Skip to main content
Cybersecurity ops

Lead Cloud Security Manager

Lead Cloud Security Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Cloud security and information security professionals responsible for managing a cloud security programme
  • Managers and consultants seeking to master cloud security best practices
  • Individuals tasked with maintaining and governing a cloud security programme
  • Technical experts looking to broaden their cloud security knowledge into a management context
  • Cloud security advisors who guide organisations on programme design and improvement

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no background in cloud computing or information security who would need foundational training first
  • Professionals seeking a purely technical, hands-on cloud penetration testing or engineering course
  • Those looking for a general ISO/IEC 27001 ISMS implementation course rather than cloud-specific programme management

What you'll be able to do

  • 1Explain the concepts, approaches, and techniques used to implement and manage a cloud security programme
  • 2Describe the correlation between ISO/IEC 27017, ISO/IEC 27018, and other relevant regulatory frameworks
  • 3Interpret ISO/IEC 27017 and ISO/IEC 27018 guidelines within a specific organisational context
  • 4Plan and initiate a cloud security programme aligned with recognised best practices
  • 5Apply cloud computing security risk management processes to identify and treat cloud-specific risks
  • 6Implement cloud-specific security controls drawn from ISO/IEC 27017 and ISO/IEC 27018
  • 7Manage cloud security awareness and training activities for relevant stakeholders
  • 8Monitor, test, and continually improve a cloud security programme through structured review processes

Day by day

Day 1Introduction to ISO/IEC 27017 and ISO/IEC 27018 and initiation of a cloud security programme
  • Fundamental concepts of cloud computing

    Participants review cloud service and deployment models, shared responsibility, and the role that ISO/IEC 27017 and ISO/IEC 27018 play in securing cloud environments.

  • Relationship between ISO/IEC 27017, ISO/IEC 27018, and regulatory frameworks

    This module maps the two standards against ISO/IEC 27001 and other regulatory frameworks, clarifying how they complement each other.

  • Initiating a cloud security programme

    Learners examine the steps required to scope, charter, and begin a cloud security programme, including stakeholder identification and leadership commitment.

By end of day

  • Explain the purpose and scope of ISO/IEC 27017 and ISO/IEC 27018 to organisational stakeholders
  • Outline the key activities needed to initiate a cloud security programme
Day 2Cloud computing security risk management and cloud-specific controls
  • Cloud security risk management processes

    This module covers risk identification, analysis, and treatment techniques specific to cloud computing environments, including multi-tenancy and data residency considerations.

  • Cloud-specific controls based on ISO/IEC 27017 and ISO/IEC 27018

    Participants learn how to select and implement controls that address cloud-unique threats, covering areas such as virtual machine security, customer-managed encryption, and personal data protection in the cloud.

By end of day

  • Conduct a cloud-focused risk assessment using structured risk management processes
  • Select and justify cloud-specific controls aligned with ISO/IEC 27017 and ISO/IEC 27018 requirements
Day 3Documented information management and cloud security awareness and training
  • Documented information management for cloud security

    This module addresses the policies, procedures, and records needed to support a cloud security programme, including version control and access management for documentation.

  • Information security policy for cloud computing

    Learners examine how to develop and maintain cloud-specific security policies consistent with organisational governance requirements.

  • Cloud security awareness and training programmes

    This module covers the design and delivery of awareness campaigns and training activities to build a security-conscious culture among cloud users and administrators.

By end of day

  • Develop a documented information framework that supports cloud security governance
  • Design a cloud security awareness programme targeting relevant internal audiences
Day 4Cloud security incident management, testing, monitoring, and continual improvement
  • Cloud security incident management

    Participants explore detection, response, and recovery processes tailored to cloud environments, including coordination between cloud service providers and customers.

  • Cloud security testing

    This module introduces testing methodologies such as vulnerability assessments and security reviews used to validate the effectiveness of cloud controls.

  • Monitoring and continual improvement

    Learners examine how to establish metrics, conduct management reviews, and drive continual improvement of the cloud security programme.

By end of day

  • Establish an incident response workflow suited to shared-responsibility cloud environments
  • Define monitoring metrics and testing schedules to sustain cloud programme effectiveness
  • Apply continual improvement principles to evolve the cloud security programme over time
Day 5Certification exam
  • PECB Certified Lead Cloud Security Manager exam

    The exam assesses competency across seven domains covering cloud computing fundamentals, policy, risk management, controls, awareness, incident management, and continual improvement, as defined in the PECB Examination and Certification Program.

By end of day

  • Demonstrate readiness to sit the PECB Certified Lead Cloud Security Manager exam by consolidating knowledge from all programme domains

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of cloud computing
  • Domain 2: Information security policy for cloud computing and documented information management
  • Domain 3: Cloud computing security risk management
  • Domain 4: Cloud-specific controls based on ISO/IEC 27017 and ISO/IEC 27018 and best practices
  • Domain 5: Cloud security awareness, training, roles, and responsibilities
  • Domain 6: Cloud security incident management
  • Domain 7: Cloud security testing, monitoring, and continual improvement

Certification Rules and Policies

The requirements for PECB Cloud Security Manager Certifications are as follows:

The cloud security project experience should follow best implementation and management practices and include the following activities:

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational approach

  • The training course contains essay-type exercises, multiple-choice quizzes, and examples of cloud security best practices.
  • The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
  • The exercises are based on a case study.
  • The structure of the quizzes is similar to that of the certification exam.

Buyers always ask

What is the difference between completing this training and becoming a PECB Certified Lead Cloud Security Manager?+

Completing this training course means you have participated in all scheduled learning activities. Earning the PECB Certified Lead Cloud Security Manager credential requires passing the PECB exam and meeting any professional-experience criteria set by PECB under their Examination and Certification Program.

Cyber Academy provides the training; exam registration and certification applications are managed separately through PECB.

Which standards form the technical foundation of this programme?+

The programme is built around ISO/IEC 27017, which provides security controls for cloud services, and ISO/IEC 27018, which focuses on the protection of personally identifiable information in public cloud environments. Both standards are examined in relation to ISO/IEC 27001 and other relevant regulatory frameworks.

Together, they give participants a comprehensive view of cloud security governance from both a technical control and a data protection perspective.

How many domains does the PECB Lead Cloud Security Manager exam cover?+

According to PECB, the exam spans seven competency domains: fundamental cloud computing principles, information security policy and documented information management, cloud security risk management, cloud-specific controls, awareness and training, incident management, and testing with continual improvement.

For details on exam format, available languages, and scheduling, refer to the official PECB List of Exams and Examination Rules and Policies.

Is this course suitable for someone who manages cloud vendors but does not configure cloud services directly?+

Yes. The programme focuses on planning, governing, and managing a cloud security programme rather than on technical configuration tasks. Professionals responsible for vendor oversight, compliance, and risk management will find the risk management, documented information, and incident management content particularly relevant.

A general understanding of cloud computing concepts is recommended so that discussions of cloud-specific controls are meaningful in your context.

How does Day 4 content on incident management differ from general information security incident management?+

Cloud security incident management introduces shared-responsibility considerations that are unique to cloud environments, such as coordinating response activities with cloud service providers, managing incidents that may span multiple tenants, and handling data breach notifications under cloud data protection obligations.

This cloud-specific framing distinguishes the content from generic incident management training and directly reflects the guidance provided in ISO/IEC 27017 and ISO/IEC 27018.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.