Get in Touch
 Duration 14 hours

Course Outline

Day 1: ISO/IEC 27017 Fundamentals, Frameworks, and Cloud Risk Management

  • Module 1: Introduction to ISO/IEC 27017 – An overview, its relationship with ISO/IEC 27001/27002, and the standard’s core objectives.
  • Module 2: Scope of ISO/IEC 27017 – Additional controls, cloud environments, and defining audit boundaries.
  • Module 3: ISO/IEC 27017 Certification Scheme – Understanding the certification model as an extension of ISO/IEC 27001.
  • Module 4: ISO/IEC 27017 Auditor Competency Model – Essential competencies, cloud technical knowledge, and risk-based thinking.
  • Module 5: Cloud-Specific Risk Examples – Risks associated with VM management, multi-tenancy, isolation, and legal jurisdictions.
  • Module 6: Cloud Service Categories – Discussing audit impacts for SaaS, PaaS, IaaS, NaaS, and DSaaS.
  • Module 7: ISO/IEC 27017 Specific Controls – Shared responsibilities, VM hardening, and cloud service monitoring.
  • Module 8: Mapping Controls to Cloud Services – Aligning controls with IAM, Cloud Logging, Cloud KMS, and VPC.

Day 2: Technical Audit Simulations and Regulatory Integration

  • Module 9: Planning Audit Simulations – Defining the audit scope (GCP/Organization) and resource sampling strategies.
  • Module 10: Cloud Control Audit Simulation (Hands-on) – Auditing Access Control, Resource Configuration, and Security Posture using real-world evidence.
  • Module 11: Cloud Regulations and Compliance Requirements
    • Indonesia Cloud Regulations: An in-depth analysis of POJK 11/2022 & PADK No. 1 Year 2026 concerning Information Technology Implementation by Commercial Banks.
    • Mapping: Directly aligning ISO/IEC 27017 controls with local banking compliance mandates.
  • Module 12: ISO/IEC 27017 Certification Audit Process – Exploring audit techniques, methodology, and the full lifecycle.
  • Module 13: Integrated Audit Guidance – Comparative analysis of ISO/IEC 27001, 27017, and 27018.
  • Module 14: Final Workshop – Conducting an End-to-End Audit Simulation, preparing findings, and presenting results.

Requirements

  • Familiarity with foundational IT Security concepts.
  • Practical experience with IT Security and Cloud Platforms.

Target Audience

  • IT Security professionals in the banking sector.
  • IT Security teams from other financial institutions.

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories