Covering all 12 domains of critical cloud security knowledge, this CCSK+ v5 course covers the core concepts, best practices, and recommendations for securing an organization on the cloud regardless of the provider or platform, with hands-on labs.
Learn and practice applying the knowledge from all 12 domains of the Cloud Security Alliance (CSA) Security Guidance v5.
There are no prerequisites for this course.
Domain 1: Cloud Computing Concepts & Architectures
Describes and defines cloud computing, sets baseline terminology, and details the overall controls, deployment, and architectural models.
Learning Objectives
Domain 2: Cloud Governance
Focuses on cloud governance with an emphasis on the role of security and how enterprise governance helps align the strategic, tactical, and operational capabilities of information and technology with the business objectives.
Learning Objectives
Domain 3: Risk, Audit, & Compliance
Focuses on cloud security, risk, audit, and compliance, including evaluating cloud service providers and establishing cloud risk registries.
Learning Objectives
Domain 4: Organization Management
Focuses on managing your entire cloud footprint, including securing and validating service provider deployments.
Learning Objectives
Domain 5: Identity & Access Management
Focuses primarily on IAM between an organization and cloud providers or between cloud providers and services.
Learning Objectives
Domain 6: Security Monitoring
Presents unique security monitoring challenges and solutions for cloud environments, emphasizing the distinct aspects of cloud telemetry, management plane logs, service and resource logs, and the integration of advanced monitoring tools.
Learning Objectives
Domain 7: Infrastructure & Networking
Focuses on managing the overall infrastructure footprint and network security, including the CSP's infrastructure security responsibilities.
Learning Objectives
Domain 8: Cloud Workload Security
Focuses on the related set of software and data units that are deployable on some type of infrastructure or platform.
Learning Objectives
Domain 9: Data Security
Addresses the complexities of data security in the cloud, covering essential strategies, tools, and practices for protecting data in transit and at rest.
Learning Objectives
Domain 10: Application Security
Focuses on the unique challenges and opportunities presented by application security in the cloud environment from the initial design phase to ongoing maintenance.
Learning Objectives
Domain 11: Incident Response & Resilience
Focuses on identifying and explaining best practices for cloud incident response and resilience that security professionals may reference when developing their own incident plans and processes.
Learning Objectives
Domain 12: Related Technologies & Strategies
Introduces the foundational concepts and focuses on developing a strategic cybersecurity approach to Zero Trust and Artificial Intelligence.
Learning Objectives
Lab Material Outline
Learn what to configure in the first 5 minutes of opening a new cloud account and enable security controls such as MFA, basic monitoring, and IAM.
Expand on your work in the first lab and implement more-complex identity management and monitoring. This includes expanding IAM with Attribute Based Access Controls, implementing security alerting, and understanding how to structure enterprise-scale IAM and monitoring.
Create a virtual network (VPC) and implement a baseline security configuration. You will also learn how to securely select and launch a virtual machine (instance), run a vulnerability assessment in the cloud, and connect to the instance.
Expand your deployment by adding a storage volume encrypted with a customer managed key. You will also learn how to secure snapshots and other data.
Finish the technical labs by completely building out a 2-tier application and implementing federated identity using OpenID.
Practice using the CSA Cloud Controls Matrix and STAR registry to evaluate risk and select a cloud provider.
Join our public courses in our Hong Kong facilities. Private class trainings will be organized at the location of your preference, according to your schedule.