Get in Touch
 Duration 21 hours

Course Outline

Module 1. Cloud Architecture

Explores the principles of cloud computing, including definitions, architectural frameworks, and the significance of virtualization. Key areas include cloud computing service models, delivery methods, and essential characteristics. The module also introduces the Shared Responsibilities Model and establishes a framework for addressing cloud security.

Covered Topics:

  • Unit 1 - Introduction to Cloud Computing
  • Unit 2- Introduction & Cloud Architecture
  • Unit 3 - Cloud Essential Characteristics
  • Unit 4 - Cloud Service Models
  • Unit 5 - Cloud Deployment Models
  • Unit 6 - Shared Responsibilities

Module 2. Infrastructure Security for Cloud

Examines the specifics of protecting core cloud computing infrastructure, including components, networks, management interfaces, and administrator credentials. It explores virtual networking and workload security, covering the fundamentals of containers and serverless technologies.

Covered Topics:

  • Unit 1 - Module Intro
  • Unit 2 - Intro to Infrastructure Security for Cloud Computing
  • Unit 3 - Software Defined Networks
  • Unit 4 - Cloud Network Security
  • Unit 5 - Securing Compute Workloads
  • Unit 6 - Management Plane Security
  • Unit 7 - BCDR

Module 3. Managing Cloud Security and Risk

Addresss critical considerations for overseeing security in cloud computing environments. It starts with risk assessment and governance, followed by legal and compliance matters, such as discovery requirements within the cloud. The module also highlights key CSA risk management tools, including the CAIQ, CCM, and STAR registry.

Covered Topics:

  • Unit 1 - Module Introduction
  • Unit 2 - Governance
  • Unit 3 - Managing Cloud Security Risk
  • Unit 4 - Legal
  • Unit 5 - Legal Issues In Cloud
  • Unit 6 - Compliance
  • Unit 7 - Audit
  • Unit 8 - CSA Tools

Module 4. Data Security for Cloud Computing

Discusses information lifecycle management in the cloud and the application of security controls, with a focus on public cloud environments. Topics include the Data Security Lifecycle, cloud storage models, data security challenges associated with various delivery models, and managing encryption in and for the cloud, including customer managed keys (BYOK).

Covered Topics:

  • Unit 1 - Module Introduction
  • Unit 2 - Cloud Data Storage
  • Unit 3 - Securing Data In The Cloud
  • Unit 4 - Encryption For IaaS
  • Unit 5 - Encryption For PaaS & SaaS
  • Unit 6 - Encryption Key Management
  • Unit 7 - Other Data Security Options
  • Unit 8 - Data Security Lifecycle

Module 5. Application Security and Identity Management for Cloud Computing

Focuses on identity management and application security within cloud deployments. Subjects include federated identity, various IAM applications, secure development practices, and the management of application security in and for the cloud.

Covered Topics:

  • Unit 1 - Module Introduction
  • Unit 2 - Secure Software Development Life Cycle (SSDLC)
  • Unit 3 - Testing & Assessment
  • Unit 4 - DevOps
  • Unit 5 - Secure Operations
  • Unit 6 - Identity & Access Management Definitions
  • Unit 7 - IAM Standards
  • Unit 8 - IAM In Practice

Module 6. Cloud Security Operations

Considers key factors when evaluating, selecting, and managing cloud computing providers. The discussion also covers the role of Security as a Service providers and the impact of cloud computing on Incident Response.

Covered Topics:

  • Unit 1 - Module Introduction
  • Unit 2 - Selecting A Cloud Provider
  • Unit 3 - SECaaS Fundamentals
  • Unit 4 - SECaaS Categories
  • Unit 5 - Incident Response
  • Unit 6 - Domain 14 Considerations
  • Unit 7 - CCSK Exam Preparation

Additional material

Core Account Security

Learners identify the configurations required within the first 5 minutes of opening a new cloud account and enable security controls such as MFA, basic monitoring, and IAM.

IAM and Monitoring In-Depth

Participants build upon initial lab work by implementing more complex identity management and monitoring strategies. This includes extending IAM with Attribute Based Access Controls, setting up security alerting, and understanding the structure of enterprise-scale IAM and monitoring.

Network and Instance Security

Students design a virtual network (VPC) and apply baseline security configurations. They also learn how to securely select and launch a virtual machine (instance), conduct vulnerability assessments in the cloud, and establish connections to the instance.

Encryption and Storage Security

Learners enhance their deployment by adding a storage volume encrypted with a customer managed key. They also examine methods for securing snapshots and other data assets.

Application Security and Federation

Students conclude the technical labs by fully constructing a 2-tier application and implementing federated identity using OpenID.

Risk and Provider Assessment

Participants utilize the CSA Cloud Controls Matrix and STAR registry to evaluate risks and select an appropriate cloud provider.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 4800 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories