
Cloud Security Auditor Accelerator
September 15, 2021, 10 AM - 1 PM, EDT
CA$349.00
Overview
Control Frameworks (such as IT General Controls, SOX, SOC2), while relevant, are very different in their implementation when applying them to cloud infrastructure. As more organizations embrace public cloud infrastructures such as Azure, Amazon Web Services and Google Cloud Platform, cybersecurity audits for the environment with the right sized controls and implementation become a key topic for auditors. While there are industry-leading frameworks (such as Cloud Security Alliance Cloud Controls Matrix) available for reference to auditors, often, practical implementation and auditing guides may not be readily available for them.
Talking about audit controls to cloud teams has always been challenging. With this workshop, familiarize yourself with cloud security principles that you can leverage in your next audit and effectively test the design and operating effectiveness of cloud platform security. The course will start with the fundamental concepts of cloud security. Then we will go through some of the recent security incidents and lessons learnt. Once you understand different threats in the public cloud environment, we will go through the mitigation controls to protect against such threats. Then we will cover how to audit these security controls in the cloud environment. The course will finish with the advanced topic of utilizing native CSP provided security tools for auditing.
Key
Takeaways
As an outcome, participants will be able to walk away with key understanding of how security controls operate in the public cloud environment and have practical use cases they can refer to during audits.
After attending this workshop, you should be comfortable talking to your cloud engineering teams about security controls and effectively communicate the requirements of your audit. You will become familiar with how to translate IT general and security in the cloud environment. You will learn how to audit and obtain evidence during audits through automated and native tools.
Who Should
Attend
- Internal and external auditors
- Cybersecurity professionals
- IT professionals with interest in cloud security
Prerequisites
- Knowledge of audit methodology such as design testing, operating effectiveness testing
- Foundational knowledge of cybersecurity
- Basic knowledge about cloud computing is a plus
Workshop
Agenda
- Introduction to general concepts for cloud security
- Market landscape overview of cloud security
- Cloud security incidents and lessons learnt
- Cloud security controls frameworks and regulatory landscape
- Cloud specific threats and mitigations
- Auditing cloud security controls (Design and Operating Effectiveness Testing)
- Introduction to automated controls auditing and monitoring
- Leveraging native cloud security tools for auditing
- Case study of controls Review
Workshop
Leader

Vishal Patel
