ISO 27017: Information Security Controls for Cloud Services Training Course
ISO/IEC 27017 is an international standard that provides guidelines for information security controls specific to cloud services. It builds upon ISO/IEC 27002 and enhances security measures tailored for cloud computing environments.
This instructor-led, live training (online or onsite) is aimed at intermediate-level IT and security professionals who wish to implement ISO 27017 controls to enhance cloud security and compliance.
By the end of this training, participants will be able to:
- Understand the principles and objectives of ISO 27017.
- Identify key security controls specific to cloud environments.
- Implement ISO 27017 controls within cloud service providers and cloud customers.
- Align cloud security strategies with ISO 27001 requirements.
- Ensure compliance with international cloud security best practices.
Format of the Course
- Interactive lecture and discussion.
- Lots of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Introduction to ISO 27017
- Overview of ISO/IEC 27017
- Relation to ISO 27001 and ISO 27002
- Importance of cloud security governance
Cloud Security Risks and Threats
- Common security risks in cloud environments
- Cloud-based attack vectors
- Risk assessment methodologies for cloud services
Key Information Security Controls in ISO 27017
- Additional cloud-specific controls
- Shared security responsibilities between CSPs and customers
- Data protection and encryption in the cloud
Implementing Cloud Security Policies
- Defining security policies for cloud adoption
- Access control and identity management
- Security incident management in the cloud
Compliance and Regulatory Considerations
- Legal and regulatory implications of cloud security
- Mapping ISO 27017 to GDPR, HIPAA, and other regulations
- Cloud compliance audits and certification processes
Best Practices for Cloud Security
- Security monitoring and threat detection
- Implementing continuous improvement in cloud security
- Ensuring resilience and disaster recovery
Hands-On Implementation and Case Studies
- Applying ISO 27017 controls in real-world scenarios
- Reviewing cloud security case studies
- Interactive exercises on cloud security strategy
Summary and Next Steps
Requirements
- Basic understanding of cloud computing
- Knowledge of general information security principles
- Familiarity with ISO 27001 or other cybersecurity frameworks
Audience
- Cloud security professionals
- IT security managers
- Compliance officers
- Cloud service providers
Open Training Courses require 5+ participants.
ISO 27017: Information Security Controls for Cloud Services Training Course - Booking
ISO 27017: Information Security Controls for Cloud Services Training Course - Enquiry
ISO 27017: Information Security Controls for Cloud Services - Consultancy Enquiry
Consultancy Enquiry
Testimonials (4)
The fact that all the standard was reviewed and discussed with some examples, when needed and required.
Ioana
Course - ISO/IEC 27005 Information Security Risk Management
The training was well put together & very informative.
Siobhan Kavanagh - SEEC MM Ltd.,
Course - ISO 9001 Lead Implementer
The quizzes to reinforce the reading and the ability to ask questions at any time
Jonathan
Course - ISO 9001 Lead Auditor
Dereck's overall preparedness . Dereck has great communications' skills !!
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
Upcoming Courses
Related Courses
ISO 22000 Certification: Food Safety Management Systems
14 HoursThis instructor-led, live training in Serbia (online or onsite) is aimed at intermediate-level to advanced-level professionals in the food industry who wish to understand, implement, and achieve ISO 22000 certification.
By the end of this training, participants will be able to:
- Understand the principles and requirements of ISO 22000.
- Implement a Food Safety Management System (FSMS).
- Identify and manage food safety hazards using HACCP principles.
- Prepare for ISO 22000 certification audits.
- Ensure compliance with international food safety regulations.
PECB ISO/IEC 27001 Foundation
14 HoursWhy should you attend?
ISO/IEC 27001 Foundation training allows you to learn the basic elements to implement and manage an Information Security Management System as specified in ISO/IEC 27001. During this training course, you will be able to understand the different modules of ISMS, including ISMS policy, procedures, performance measurements, management commitment, internal audit, management review and continual improvement.
After completing this course, you can sit for the exam and apply for the “PECB Certified ISO/IEC 27001 Foundation” credential. A PECB Foundation Certificate shows that you have understood the fundamental methodologies, requirements, framework and management approach.
Who should attend?
- Individuals involved in Information Security Management
- Individuals seeking to gain knowledge about the main processes of Information Security Management Systems (ISMS)
- Individuals interested to pursue a career in Information Security Management
Educational approach
- Lecture sessions are illustrated with practical questions and examples
- Practical exercises include examples and discussions
- Practice tests are similar to the Certification Exam
PECB ISO/IEC 27001 Lead Auditor
35 HoursISO/IEC 27001 Lead Auditor
ISO/IEC 27001 Lead Auditor training enables you to develop the necessary expertise to perform an Information Security Management System (ISMS) audit by applying widely recognized audit principles, procedures and techniques.
Why should you attend?
During this training course, you will acquire the knowledge and skills to plan and carry out internal and external audits in compliance with ISO 19011 and ISO/IEC 17021-1 certification process.
Based on practical exercises, you will be able to master audit techniques and become competent to manage an audit program, audit team, communication with customers, and conflict resolution.
After acquiring the necessary expertise to perform this audit, you can sit for the exam and apply for a “PECB Certified ISO/IEC 27001 Lead Auditor” credential. By holding a PECB Lead Auditor Certificate, you will demonstrate that you have the capabilities and competencies to audit organizations based on best practices.
Who should attend?
- Auditors seeking to perform and lead Information Security Management System (ISMS) certification audits
- Managers or consultants seeking to master an Information Security Management System audit process
- Individuals responsible for maintaining conformance with Information Security Management System requirements
- Technical experts seeking to prepare for an Information Security Management System audit
- Expert advisors in Information Security Management
Learning objectives
- Understand the operations of an Information Security Management System based on ISO/IEC 27001
- Acknowledge the correlation between ISO/IEC 27001, ISO/IEC 27002 and other standards and regulatory frameworks
- Understand an auditor’s role to: plan, lead and follow-up on a management system audit in accordance with ISO 19011
- Learn how to lead an audit and audit team
- Learn how to interpret the requirements of ISO/IEC 27001 in the context of an ISMS audit
- Acquire the competencies of an auditor to: plan an audit, lead an audit, draft reports, and follow-up on an audit in compliance with ISO 19011
Educational approach
- This training is based on both theory and best practices used in ISMS audits
- Lecture sessions are illustrated with examples based on case studies
- Practical exercises are based on a case study which includes role playing and discussions
- Practice tests are similar to the Certification Exam
ISO/IEC 27005 Lead Risk Manager
35 HoursISO/IEC 27005 Lead Risk Manager training enables you to acquire the necessary expertise to support an organization in the risk management process related to all assets of relevance for Information Security using the ISO/IEC 27005 standard as a reference framework. During this training course, you will gain a comprehensive knowledge of a process model for designing and developing an Information Security Risk Management program. The training will also contain a thorough understanding of best practices of risk assessment methods such as OCTAVE, EBIOS, MEHARI and harmonized TRA. This training course supports the implementation process of the ISMS framework presented in the ISO/IEC 27001 standard.
After mastering all the necessary concepts of Information Security Risk Management based on ISO/IEC 27005, you can sit for the exam and apply for a “PECB Certified ISO/IEC 27005 Lead Risk Manager” credential. By holding a PECB Lead Risk Manager Certificate, you will be able to demonstrate that you have the practical knowledge and professional capabilities to support and lead a team in managing Information Security Risks.
Who should attend?
- Information Security risk managers
- Information Security team members
- Individuals responsible for Information Security, compliance, and risk within an organization
- Individuals implementing ISO/IEC 27001, seeking to comply with ISO/IEC 27001 or individuals who are involved in a risk management program
- IT consultants
- IT professionals
- Information Security officers
- Privacy officers
Examination - Duration: 3 hours
The “PECB Certified ISO/IEC 27005 Lead Risk Manager” exam fully meets the requirements of the PECB Examination and Certification Programme (ECP). The exam covers the following competency domains:
- Domain 1 Fundamental principles and concepts of Information Security Risk Management
- Domain 2 Implementation of an Information Security Risk Management program
- Domain 3 Information security risk assessment
- Domain 4 Information security risk treatment
- Domain 5 Information security risk communication, monitoring and improvement
- Domain 6 Information security risk assessment methodologies
General Information
- Certification fees are included on the exam price
- Training material containing over 350 pages of information and practical examples will be distributed
- A participation certificate of 21 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months for free
PECB ISO/IEC 42001 Lead Auditor
35 HoursISO/IEC 42001 Lead Auditor training course enables you to gain the necessary expertise to audit artificial intelligence management systems (AIMS) by applying widely recognized audit principles, procedures, and techniques.
PECB ISO 9001 Foundation
14 HoursISO 9001 Foundation training enables you to learn the basic elements to implement and manage a Quality Management System (QMS) as specified in ISO 9001. During this training course, you will be able to understand the different modules of a QMS, including QMS policy, procedures, performance measurements, management commitment, internal audit, management review and continual improvement.
After completing this course, you can sit for the exam and apply for a “PECB Certified ISO 9001 Foundation” credential. A PECB Foundation Certificate shows that you have understood the fundamental methodologies, requirements, framework and management approach.
Who should attend?
- Individuals involved in Quality Management
- Individuals seeking to gain knowledge about the main processes of Quality Management Systems (QMS)
- Individuals interested to pursue a career in Quality Management
The “PECB Certified ISO 9001 Foundation” exam fully meets the requirements of the PECB Examination and Certification Programme (ECP). The exam covers the following competency domains: h Domain 1: Fundamental principles and concepts of a Quality Management System (QMS) h Domain 2: Quality Management System (QMS)
Upon the successful completion of the exam, you can apply for the “PECB Certified ISO 9001 Foundation” credential.
General Information
Certification fees are included on the exam price
Training material containing over 200 pages of information and practical examples will be distributed
A participation certificate of 14 CPD (Continuing Professional Development) credits will be issued
In case of exam failure, you can retake the exam within 12 months for free
PECB ISO 9001 Lead Auditor
35 HoursThe ISO 9001 Lead Auditor training enables you to develop the necessary expertise to perform a Quality Management System (QMS) audit by applying widely recognized audit principles, procedures and techniques. During this training course, you will acquire the knowledge and skills to plan and carry out internal and external audits in compliance with ISO 19011 and the certification process according to ISO/IEC 17021-1.
Based on practical exercises, you will be able to master the audit techniques and become competent to manage an audit program, audit team, communication with customers, and conflict resolution.
After acquiring the necessary expertise to perform this audit, you can sit for the exam and apply for a “PECB Certified ISO 9001 Lead Auditor” credential. By holding a PECB Lead Auditor Certificate, you will demonstrate that you have the capabilities and competencies to audit organizations based on best practices.
Who should attend?
- Auditors seeking to perform and lead Quality Management System (QMS) certification audits
- Managers or consultants seeking to master a Quality Management System audit process
- Individuals responsible for maintaining conformance with QMS requirements
- Technical experts seeking to prepare for a Quality Management System audit
- Expert advisors in Quality Management
General information
- Certification fees are included in the exam price
- Training material containing over 450 pages of information and practical examples will be distributed
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months free of charge
PECB ISO 9001 Lead Implementer
35 HoursISO 9001 Lead Implementer training enables you to develop the necessary expertise to support an organization in establishing, implementing, managing and maintaining a Quality Management System (QMS) based on ISO 9001. During this training course, you will also gain a thorough understanding of the best practices of Quality Management Systems and consequently improve an organization’s customer satisfaction and overall performance and effectiveness.
After mastering all the necessary concepts of Quality Management Systems, you can sit for the exam and apply for a “PECB Certified ISO 9001 Lead Implementer” credential. By holding a PECB Lead Implementer Certificate, you will be able to demonstrate that you have the practical knowledge and professional capabilities to implement ISO 9001 in an organization.
