ISO/IEC 27017:2015 - CLOUD
SECURITY

Overview

ISO/IEC 27017 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:

  • Additional implementation guidance for relevant controls specified in ISO/IEC 27002;
  • Additional controls with implementation guidance that specifically relate to cloud services.

Implementing the guidelines of ISO/IEC 27017 helps cloud service providers and customers to establish, implement, and maintain information security controls related to cloud services. ISO/IEC 27017 provides additional guidance in selecting information security controls applicable to cloud services based on risk assessment and other cloud-specific information security requirements.

Benefits of ISO 27017 Certification

 Identify key benefits associated with using ISO/IEC 27017 for cloud services, alongside an effective ISMS

 Consider the risks associated with using cloud services

 Ensure that your management system considers appropriate cloud-related controls that enable improved organizational security as technology evolves

 Provide products and services that consistently meet customer needs and enhance confidence

 Knowledge needed to respond to and recover from a cloud security incident

ISO 27017 Foundation (FD):

The ISO 27017 Cloud Security Foundation training course enables participants to gain fundamental knowledge needed to implement a cloud security program by following widely recognized best practices.

After completing this course, participants can sit for the exam. Once participants meet the pass mark, he/she will be given a “SandBP Certified ISO 27017 Cloud Security Foundation” credential. A SandBP Foundation Certificate shows that the participants have understood the fundamental methodologies, requirements, framework and management approach.

ISO 27017 Manager(MG)

Cloud Security Manager Certification program enables participants to develop the competence, needed to implement and manage a cloud security program by following widely recognized best practices.

After mastering all the necessary concepts of ISO 27017, participants can sit for the exam. Once participants meet the pass mark, he/she will be given “S and BP Certified ISO 27017 Cloud Security Manager” credential. By holding a SandBP Manager Certificate, the participant can be able to demonstrate that he/she has the practical knowledge and professional capabilities to implement ISO 27017 in an organization.

Terms of Certification

 Candidates who score 70% and above in the examination will be issued an SANDBP certificate.

 In case you do not meet the pass mark, you can retake the exam for FREE after the first attempt while subsequent retakes would come at a cost.

Criteria for Suspending and Withdrawing the Scope of Certification

SANDBP reserves the right to suspend or revoke certifications for reasons including fraud, deceit, or submission of inaccurate data.

Process:

 Certificate holders will be notified by certified mail if evidence of charges is found.

 They may present their defense in writing to the certification board.

 The board will review the case and decide to uphold or deny the suspension/revocation.

Causes for Suspension/Withdrawal:

 Improper use of certificates/logos

 Malpractices

 Providing false information

 Ineligibility for applied examinations

 Voluntary suspension requests

Recertification Process

Recertification ensures that certified individuals maintain their knowledge and skills in line with the latest standards and practices. It is a critical process that reaffirms the competency of certified professionals, allowing them to stay current with evolving industry standards.

Criteria for Recertification:

 Transition Exam:

  • Individuals must take and pass a transition exam when there is a change in the current version of the certification standard.
  • The transition exam focuses on the updates and changes in the new version of the standard,     ensuring that certified individuals are knowledgeable about the latest requirements and practices.

 Adherence to Code of Ethics:

Certified individuals must adhere to a code of ethics, demonstrating professionalism and integrity in their practice. Any violations of the code of ethics may result in the suspension or revocation of certification

 Payment of Recertification Fees:

Payment of the required recertification fees is necessary to process and validate the renewal of certification.

Introduction

To maintain the integrity and fairness of our examinations, specific guidelines have been established for proctoring. These rules apply to all candidates and must be adhered to strictly. Failure to comply may result in disqualification or other disciplinary actions.

General Requirements

Technology Setup

  •  Device: Use a desktop or laptop with a working webcam and microphone. Mobile phones or tablets are not permitted unless explicitly allowed.
  •  Internet: Ensure a stable internet connection with sufficient bandwidth to stream video and audio continuously.
  •  Browser: Use the designated browser as specified by the exam platform.
  •  Power Backup: Ensure your device is fully charged and/or connected to a reliable power source.

Environmental Setup

  •  Location: Choose a quiet, well-lit room with minimal distractions.
  •  Background: Ensure the background is plain and free of any clutter or distractions.
  •  Privacy: No other person is allowed in the room during the examination.

Pre-Exam Procedures

Present a valid government-issued photo ID or institution-approved identification document. Ensure that no unauthorized materials (e.g., books, notes, or electronic devices) are present.

During the Exam
Behavior Guideline
  •  Focus on the Screen: Avoid looking away from the screen for extended periods.
  •  No Assistance: You are prohibited from receiving help from anyone or any external resource.
Prohibited Items
  •  Electronic devices such as mobile phones, tablets, smartwatches, and earphones.
  •  Books, notes, or any other study material unless explicitly permitted.
Proctor Interaction
  •  Follow all instructions given by the proctor.
  •  If contacted for clarification or rule enforcement, respond promptly and cooperatively.
  •  Inform the proctor immediately in case of technical issues.

Post-Exam Procedures

Submission
  •  Ensure your exam responses are submitted within the designated time.
  •  Do not close the exam window or disconnect until you receive confirmation that your submission is successful.
Feedback
  •  Report any technical issues or concerns to the designated support team immediately aƜer the exam.

Violations and Consequences

Examples of Violations

  •  Using unauthorized materials or devices.
  •  Attempting to impersonate another candidate.
  •  Engaging in suspicious behavior (e.g., frequent movement, talking).
  •  Disconnecting intentionally without justification.

Consequences

  •  Warnings for minor infractions.
  •  Disqualification of the exam attempt for major violations.

Support and Troubleshooting

Contact the technical support team in case of any issues with logging in, connectivity, or proctoring tools. (support@sandbp.net)

$33

$115