Course Outline
Module 1. Cloud Architecture
Establishes the basics of cloud computing, covering definitions, architectural structures, and the role of virtualization. Key areas include service models, delivery models, and fundamental cloud characteristics. The module also introduces the Shared Responsibilities Model and a framework for approaching cloud security.
Topics Covered:
- Unit 1 - Introduction to Cloud Computing
- Unit 2- Introduction & Cloud Architecture
- Unit 3 - Cloud Essential Characteristics
- Unit 4 - Cloud Service Models
- Unit 5 - Cloud Deployment Models
- Unit 6 - Shared Responsibilities
Module 2. Infrastructure Security for Cloud
Examines the secure configuration of core cloud infrastructure, including cloud components, networks, management interfaces, and administrator credentials. It further explores virtual networking and workload security, introducing the fundamentals of containers and serverless architectures.
Topics Covered:
- Unit 1 - Module Intro
- Unit 2 - Intro to Infrastructure Security for Cloud Computing
- Unit 3 - Software Defined Networks
- Unit 4 - Cloud Network Security
- Unit 5 - Securing Compute Workloads
- Unit 6 - Management Plane Security
- Unit 7 - BCDR
Module 3. Managing Cloud Security and Risk
Addresses critical aspects of cloud security management. It starts with risk assessment and governance, followed by legal and compliance considerations, such as data discovery requirements in the cloud environment. The module also highlights key CSA risk tools, including the CAIQ, CCM, and STAR registry.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Governance
- Unit 3 - Managing Cloud Security Risk
- Unit 4 - Legal
- Unit 5 - Legal Issues In Cloud
- Unit 6 - Compliance
- Unit 7 - Audit
- Unit 8 - CSA Tools
Module 4. Data Security for Cloud Computing
Focuses on information lifecycle management within the cloud and the application of security controls, with a particular emphasis on public cloud environments. Topics include the Data Security Lifecycle, cloud storage models, security challenges associated with different delivery models, and encryption management, including customer-managed keys (BYOK).
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Cloud Data Storage
- Unit 3 - Securing Data In The Cloud
- Unit 4 - Encryption For IaaS
- Unit 5 - Encryption For PaaS & SaaS
- Unit 6 - Encryption Key Management
- Unit 7 - Other Data Security Options
- Unit 8 - Data Security Lifecycle
Module 5. Application Security and Identity Management for Cloud Computing
Explores identity management and application security strategies for cloud deployments. The curriculum covers federated identity, various IAM applications, secure development practices, and the management of application security within the cloud ecosystem.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Secure Software Development Life Cycle (SSDLC)
- Unit 3 - Testing & Assessment
- Unit 4 - DevOps
- Unit 5 - Secure Operations
- Unit 6 - Identity & Access Management Definitions
- Unit 7 - IAM Standards
- Unit 8 - IAM In Practice
Module 6. Cloud Security Operations
Highlights key factors in evaluating, selecting, and managing cloud service providers. It also discusses the role of Security as a Service (SECaaS) providers and the impact of cloud environments on Incident Response strategies.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Selecting A Cloud Provider
- Unit 3 - SECaaS Fundamentals
- Unit 4 - SECaaS Categories
- Unit 5 - Incident Response
- Unit 6 - Domain 14 Considerations
- Unit 7 - CCSK Exam Preparation
Additional material
Core Account Security
Participants learn the essential configurations to perform during the initial minutes of creating a new cloud account, enabling security controls such as MFA, basic monitoring, and IAM.
IAM and Monitoring In-Depth
Building on the initial lab, attendees implement more complex identity management and monitoring solutions. This includes extending IAM with Attribute Based Access Controls, configuring security alerting, and structuring enterprise-scale IAM and monitoring systems.
Network and Instance Security
Participants design a virtual network (VPC) and establish a baseline security configuration. They also learn to securely select and launch virtual machines, conduct cloud vulnerability assessments, and establish secure connections to instances.
Encryption and Storage Security
Participants enhance their deployment by integrating storage volumes encrypted with customer-managed keys. The module also covers securing snapshots and other data assets.
Application Security and Federation
Concluding the technical labs, participants build a complete two-tier application and implement federated identity using OpenID.
Risk and Provider Assessment
Participants utilize the CSA Cloud Controls Matrix and STAR registry to evaluate risks and make informed decisions when selecting cloud providers.
Testimonials (1)
A wide range of knowledge of the lecturer.