Course Outline
Module 1. Cloud Architecture
This module establishes the foundational principles of cloud computing, defining core architectures and the critical role of virtualization. It examines key service and delivery models alongside fundamental cloud characteristics. Additionally, it introduces the Shared Responsibilities Model and provides a structured framework for approaching cloud security governance for government entities.
Topics Covered:
- Unit 1 - Introduction to Cloud Computing
- Unit 2 - Introduction & Cloud Architecture
- Unit 3 - Cloud Essential Characteristics
- Unit 4 - Cloud Service Models
- Unit 5 - Cloud Deployment Models
- Unit 6 - Shared Responsibilities
Module 2. Infrastructure Security for Cloud
This section details the securing of core cloud infrastructure, encompassing cloud components, network architectures, management interfaces, and the administration of credentials. It further explores virtual networking and workload security, covering the fundamentals of containers and serverless computing to ensure robust operational security for government applications.
Topics Covered:
- Unit 1 - Module Intro
- Unit 2 - Intro to Infrastructure Security for Cloud Computing
- Unit 3 - Software Defined Networks
- Unit 4 - Cloud Network Security
- Unit 5 - Securing Compute Workloads
- Unit 6 - Management Plane Security
- Unit 7 - BCDR
Module 3. Managing Cloud Security and Risk
This module addresses critical considerations for governing cloud security. It begins with risk assessment and governance frameworks, progressing to legal and compliance obligations, including discovery requirements in cloud environments. It also introduces essential Cloud Security Alliance (CSA) risk management tools, such as the CAIQ, CCM, and STAR registry, to support accountability for government operations.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Governance
- Unit 3 - Managing Cloud Security Risk
- Unit 4 - Legal
- Unit 5 - Legal Issues In Cloud
- Unit 6 - Compliance
- Unit 7 - Audit
- Unit 8 - CSA Tools
Module 4. Data Security for Cloud Computing
Focusing on public cloud environments, this module covers information lifecycle management and the application of security controls. Key topics include the Data Security Lifecycle, cloud storage models, and data security challenges associated with various delivery models. It also addresses encryption management, including the implementation of customer-managed keys (BYOK) to protect sensitive government data for government compliance standards.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Cloud Data Storage
- Unit 3 - Securing Data In The Cloud
- Unit 4 - Encryption For IaaS
- Unit 5 - Encryption For PaaS & SaaS
- Unit 6 - Encryption Key Management
- Unit 7 - Other Data Security Options
- Unit 8 - Data Security Lifecycle
Module 5. Application Security and Identity Management for Cloud Computing
This module examines identity management and application security within cloud deployments. It covers federated identity systems, Identity and Access Management (IAM) applications, and secure development practices. Participants will learn to manage application security effectively, ensuring that software components meet rigorous standards for government use.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Secure Software Development Life Cycle (SSDLC)
- Unit 3 - Testing & Assessment
- Unit 4 - DevOps
- Unit 5 - Secure Operations
- Unit 6 - Identity & Access Management Definitions
- Unit 7 - IAM Standards
- Unit 8 - IAM In Practice
Module 6. Cloud Security Operations
This module outlines key considerations for evaluating, selecting, and managing cloud computing providers. It also discusses the role of Security as a Service (SECaaS) providers and the impact of cloud environments on Incident Response capabilities, emphasizing best practices for government incident management.
Topics Covered:
- Unit 1 - Module Introduction
- Unit 2 - Selecting A Cloud Provider
- Unit 3 - SECaaS Fundamentals
- Unit 4 - SECaaS Categories
- Unit 5 - Incident Response
- Unit 6 - Domain 14 Considerations
- Unit 7 - CCSK Exam Preparation
Additional material
Core Account Security
Participants learn essential initial configurations to secure a new cloud account, including enabling Multi-Factor Authentication (MFA), basic monitoring, and Identity and Access Management (IAM) controls for government systems.
IAM and Monitoring In-Depth
Participants build upon initial lab work to implement complex identity management and monitoring strategies. This includes expanding IAM with Attribute-Based Access Controls (ABAC), implementing security alerting, and structuring enterprise-scale IAM and monitoring for government infrastructure.
Network and Instance Security
Participants configure a Virtual Private Cloud (VPC) and implement baseline security settings. The module also covers the secure selection and launch of virtual machine instances, conducting vulnerability assessments, and establishing secure connections for government workloads.
Encryption and Storage Security
Participants extend their deployment by adding encrypted storage volumes using customer-managed keys. They also learn methods to secure snapshots and other data assets to maintain integrity for government records.
Application Security and Federation
Participants complete technical labs by constructing a two-tier application and implementing federated identity using OpenID, ensuring seamless and secure access management for government platforms.
Risk and Provider Assessment
Participants utilize the CSA Cloud Controls Matrix and STAR registry to evaluate risk profiles and select cloud providers that meet the stringent requirements for government services.
Testimonials (1)
A wide range of knowledge of the lecturer.