Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Day 1: ISO/IEC 27017 Fundamentals, Frameworks, and Cloud Risk Management
- Module 1: Introduction to ISO/IEC 27017 – An overview, its relationship with ISO/IEC 27001/27002, and the standard’s core objectives.
- Module 2: Scope of ISO/IEC 27017 – Additional controls, cloud environments, and defining audit boundaries.
- Module 3: ISO/IEC 27017 Certification Scheme – Understanding the certification model as an extension of ISO/IEC 27001.
- Module 4: ISO/IEC 27017 Auditor Competency Model – Essential competencies, cloud technical knowledge, and risk-based thinking.
- Module 5: Cloud-Specific Risk Examples – Risks associated with VM management, multi-tenancy, isolation, and legal jurisdictions.
- Module 6: Cloud Service Categories – Discussing audit impacts for SaaS, PaaS, IaaS, NaaS, and DSaaS.
- Module 7: ISO/IEC 27017 Specific Controls – Shared responsibilities, VM hardening, and cloud service monitoring.
- Module 8: Mapping Controls to Cloud Services – Aligning controls with IAM, Cloud Logging, Cloud KMS, and VPC.
Day 2: Technical Audit Simulations and Regulatory Integration
- Module 9: Planning Audit Simulations – Defining the audit scope (GCP/Organization) and resource sampling strategies.
- Module 10: Cloud Control Audit Simulation (Hands-on) – Auditing Access Control, Resource Configuration, and Security Posture using real-world evidence.
- Module 11: Cloud Regulations and Compliance Requirements
- Indonesia Cloud Regulations: An in-depth analysis of POJK 11/2022 & PADK No. 1 Year 2026 concerning Information Technology Implementation by Commercial Banks.
- Mapping: Directly aligning ISO/IEC 27017 controls with local banking compliance mandates.
- Module 12: ISO/IEC 27017 Certification Audit Process – Exploring audit techniques, methodology, and the full lifecycle.
- Module 13: Integrated Audit Guidance – Comparative analysis of ISO/IEC 27001, 27017, and 27018.
- Module 14: Final Workshop – Conducting an End-to-End Audit Simulation, preparing findings, and presenting results.
Requirements
- Familiarity with foundational IT Security concepts.
- Practical experience with IT Security and Cloud Platforms.
Target Audience
- IT Security professionals in the banking sector.
- IT Security teams from other financial institutions.
Testimonials (3)
Cloud security standar
Singgih Sulaksono - Pt bank Sinarmas
Course - Cloud Security Audit for Financial Institutions
mas nya bagus berikan insightnya buat ngaudit and additional value
Retno Wulansari - Pt bank Sinarmas
Course - Cloud Security Audit for Financial Institutions
sharing knowledge