Implement security solutions for cloud services LEGACY

URN: TECIS40945L
Business Sectors (Suites): IT and Telecoms Professional (procom)
Developed by: e-skills
Approved on: 30 Mar 2017

Overview

This standard concerns mitigating the cyber security risks associated with cloud services infrastructure. This includes implementing security solutions in line with organisational cloud security policies and the associated security challenges. It also includes the main requirements to move current cloud untrusted infrastructure to a trustworthy Internet-scale cloud computing infrastructure.


Performance criteria

You must be able to:

  1. Develop security cases for cloud services that align to the organisational cloud security strategy
  2. Develop security architectures for public, private, and hybrid cloud based systems in line with organisational requirements
  3. Implement cloud security solutions and controls to mitigate security risks in line with organisational security policies and regulatory requirements
  4. Audit the compliance of cloud services security in line with regulatory, legislative and organisational policies and standards
  5. Assess the impact of a cloud services security failure or breach to business operations
  6. Report cloud security status to business stakeholders in line with organisational standards

Knowledge and Understanding

You need to know and understand:

  1. The security risks associated with cloud services and how these can be mitigated
  2. The security solutions and controls that can be applied to reduce risk
  3. The procedures to follow when auditing cloud services for security compliance
  4. Why an impact analysis needs to be undertaken for all security breaches to cloud services
  5. The factors involved in undertaking a security risk assessment for cloud services
  6. The legal and regulatory requirements for cloud services security compliance
  7. The organisation's policies and standards for cloud services security

Scope/range


Scope Performance


Scope Knowledge


Values


Behaviours


Skills


Glossary


Links To Other NOS


External Links


Version Number

1

Indicative Review Date

31 Mar 2020

Validity

Legacy

Status

Original

Originating Organisation

The Tech Partnership

Original URN

TECIS40945

Relevant Occupations

Information and Communication Technology, Information and Communication Technology Officer, Information and Communication Technology Professionals

SOC Code

2135

Keywords

Cloud security