At the end of the course, the participants must be able to:
understand the role and responsibilities of the cloud officer / outsourcing officer
have an overview of the applicable circulars including CSSF Circular 22/806 and the domains covered in this circular. It will enable them to make their choices including gap analysis and remediation actions for conformity with this circular.
understand and demonstrate different service and delivery models of cloud computing
understand and demonstrate the risk management for outsourcing arrangements (ICT, cloud, and business process outsourcing)
understand and demonstrate security aspects and principles of cloud computing
practically manage the outsourcing operations
Role and responsibilities
Based on the European Banking Authority (EBA) guidelines and best practices in the field of outsourcing compliance
CSSF 21/769 (22/804)
Circular 22/806 domains
General principles (including sustainability (ESG))
Assessments of outsourcing arrangements
Requirements in the context of ICT outsourcing arrangements
Cybersecurity, policies, processes, and Risk Management
Governance and strategy
Basics of Risk Management
Risk management of the outsourcing arrangements (ICT, cloud and business process outsourcing)
Policy and processes
Identity and Access management
Examples of cloud security solutions
Business continuity management
Outsourcing and Technologies: Cloud Solution Providers (AWS & AZURE) and other outsourcing use case
Introduction to different service and delivery models of cloud computing.
Introduction to the cloud solution providers
Cloud solution providers
How principles apply (Security options, data encryption…)?
Cascade outsourcing: Organisational and Compliance Aspects
Other outsourcing use cases: SOC, Hosting, Development, …
Compliance practical implications (Circular 22/806 CSSF included)
CSSF notification step by step
Alignment of the governance with the circular
Management body responsibility
Upgrade of existing outsourced functions
Critical or important functions (CIF)
Exit strategy and Business Continuity management
Service provider monitoring process – Outsourcing monitoring framework.
ICT/Security Risk Managers, (C)ISO, Risk Officer, Cloud Officer, Outsourcing Officer, Business Continuity Manager, Compliance Officer, of Banks
Any manager involved in the 2nd Line of defense (such as governance, risk management, compliance, security, business continuity)
The training material will be handed out at the beginning of the course.
The knowledge acquired in the seminar will be validated through an ONLINE examination. The examination is based on a MCQ questionnaire of around 50 questions. The required passing rate is 80%.
By the end of the course participants will receive the link for the examination and will have 5 working days to take it.
At the end of the training, a certificate of attendance will be available either on your client account or on demand to the customer service.
Candidates who successfully complete the examination will receive the following certificate of completion co-signed by the ABBL: "Certified Cloud Officer & Outsourcing Officer"
For further questions please contact our partner in your country
Cloud Officer & Outsourcing Officer - Certified programme
Great course and great instructor!!! The content, the opportunities to ask questions and talk about real life examples made this a really enjoyable and insightful course.
Jean-Hubert was an excellent instructor. He balanced everyone’s varying levels of experience well throughout the course.
I really expanded my knowledge regarding cloud technology and outsourcing.
Hermiona Jolle - Albania