
This course contains the use of artificial intelligence.
This comprehensive course is dedicated to ISO/IEC 27017 — an international standard providing information security guidelines and additional controls for cloud services. It will provide you with a practical understanding of how organizations can implement and maintain effective security controls in cloud environments and appropriately allocate responsibilities between Cloud Service Customers and Cloud Service Providers.
Throughout the course, you will gain a clear and structured understanding of ISO/IEC 27017, its relationship with ISO/IEC 27001 and ISO/IEC 27002, and the specific aspects of managing information security when using or providing cloud services.
The course covers key aspects of cloud security, including the allocation of responsibilities between parties, access management, administration of cloud environments, data protection, monitoring of cloud services, change and configuration management, virtualization, removal and return of assets, and interaction between parties throughout the cloud service lifecycle.
Special attention is given to the additional controls introduced by ISO/IEC 27017 specifically for cloud environments and to the practical application of the standard’s guidance by organizations using or providing SaaS, PaaS, and IaaS.
The material is presented in a clear and practical way without unnecessary technical complexity. Therefore, the course is suitable both for beginners in cloud information security and for professionals who already have experience with ISO/IEC 27001 or information security management systems.
The course will be useful for information security managers, IT and Cloud Security professionals, compliance and GRC specialists, Cloud Architects, consultants, auditors, Cloud Service Customers, Cloud Service Providers, and anyone responsible for the secure use, implementation, or provision of cloud services.
The program has a practical focus and is based on real-world experience in implementing and auditing information security management systems. After completing the course, you will be able to integrate ISO/IEC 27017 guidance into an information security management system based on ISO/IEC 27001, define and document the responsibilities of relevant parties, assess cloud service risks, implement appropriate cloud security controls, and evaluate their effectiveness.
The knowledge gained will help you strengthen the security of cloud services, reduce risks associated with cloud infrastructure and third-party providers, improve control over information in cloud environments, and demonstrate a systematic approach to cloud security to customers and partners.
Disclaimer: Some parts of this course were created or enhanced using artificial intelligence tools, including for text processing and translation support. All educational content has been reviewed, edited, and approved by the course author to ensure its accuracy, relevance, and educational value.