Get in Touch
 Duration 21 hours

Course Outline

Module 1. Cloud Architecture

Establishes the fundamentals of cloud computing, covering definitions, architectural frameworks, and the pivotal role of virtualization. Key areas include service models, delivery mechanisms, and core characteristics. It also introduces the Shared Responsibilities Model and provides a framework for approaching cloud security.

Topics Covered:

  • Unit 1 - Introduction to Cloud Computing
  • Unit 2- Introduction & Cloud Architecture
  • Unit 3 - Cloud Essential Characteristics
  • Unit 4 - Cloud Service Models
  • Unit 5 - Cloud Deployment Models
  • Unit 6 - Shared Responsibilities

Module 2. Infrastructure Security for Cloud

Examines the specifics of securing core cloud computing infrastructure, including components, networks, management interfaces, and administrator credentials. It explores virtual networking and workload security, touching on container basics and serverless technologies.

Topics Covered:

  • Unit 1 - Module Intro
  • Unit 2 - Intro to Infrastructure Security for Cloud Computing
  • Unit 3 - Software Defined Networks
  • Unit 4 - Cloud Network Security
  • Unit 5 - Securing Compute Workloads
  • Unit 6 - Management Plane Security
  • Unit 7 - BCDR

Module 3. Managing Cloud Security and Risk

Addresses critical considerations for overseeing security in cloud computing environments. It begins with risk assessment and governance, progressing to legal and compliance matters, such as data discovery requirements in the cloud. It also highlights essential CSA risk tools, including the CAIQ, CCM, and STAR registry.

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Governance
  • Unit 3 - Managing Cloud Security Risk
  • Unit 4 - Legal
  • Unit 5 - Legal Issues In Cloud
  • Unit 6 - Compliance
  • Unit 7 - Audit
  • Unit 8 - CSA Tools

Module 4. Data Security for Cloud Computing

Focuses on information lifecycle management in the cloud and the application of security controls, with a particular emphasis on public cloud environments. Topics include the Data Security Lifecycle, storage models, security challenges across different delivery models, and encryption management within and for the cloud, including customer-managed keys (BYOK).

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Cloud Data Storage
  • Unit 3 - Securing Data In The Cloud
  • Unit 4 - Encryption For IaaS
  • Unit 5 - Encryption For PaaS & SaaS
  • Unit 6 - Encryption Key Management
  • Unit 7 - Other Data Security Options
  • Unit 8 - Data Security Lifecycle

Module 5. Application Security and Identity Management for Cloud Computing

Discusses identity management and application security tailored for cloud deployments. Subjects include federated identity, various IAM applications, secure development practices, and the management of application security within and for cloud environments.

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Secure Software Development Life Cycle (SSDLC)
  • Unit 3 - Testing & Assessment
  • Unit 4 - DevOps
  • Unit 5 - Secure Operations
  • Unit 6 - Identity & Access Management Definitions
  • Unit 7 - IAM Standards
  • Unit 8 - IAM In Practice

Module 6. Cloud Security Operations

Outlines key considerations for evaluating, selecting, and managing cloud computing providers. It also examines the role of Security as a Service (SECaaS) providers and the impact of cloud computing on Incident Response.

Topics Covered:

  • Unit 1 - Module Introduction
  • Unit 2 - Selecting A Cloud Provider
  • Unit 3 - SECaaS Fundamentals
  • Unit 4 - SECaaS Categories
  • Unit 5 - Incident Response
  • Unit 6 - Domain 14 Considerations
  • Unit 7 - CCSK Exam Preparation

Additional material

Core Account Security

Learners identify critical configurations to implement in the initial moments of opening a new cloud account, focusing on enabling security controls like MFA, basic monitoring, and IAM.

IAM and Monitoring In-Depth

Participants build upon initial lab work by implementing more complex identity management and monitoring strategies. This includes expanding IAM with Attribute Based Access Controls, setting up security alerting, and structuring enterprise-scale IAM and monitoring solutions.

Network and Instance Security

Learners construct a virtual network (VPC) and establish a baseline security configuration. They also learn to securely select and launch virtual machines (instances), conduct cloud vulnerability assessments, and establish secure connections to instances.

Encryption and Storage Security

Participants enhance their deployment by adding storage volumes encrypted with customer-managed keys. They also explore methods for securing snapshots and other data assets.

Application Security and Federation

Learners conclude the technical labs by fully deploying a 2-tier application and implementing federated identity using OpenID.

Risk and Provider Assessment

Participants utilize the CSA Cloud Controls Matrix and STAR registry to assess risks and select appropriate cloud providers.

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories