Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
DAY 1: ISO/IEC 27017 Essentials, Frameworks, and Cloud Risk Management
- Module 1: Intro to ISO/IEC 27017 – Overview, its connection with ISO/IEC 27001/27002, and core objectives.
- Module 2: Scope of ISO/IEC 27017 – Supplementary controls, cloud contexts, and audit boundaries.
- Module 3: ISO/IEC 27017 Certification Model – Certification approach as an extension of ISO/IEC 27001.
- Module 4: ISO/IEC 27017 Auditor Competencies – Essential skills, cloud technical understanding, and risk-based analysis.
- Module 5: Cloud Risk Case Studies – Risks in VM management, multi-tenancy, isolation, and legal jurisdiction.
- Module 6: Cloud Service Models – Audit implications for SaaS, PaaS, IaaS, NaaS, and DSaaS.
- Module 7: ISO/IEC 27017 Specific Controls – Shared responsibility models, VM hardening, and cloud service monitoring.
- Module 8: Mapping Controls to Cloud Services – Aligning controls with IAM, Cloud Logging, Cloud KMS, and VPC.
DAY 2: Technical Audit Simulations and Regulatory Alignment
- Module 9: Planning Audit Simulations – Defining audit scope (GCP/Organization) and selecting resource samples.
- Module 10: Hands-on Cloud Control Audit – Assessing Access Control, Resource Configuration, and Security Posture using real-world evidence.
- Module 11: Cloud Regulations and Compliance Standards
- Indonesian Cloud Regulations: In-depth analysis of POJK 11/2022 & PADK No. 1 Year 2026 concerning IT implementation in commercial banks.
- Alignment: Directly mapping ISO/IEC 27017 controls to local banking compliance mandates.
- Module 12: ISO/IEC 27017 Certification Audit Process – Audit techniques, methodologies, and lifecycle management.
- Module 13: Integrated Audit Insights – Comparative analysis of ISO/IEC 27001, 27017, and 27018.
- Module 14: Capstone Workshop – End-to-End Audit Simulation, drafting findings, and presenting outcomes.
Requirements
- Familiarity with fundamental IT Security concepts
- Practical experience with IT Security and Cloud Platforms
Target Audience
- Banking IT Security professionals
- IT Security personnel from other financial institutions
Testimonials (3)
Cloud security standar
Singgih Sulaksono - Pt bank Sinarmas
Course - Cloud Security Audit for Financial Institutions
mas nya bagus berikan insightnya buat ngaudit and additional value
Retno Wulansari - Pt bank Sinarmas
Course - Cloud Security Audit for Financial Institutions
sharing knowledge