
Skills
-
ISO/IEC 27017 clause interpretation and implementation
-
Cloud-specific risk identification and control design
-
CSP/CSC role delineation
-
Security in virtualization and multitenant environments
-
Data lifecycle protection in cloud services
-
Secure configuration and administrative operations
-
SLA and contractual security alignment
-
Incident management in cloud infrastructure
-
Integration with ISO/IEC 27001 and 27002