Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
ISO/IEC 27018 – Protecting PII in Public Clouds (EN)
New

ISO/IEC 27018 – Protecting PII in Public Clouds (EN)

ISO/IEC 27018 – Protecting PII in Public Clouds
Last updated 8/2026
English

What you'll learn

  • Understand the purpose, scope, and structure of ISO/IEC 27017 for cloud security.
  • Understand how ISO/IEC 27017 complements ISO/IEC 27001 and ISO/IEC 27002.
  • Understand the roles of Cloud Service Customers and Cloud Service Providers.
  • Identify and assess information security risks related to cloud services.
  • Understand the additional cloud-specific controls introduced by ISO/IEC 27017.
  • Apply security controls for access, configuration, monitoring, and cloud environments.
  • Define and document shared security responsibilities between customers and providers.
  • Integrate ISO/IEC 27017 guidance into an existing ISMS and improve cloud security governance.

Course content

1 section16 lectures31m total length
  • Course Overview3:04
  • What Is ISO/IEC 27018?2:24
  • Roles and the Shared Responsibility Model2:11
  • Contracts, Instructions, and Transparency1:58
  • Consent, Purpose, and Use Limitations1:58
  • Data Subject Rights and Customer Support1:55
  • Locations, Transfers, and Subprocessors1:51
  • Access Control and Administration1:46
  • Cryptography, Isolation, and Secure Architecture1:42
  • Logging, Monitoring, and Data Minimization in Logs1:33
  • Retention, Return, and Deletion of PII1:48
  • Incidents and Breach Notification1:47
  • Continuity, Backups, and Recovery1:37
  • Internal Audit and Conformity Assessment1:53
  • Practical Implementation at Baltum Bureau1:43
  • Summary and Next Steps2:03

Requirements

  • No previous experience with ISO/IEC 27017 is required.
  • Basic knowledge of IT, cloud services, or information security will be helpful.
  • Basic familiarity with ISO/IEC 27001 is useful but not required.

Description

This course contains the use of artificial intelligence.

This comprehensive course is dedicated to ISO/IEC 27017 — an international standard providing information security guidelines and additional controls for cloud services. It will provide you with a practical understanding of how organizations can implement and maintain effective security controls in cloud environments and appropriately allocate responsibilities between Cloud Service Customers and Cloud Service Providers.

Throughout the course, you will gain a clear and structured understanding of ISO/IEC 27017, its relationship with ISO/IEC 27001 and ISO/IEC 27002, and the specific aspects of managing information security when using or providing cloud services.

The course covers key aspects of cloud security, including the allocation of responsibilities between parties, access management, administration of cloud environments, data protection, monitoring of cloud services, change and configuration management, virtualization, removal and return of assets, and interaction between parties throughout the cloud service lifecycle.

Special attention is given to the additional controls introduced by ISO/IEC 27017 specifically for cloud environments and to the practical application of the standard’s guidance by organizations using or providing SaaS, PaaS, and IaaS.

The material is presented in a clear and practical way without unnecessary technical complexity. Therefore, the course is suitable both for beginners in cloud information security and for professionals who already have experience with ISO/IEC 27001 or information security management systems.

The course will be useful for information security managers, IT and Cloud Security professionals, compliance and GRC specialists, Cloud Architects, consultants, auditors, Cloud Service Customers, Cloud Service Providers, and anyone responsible for the secure use, implementation, or provision of cloud services.

The program has a practical focus and is based on real-world experience in implementing and auditing information security management systems. After completing the course, you will be able to integrate ISO/IEC 27017 guidance into an information security management system based on ISO/IEC 27001, define and document the responsibilities of relevant parties, assess cloud service risks, implement appropriate cloud security controls, and evaluate their effectiveness.

The knowledge gained will help you strengthen the security of cloud services, reduce risks associated with cloud infrastructure and third-party providers, improve control over information in cloud environments, and demonstrate a systematic approach to cloud security to customers and partners.

Disclaimer: Some parts of this course were created or enhanced using artificial intelligence tools, including for text processing and translation support. All educational content has been reviewed, edited, and approved by the course author to ensure its accuracy, relevance, and educational value.

Who this course is for:

  • Information security, cybersecurity, and Cloud Security professionals.
  • IT professionals, Cloud Architects, engineers, and administrators working with cloud services.
  • Compliance and GRC professionals, consultants, internal auditors, and ISO/IEC 27001 specialists.
  • Cloud Service Customers and Cloud Service Providers seeking to strengthen cloud security and apply ISO/IEC 27017 guidance.