Cloud Security
Plan, implement and review security for cloud services using recognised standards.
Cloud Security: what it is and why it matters
ISO/IEC 27017 adds cloud-specific control guidance on top of ISO/IEC 27002 for cloud service customers and providers. ISO/IEC 27018 gives guidelines for protecting personally identifiable information in public clouds where the provider acts as a PII processor.
Cloud security training connects those standards to practical work: shared responsibility, identity, data protection, monitoring and supplier assurance.
Built for the people who carry the work
- Cloud and infrastructure security engineers
- Security managers responsible for cloud adoption
- Compliance and privacy staff who assess cloud suppliers
- Architects designing cloud workloads
What you will be able to do
- Explain shared responsibility between customer and provider
- Apply ISO/IEC 27017 and 27018 guidance to a cloud service
- Assess cloud supplier risk and contract controls
- Design identity, data protection and logging controls
- Plan monitoring and incident handling for cloud services
Subject outline
- 01
Cloud computing fundamentals
- 02
Information security policy for cloud
- 03
Cloud security risk management
- 04
Cloud-specific controls from ISO/IEC 27017 and 27018
- 05
Awareness, training and monitoring
- 06
Incident management in the cloud
- 07
Testing and continual improvement
How it supports real work
Reviewing a cloud supplier before signing
Mapping cloud controls to your existing control set
Defining who monitors what in a shared responsibility model
Training, examination and certification are different steps
Cloud security credentials come from several bodies with different rules. This page names them for comparison and does not suggest that one replaces another.
- PECB Lead Cloud Security Manager: 5 days with the exam on day 5; the handbook describes 80 multiple-choice questions, 70% pass mark, seven domains, and says candidates may take the exam without attending the course.
- CSA CCSK is published by the Cloud Security Alliance as an open-book online exam with no official prerequisites.
- ISC2 CCSP asks for documented professional experience.
- Edition status of ISO/IEC 27017 is changing, so we confirm which edition a course teaches.
Certification bodies set and can change their own exam, eligibility and renewal rules. The details below are what the body publishes; we confirm the current position with you before you enrol.
Sources checked, October 2026: pecb.com
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Are ISO/IEC 27017 and 27018 certifiable?
They are guidance standards. Check with the certification body before assuming a certificate exists.
Is training required to sit the PECB exam?
PECB’s handbook says candidates may take the exam without attending the course.
Which edition of ISO/IEC 27017 applies?
Edition status is changing on iso.org, so we confirm the edition used in a course when you enquire.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for Cloud Security.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


