Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
DAY 1: ISO/IEC 27017 Fundamentals, Framework, and Cloud Risk Management
- Module 1: Introduction to ISO/IEC 27017 – Covers the overview, its relationship with ISO/IEC 27001/27002, and the standard’s primary goals.
- Module 2: Scope of ISO/IEC 27017 – Examines additional controls, specific cloud environments, and defining audit boundaries.
- Module 3: ISO/IEC 27017 Certification Scheme – Explains the certification model as an extension of ISO/IEC 27001.
- Module 4: ISO/IEC 27017 Auditor Competency Model – Details required competencies, necessary cloud technical knowledge, and risk-based thinking.
- Module 5: Cloud-Specific Risk Examples – Discusses risks associated with VM management, multi-tenancy, isolation, and legal jurisdiction.
- Module 6: Cloud Service Categories – Analyzes the audit impact for SaaS, PaaS, IaaS, NaaS, and DSaaS.
- Module 7: ISO/IEC 27017 Specific Controls – Focuses on shared responsibilities, VM hardening, and cloud service monitoring.
- Module 8: Control Mapping to Cloud Services – Demonstrates how to map controls to IAM, Cloud Logging, Cloud KMS, and VPC.
DAY 2: Technical Audit Simulation and Regulatory Integration
- Module 9: Audit Simulation Planning – Involves defining the audit scope (GCP/Organization) and selecting resource samples.
- Module 10: Cloud Control Audit Simulation (Hands-on) – Practical auditing of Access Control, Resource Configuration, and Security Posture using real evidence.
- Module 11: Cloud Regulations and Compliance Requirements
- Indonesia Cloud Regulations: A detailed review of POJK 11/2022 and PADK No. 1 Year 2026 concerning Information Technology Implementation by Commercial Banks.
- Mapping: Aligning ISO/IEC 27017 controls directly with local banking compliance needs.
- Module 12: ISO/IEC 27017 Certification Audit Process – Covers audit techniques, methodology, and the full lifecycle.
- Module 13: Integrated Audit Guidance – Provides a comparison between ISO/IEC 27001, 27017, and 27018.
- Module 14: Final Workshop – An end-to-end audit simulation, including preparing findings and presenting results.
Requirements
- A solid grasp of fundamental IT Security principles.
- Practical experience with IT Security and Cloud Platforms.
Target Audience
- IT Security professionals within the banking sector.
- IT Security personnel from other financial institutions.
Testimonials (3)
Cloud security standar
Singgih Sulaksono - Pt bank Sinarmas
Course - Cloud Security Audit for Financial Institutions
mas nya bagus berikan insightnya buat ngaudit and additional value
Retno Wulansari - Pt bank Sinarmas
Course - Cloud Security Audit for Financial Institutions
sharing knowledge