Digital Academy

Digital upskilling to future-proof your team

Advancements in digital and technology are reshaping the way we do business. Equip yourself with the necessary tools and mindsets to accelerate the impact of digital in your organisation. Learn about cloud security, data analytics, data visualisation and more with our industry practitioners.

Our programmes

Cloud Security Assessment and Auditing

Companies are increasingly opting to migrate its IT infrastructure and services onto Cloud, driven by obvious reasons - cost effectiveness and scalability. However, many are unaware of the "shared security responsibilties" with Cloud Service Provider (CSP) and assume that security responsibilities will be the function of the CSP. Cloud security breaches are on the rise and most can be attributed to 'customer's fault'. It is important for companies to understand the various Cloud deployment models, carefully assess and evaluate the inherent risks for each, and put in place measures and safeguards to ensure cloud security risks are managed effectively.
 

Objectives

The course aims to provide participants a better understanding of the Cloud architecture and deployment models, benefits of each, and the security related risks companies will need to be aware of as they move their services onto Cloud platform.

Outcome

At the end of the course, participants will be able to take away key learning points and tips in understanding Cloud fundamentals and the following:

  • Recognise the key components and unique characteristics of Cloud
  • Recognise the business value of using Cloud
  • Identify the security and non-security risks arising from use of Cloud 
  • Understand the key auditing techniques on Cloud
Agenda/topics covered?
  • What is Cloud Computing
  • History and Evolution of Cloud - Core Services: Compute, Storage, Network, and Database
  • Why Businesses are Moving to Cloud 
  • Characteristics: On-demand, Elasticity, PayPer Use, Independent Resource Pooling, Network Access
  • Cloud Concepts (covering on-premises vs. cloud, virtual resource, Availability Zone vs. Region vs. Edge Locations, etc.)
  • Deep dive into Cloud Categories and Delivery Models:  Categories: Public Cloud /Private Cloud /Hybrid Cloud /
  • Community Cloud
  • Delivery Models: Business Process Cloud /SaaS /PaaS / IaaS
  • Design for Failure: Design Principles
  • Scalability (vertically and horizontally, covering stateless applications, distribution of load to multiple loads, stateless/stateful components, distributed processing, etc.)
  • Disposable Resources (covering bootstrapping, golden images, containers, etc.)
  • Loose Coupling and removing Single Points of Failure (e.g. redundancy, durable data storage, detecting failure, fault isolation, etc.)
  • Automation (serverless management and deployment, alarms and events, etc.)
  • Built-in Security (touching on defense in depth, shared responsibility models, reduced privileged access with identity access management, real-time auditing, security as code, etc.)
Other Architectural Considerations
  • Cost Optimization
  • High Performance
  • Cloud Threats and Mitigation Strategies
  • Shared Responsibility Model
  • Responsibilities of the Customer / Secure Cloud Case Studies 
  • Cloud Audit - Value and Tactics / Cloud Management Audit/Assurance Program / SOC 2 Compliance
  • Key takeaways from both training session

Duration: 2 days

Delivery mode: Classroom

Target audience

IT, Risk Management & Compliance / Internal audit executives above

Follow us
Hide

Required fields are marked with an asterisk(*)

By submitting your email address, you acknowledge that you have read the Privacy Statement and that you consent to our processing data in accordance with the Privacy Statement (including international transfers). If you change your mind at any time about wishing to receive the information from us, you can send us an email message using the Contact Us page.

Contact us

Lay See Wee

Lay See Wee

Digital Academy Lead, PwC Malaysia

Tel: +60 3-2173 1120