Get in Touch

Course Outline

Module 1. Cloud Architecture

This section establishes the fundamentals of cloud computing, covering definitions, architectural models, and the role of virtualization. Key areas of focus include service models, delivery models, and core characteristics. It also introduces the Shared Responsibilities Model and provides a framework for approaching cloud security systematically.

Topics Covered:

  • Unit 1 - Introduction to Cloud Computing
  • Unit 2- Introduction & Cloud Architecture
  • Unit 3 - Cloud Essential Characteristics
  • Unit 4 - Cloud Service Models
  • Unit 5 - Cloud Deployment Models
  • Unit 6 - Shared Responsibilities

Module 2. Infrastructure Security for Cloud

This module delves into securing core cloud infrastructure, including components, networks, management interfaces, and administrator credentials. It explores virtual networking and workload security, with an introduction to containers and serverless technologies.

Topics Covered:

  • Unit 1 - Module Intro
  • Unit 2 - Intro to Infrastructure Security for Cloud Computing
  • Unit 3 - Software Defined Networks
  • Unit 4 - Cloud Network Security
  • Unit 5 - Securing Compute Workloads
  • Unit 6 - Management Plane Security
  • Unit 7 - BCDR

Module 3. Managing Cloud Security and Risk

Addressing critical considerations for cloud security management, this module begins with risk assessment and governance. It proceeds to cover legal and compliance matters, such as discovery requirements, and introduces key CSA risk tools, including the CAIQ, CCM, and STAR registry.

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Governance
  • Unit 3 - Managing Cloud Security Risk
  • Unit 4 - Legal
  • Unit 5 - Legal Issues In Cloud
  • Unit 6 - Compliance
  • Unit 7 - Audit
  • Unit 8 - CSA Tools

Module 4. Data Security for Cloud Computing

Focusing on information lifecycle management in the cloud, this module demonstrates how to apply security controls, with a specific emphasis on public cloud environments. Topics include the Data Security Lifecycle, storage models, security challenges across different delivery models, and managing encryption, including customer managed keys (BYOK).

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Cloud Data Storage
  • Unit 3 - Securing Data In The Cloud
  • Unit 4 - Encryption For IaaS
  • Unit 5 - Encryption For PaaS & SaaS
  • Unit 6 - Encryption Key Management
  • Unit 7 - Other Data Security Options
  • Unit 8 - Data Security Lifecycle

Module 5. Application Security and Identity Management for Cloud Computing

This module covers identity management and application security tailored for cloud deployments. Key topics include federated identity, various IAM applications, secure development practices, and strategies for managing application security within the cloud environment.

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Secure Software Development Life Cycle (SSDLC)
  • Unit 3 - Testing & Assessment
  • Unit 4 - DevOps
  • Unit 5 - Secure Operations
  • Unit 6 - Identity & Access Management Definitions
  • Unit 7 - IAM Standards
  • Unit 8 - IAM In Practice

Module 6. Cloud Security Operations

This section outlines key considerations for evaluating, selecting, and managing cloud service providers. It also discusses the role of Security as a Service (SECaaS) providers and the impact of cloud computing on Incident Response strategies.

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Selecting A Cloud Provider
  • Unit 3 - SECaaS Fundamentals
  • Unit 4 - SECaaS Categories
  • Unit 5 - Incident Response
  • Unit 6 - Domain 14 Considerations
  • Unit 7 - CCSK Exam Preparation

Additional material

Core Account Security

Participants learn essential configurations to perform in the initial minutes of opening a new cloud account, including enabling MFA, basic monitoring, and IAM controls.

IAM and Monitoring In-Depth

Building on the initial lab, attendees implement more complex identity management and monitoring solutions. This includes expanding IAM with Attribute Based Access Controls, setting up security alerting, and structuring enterprise-scale IAM and monitoring systems.

Network and Instance Security

Students create a virtual network (VPC) and establish a baseline security configuration. They also learn to securely select and launch virtual machines, conduct vulnerability assessments in the cloud, and connect to instances safely.

Encryption and Storage Security

Participants extend their deployment by adding encrypted storage volumes using customer managed keys. They also explore methods for securing snapshots and other data assets.

Application Security and Federation

In the final technical labs, students build a complete 2-tier application and implement federated identity using OpenID.

Risk and Provider Assessment

Students utilize the CSA Cloud Controls Matrix and STAR registry to evaluate risk and select appropriate cloud providers.

 21 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 3900 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories