Get in Touch
 Duration 14 hours

Course Outline

DAY 1: ISO/IEC 27017 Fundamentals, Framework, and Cloud Risk Management

  • Module 1: Introduction to ISO/IEC 27017 – Covers the overview, its relationship with ISO/IEC 27001/27002, and the standard’s primary goals.
  • Module 2: Scope of ISO/IEC 27017 – Examines additional controls, specific cloud environments, and defining audit boundaries.
  • Module 3: ISO/IEC 27017 Certification Scheme – Explains the certification model as an extension of ISO/IEC 27001.
  • Module 4: ISO/IEC 27017 Auditor Competency Model – Details required competencies, necessary cloud technical knowledge, and risk-based thinking.
  • Module 5: Cloud-Specific Risk Examples – Discusses risks associated with VM management, multi-tenancy, isolation, and legal jurisdiction.
  • Module 6: Cloud Service Categories – Analyzes the audit impact for SaaS, PaaS, IaaS, NaaS, and DSaaS.
  • Module 7: ISO/IEC 27017 Specific Controls – Focuses on shared responsibilities, VM hardening, and cloud service monitoring.
  • Module 8: Control Mapping to Cloud Services – Demonstrates how to map controls to IAM, Cloud Logging, Cloud KMS, and VPC.

DAY 2: Technical Audit Simulation and Regulatory Integration

  • Module 9: Audit Simulation Planning – Involves defining the audit scope (GCP/Organization) and selecting resource samples.
  • Module 10: Cloud Control Audit Simulation (Hands-on) – Practical auditing of Access Control, Resource Configuration, and Security Posture using real evidence.
  • Module 11: Cloud Regulations and Compliance Requirements
    • Indonesia Cloud Regulations: A detailed review of POJK 11/2022 and PADK No. 1 Year 2026 concerning Information Technology Implementation by Commercial Banks.
    • Mapping: Aligning ISO/IEC 27017 controls directly with local banking compliance needs.
  • Module 12: ISO/IEC 27017 Certification Audit Process – Covers audit techniques, methodology, and the full lifecycle.
  • Module 13: Integrated Audit Guidance – Provides a comparison between ISO/IEC 27001, 27017, and 27018.
  • Module 14: Final Workshop – An end-to-end audit simulation, including preparing findings and presenting results.

Requirements

  • A solid grasp of fundamental IT Security principles.
  • Practical experience with IT Security and Cloud Platforms.

Target Audience

  • IT Security professionals within the banking sector.
  • IT Security personnel from other financial institutions.

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories