Visão Geral
O curso ISO 27018 Cloud Privacy tem como objetivo capacitar profissionais na implementação de controles de proteção de dados pessoais em ambientes de computação em nuvem, com base na norma ISO/IEC 27018. O treinamento aborda boas práticas para proteção de informações pessoalmente identificáveis (PII) em serviços cloud, com foco em privacidade, conformidade e confiança entre provedores e clientes.
Conteúdo Programatico
Module 1 – Introduction to Cloud Privacy and PII Protection
- Overview of ISO/IEC 27018 standard
- Relationship with ISO/IEC 27001 and ISO/IEC 27017
- Privacy principles in cloud computing
- Personally Identifiable Information (PII) concepts
- Roles and responsibilities in cloud environments
Module 2 – ISO 27018 Framework and Requirements
- Structure of ISO 27018
- Control objectives for PII protection
- Privacy-specific control extensions
- Responsibilities of cloud service providers
- Transparency and accountability principles
Module 3 – PII Processing in Cloud Environments
- Lawful processing of PII
- Consent management
- Purpose limitation and data minimization
- Data subject rights
- Data processing agreements
Module 4 – Data Protection Controls in Cloud
- Data encryption and key management
- Data segregation and isolation
- Secure data storage and transmission
- Data masking and anonymization
- Logging and monitoring for privacy
Module 5 – Cloud Provider Obligations
- Customer data handling requirements
- Restrictions on data usage
- Subcontractor management
- Data breach notification
- Return, transfer, and deletion of PII
Module 6 – Risk Management and Compliance
- Privacy risk assessment in cloud
- Integration with ISO 27005 risk management
- Compliance with GDPR and LGPD
- Audits and compliance verification
- Documentation and reporting
Module 7 – Incident Management and Response
- Privacy incident identification
- Breach response procedures
- Communication with stakeholders
- Regulatory notification requirements
- Lessons learned and improvements
Module 8 – Monitoring and Continuous Improvement
- Performance evaluation of privacy controls
- Internal audits for cloud privacy
- Management review
- Continuous improvement practices
- Integration with ISMS and PIMS