Who should attend?
- Managers or consultants involved in Quality Management
- Expert advisors seeking to master the implementation of a Quality Management System
- Individuals responsible for maintaining conformance with QMS requirements
- QMS team members
General information
- Certification fees are included on the exam price
- Training material containing over 450 pages of information and practical examples will be distributed
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months for free
PECB ISO/IEC 27005 Foundation
14 HoursTraining course is focused on the information security risk management process introduced by ISO/IEC 27005 and the structure of the standard.
The course provides an overview of the guidelines of ISO/IEC 27005 for managing information security risks, including context establishment, risk assessment, risk treatment, communication and consultation, recording and reporting, and monitoring and review.
After attending the training course, you can enroll for the Foundation Exam and, if you successfully pass it, you can apply for a “PECB Certificate Holder in ISO/IEC 27005 Foundation” certificate.
Foundation Exam ( extra cost): Duration: 1 hour, Questions: 40, Where: Online
A PECB Foundation certificate shows that you have knowledge on the fundamental concepts, principles, methodologies, processes, and management approaches used in information security risk management.
PECB ISO/IEC 42001 Lead Implementer
28 HoursAfter successfully completing the training course, you will be able to:
- Explain the fundamental concepts and principles of an AIMS based on ISO/IEC 42001
- Interpret the ISO/IEC 42001 requirements for an AIMS from the perspective of an implementer
- Initiate and plan the implementation of an AIMS based on ISO/IEC 42001 by utilizing PECB’s IMS2 Methodology and other best practices
- Support an organization in operating, maintaining, and continually improving an AIMS based on ISO/IEC 42001
- Prepare an organization to undergo a third party certification audit
PECB ISO/IEC 27001 Transition
14 HoursThe ISO/IEC 27001 Transition training course enables participants to thoroughly understand the differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022. In addition, participants will acquire knowledge on the new concepts presented by ISO/IEC 27001:2022.
ISO/IEC 27001 Lead Auditor (certification course)
35 HoursWho can attend?
- Auditors seeking to perform and lead information security management system (ISMS) audits
- Managers or consultants seeking to master the information security management system audit process
- Individuals responsible to maintain conformity with the ISMS requirements in an organization
- Technical experts seeking to prepare for the information security management system audit
- Expert advisors in information security management
Learning objectives
By the end of this training course, the participants will be able to:
- Explain the fundamental concepts and principles of an information security management system (ISMS) based on ISO/IEC 27001
- Interpret the ISO/IEC 27001 requirements for an ISMS from the perspective of an auditor
- Evaluate the ISMS conformity to ISO/IEC 27001 requirements, in accordance with the fundamental audit concepts and principles
- Plan, conduct, and close an ISO/IEC 27001 compliance audit, in accordance with ISO/IEC 17021-1 requirements, ISO 19011 guidelines, and other best practices of auditing
- Manage an ISO/IEC 27001 audit program
Educational approach
- This training is based on both theory and best practices used in ISMS audits
- Lecture sessions are illustrated with examples based on case studies
- Practical exercises are based on a case study which includes role playing and discussions
- Practice tests are similar to the Certification Exam
ISO/PAS 21448:2019 – Safety of the Intended Functionality (SOTIF)
14 HoursThis instructor-led, live training in Serbia (online or onsite) is aimed at intermediate-level quality management professionals who wish to learn the concepts, scope, and application of SOTIF for designing, implementing, and verifying the safety of the intended functionality in advanced driver assistance systems (ADAS) and autonomous driving features.
By the end of this training, participants will be able to:
- Recognize potential functional insufficiencies and misuse scenarios.
- Conduct hazard analysis and classify them based on SOTIF principles.
- Integrate SOTIF requirements into the system design, development, and validation phases.
- Implement validation methods to handle edge cases and unforeseeable risks.
- Ensure continuous monitoring and post-deployment improvements to maintain safety.
- Identify and overcome challenges specific to new technologies and SOTIF processes.