- Search BSI
- Verify a Certificate
Suggested region and language based on your location
Your current region and language
Course Aim: This course is aimed at assisting cloud service providers and their customers understand the additional guidance and controls contained within ISO/IEC 27018. The additional controls will enable providers and their customers to comply with any applicable legislation and regulations and better protect information when processing PII in the Cloud.
Course Description: The protection of PII from both internal and external threats is a major concern for every organization, irrespective of size or market sector. Furthermore, if that PII information is held in the Cloud, information security risks can increase and the requirement to have effective and specific cloud security controls in place is critical.
The purpose of ISO/IEC 27018, when used in conjunction with the information security objectives and controls in ISO/IEC 27002, is to create a common set of security categories and controls that can be implemented by a public cloud computing service provider acting as a PII processor. The Standard does not replace applicable legislation and regulations, (e.g. EU GDPR and HIPAA), but provides a common compliance framework for public cloud service providers, in particular those that operate in a multinational market.
This course is aimed at both cloud service providers and customers who are engaging with a cloud service provider.
The course will help to ensure that the appropriate information security controls are in place for protecting PII processed by cloud service providers under contract to their customers.
This course will help cloud service providers:
This course will also help cloud service customers discuss and negotiate a suitable contract with a cloud service provider, ensuring that the latter implements appropriate controls. It will also help in developing a mechanism for exercising audit and compliance rights and responsibilities.
You will be able to explain:
Anyone who wants to learn what controls and measures can be implemented in order to protect PII in a cloud computing environment.
The course is applicable to representatives from cloud service providers who plan, implement, maintain, supervise or assess information security controls, as part of an information security management system.
Equally, the course is applicable to customers who are seeking reassurances that their provider is adopting well-governed cloud-based PII processing services.
If you have any enquiries, let us know how can we help you.
Call: +91 80815 80815
Email us: info.in@bsigroup.com
Reach out and see how we can help guide you on your path to sustainable operational success.
