Loading Events

Training Calendar

หลักสูตรที่ได้รับการออกแบบเนื้อหาที่ครอบคลุม ทั้งทฤษฎี เทคนิค และสาระน่ารู้ที่ทันสมัยสอนโดยอาจารย์ผู้เชี่ยวชาญ และมีประสบการณ์ด้านความปลอดภัยของสารสนเทศโดยตรง

ISO/IEC 27018 Privacy Protection in Public Cloud

กำหนดการ
21/12/2026 - 22/12/2026
9:30 am - 4:30 pm

About this course

This course is aimed at assisting cloud service providers and their customers understand the additional guidance and controls contained within ISO/IEC 27018:2025.  The additional controls will enable providers and their customers to comply with any applicable legislation and regulations and better protect information when processing PII in the Cloud.

The purpose of ISO/IEC 27018:2025, when used in conjunction with the information security objectives and controls in ISO/IEC 27002:2022, is to create a common set of security categories and controls that can be implemented by a public cloud computing service provider acting as a PII processor.  The Standard does not replace applicable legislation and regulations, (e.g. EU GDPR, HIPAA, and NCSA Cybersecurity Standards for Cloud Systems), but provides a common compliance framework for public cloud service providers, in particular those that operate in a multinational market.

The course will help to ensure that the appropriate information security controls are in place for protecting PII processed by cloud service providers under contract to their customers.

ISO/IEC 27018 Privacy Protection in Public Cloud

Course Benefits

This course will help cloud service providers:

  • Identify key benefits associated with using ISO/IEC 27018 for protecting PII within the cloud services they provide, alongside an effective ISMS
  • Consider Cloud and PII specific risks and associated ISO/IEC 27018 controls
  • Understand the rationale behind the controls, their usage and implementation
  • Establish an appropriate level of protection for PII within the cloud services they provide.

This course will also help cloud service customers discuss and negotiate a suitable contract with a cloud service provider, ensuring that the latter implements appropriate controls.  It will also help in developing a mechanism for exercising audit and compliance rights and responsibilities.

Who should Attend?

01

Cloud service provider personnel who plan, implement, maintain, or assess information security controls

02

Information Security Officers responsible for data protection in cloud environments

03

Compliance officers and privacy professionals working with personal data (PII)

04

Risk managers assessing cloud-based services

05

Legal professionals involved in data protection, cloud contracts, or GDPR compliance

06

Internal and external IT auditors

07

Cloud service customers seeking assurance in the provider’s security controls

08

Professionals involved in implementing or maintaining ISO/IEC 27001, 27002, or 27018 standards

09

Consultants in data privacy and cloud governance

Course Contents

Typical information security risks for PII in cloud services

  • Background and purpose of ISO/IEC 27018
  • Scope and structure ISO/IEC 27018
  • The benefits of implementing ISO/IEC 27018
  • Typical ISO/IEC 27018 control implementation and integration with ISO /IEC 27001 and 27002
  • How the key concepts and requirements of ISO/IEC 27001 work when implementing ISO/IEC 27018
  • And explore/select ISO/IEC 27018 controls, relevant to your risk assessment, through practical scenarios
  • Specific guidance for cloud service providers.

Training Info

Date : 

21/12/2026 - 22/12/2026

Time : 

9:30 am - 4:30 pm

Duration: 2 Days
Venue: Grande Centre Point Lumphini 16th Floor,1188 Rama IV Road,
Thungmahamek, Sathon, Bangkok 10120
Training price: 28,000 Baht (Ex.Vat)

02 670 8980-4 ext. 321, 322, 323

Bookings

Request Registration

0 Going
10 remaining
RSVP Here

Bookings are closed for this event.

ติดต่อเรา
เพื่อรับคำปรึกษาข้อมูลเพิ่มเติม
ACinfotec พร้อมเป็นพาร์ทเนอร์เคียงข้างคุณ ตั้งแต่ก้าวแรก… จนถึงการรับรอง