Cloud Computing Security Knowledge

Course

Online

Save 60%

Special Emagister price

£ 195 £ 495 VAT inc.

Description

  • Type

    Course

  • Methodology

    Online

  • Start date

    Different dates available

"Course Description

As cloud computing shows itself to be the future of information technology, several studies have pointed to the necessity of addressing the IT industry's skills gap and training professionals in both cloud computing and security.

Cloud computing is being aggressively adopted on a global basis as businesses seek to reduce costs and improve their agility. And one of the critical needs of the industry is to provide training and certification of professionals to assure that cloud computing is implemented responsibly, and with the appropriate security controls.

My Training Academy's Cloud Computing Security Knowledge course provides students thorough coverage of cloud security fundamentals and prepares them to take the Cloud Security Alliance CCSK certification exam. The course begins with a detailed description of cloud computing and then expands into all major domains such as; Governance and Risk Management, the Cloud Architectural Framework and Business Continuity/Disaster Recovery

The course is of particular interest to:

IT infrastructure managers who need to understand and plan for Cloud adoption.
IT professionals who need to better understand Cloud technologies.
IT systems engineers who need to understand Cloud configuration, deployment and support.
Professionals working within the Cloud IT sector who want to achieve the vendor neutral Cloud Security CCSK qualification.

Upon completing this course, the students will be experts in the following topics:

Pass the CCSK Exam
Understanding cloud computing security challenges
Cloud computing security controls recommendation
Elasticity, Resiliency and Measured Usage
Understand the cloud computing architectural framework

The course has been designed to give you real-world knowledge that you can put to use from day one. It's highly flexible, so you can set your own timetable and study at your own pace. 
"

Important information

Price for Emagister users:

Facilities

Location

Start date

Online

Start date

Different dates availableEnrolment now open

About this course

"Requirements

Our training works on all devices including Mobile phones, IPad’s, Android tablets, Macs and PC’s.

For the best viewing experience on our state-of-the-art eLearning platform we recommend an internet connection of 10Mbps or better. Please also use Google Chrome or Mozilla Firefox as your browser with Adobe Flash Player."

Questions & Answers

Add your question

Our advisors and other users will be able to reply to you

Fill in your details to get a reply

We will only publish your name and question

Reviews

Subjects

  • Business Continuity
  • Risk
  • Monitoring
  • Access
  • Contracts
  • Compliance
  • Risk Management
  • Governance
  • Audit
  • Benefits
  • Computing
  • Database
  • Database training
  • Network
  • Network security
  • Communications
  • Systems
  • Industry
  • IT risk
  • Network Training

Course programme

"

Course Outline


Course Outline

Course Syllabus

1: Architecture

  • NIST Definitions
  • Essential Characteristics
  • Service Models
  • Deployment Models
  • Multi-Tenancy
  • CSA Cloud Reference Model
  • Jericho Cloud Cube Model
  • Cloud Security Reference Model
  • Cloud Service Brokers
  • Service Level Agreements

2: Governance and Enterprise Risk Management

  • Contractual Security Requirements
  • Enterprise and Information Risk Management
  • Third Party Management Recommendations
  • Supply chain examination
  • Use of Cost Savings for Cloud

3: Legal Issues: Contracts and Electronic Discovery

  • Consideration of cloud-related issues in three dimensions
  • E-Discovery considerations
  • Jurisdictions and data locations
  • Liability for activities of subcontractors
  • Due diligence responsibility
  • Federal Rules of Civil Procedure and electronically stored information
  • Metadata
  • Litigation hold

4: Compliance and Audit Management

  • Definition of Compliance
  • Right to audit
  • Compliance impact on cloud contracts
  • Audit scope and compliance scope
  • Compliance analysis requirements
  • Auditor requirements

5: Information Management and Data Security

  • Six phases of the Data Security Lifecycle and their key elements
  • Volume storage
  • Object storage
  • Logical vs physical locations of data
  • Three valid options for protecting data
  • Data Loss Prevention
  • Detection Data Migration to the Cloud
  • Encryption in IaaS, PaaS & SaaS
  • Database Activity Monitoring and File Activity Monitoring
  • Data Backup
  • Data Dispersion
  • Data Fragmentation

6: Interoperability and Portability

  • Definitions of Portability and Interoperability
  • Virtualization impacts on Portability and Interoperability
  • SAML and WS-Security
  • Size of Data Sets
  • Lock-In considerations by IaaS, PaaS & SaaS delivery models
  • Mitigating hardware compatibility issues

7: Traditional Security, Business Continuity, and Disaster Recovery

  • Four D's of perimeter security
  • Cloud backup and disaster recovery services
  • Customer due diligence related to BCM/DR
  • Business Continuity Management/Disaster Recovery due diligence
  • Restoration Plan
  • Physical location of cloud provider

8: Data Center Operations

  • Relation to Cloud Controls Matrix
  • Queries run by data center operators
  • Technical aspects of a Provider's data center operations for customers
  • Logging and report generation in multi-site clouds

9: Incident Response

  • Factor allowing for more efficient and effective containment and recovery in a cloud
  • Main data source for detection and analysis of an incident
  • Investigating and containing an incident in an Infrastructure as a Service environment
  • Reducing the occurrence of application level incidents
  • How often should incident response testing occur
  • Offline analysis of potential incidents

10: Application Security

  • Identity, entitlement, and access management (IdEA)
  • SDLC impact and implications
  • Differences in S-P-I models
  • Consideration when performing a remote vulnerability test of a cloud-based application
  • Categories of security monitoring for applications
  • Entitlement matrix

11: Encryption and Key Management

  • Adequate encryption protection of data in the cloud
  • Key management best practices, location of keys, keys per user
  • Relationship to tokenization, masking, anonymization and cloud database controls

12: Identity, Entitlement, and Access Management

  • Relationship between identities and attributes
  • Identity Federation
  • Relationship between Policy Decision Point (PDP) and Policy Enforcement Point (PEP)
  • SAML and WS-Federation
  • Provisioning and authoritative sources

13: Virtualization

  • Security concerns for hypervisor architecture
  • VM guest hardening, blind spots, VM Sprawl, data Commingling, instant-on gaps
  • In-Motion VM characteristics that can create a serious complexity for audits
  • How can virtual machine communications bypass network security controls
  • VM attack surfaces
  • Compartmentalization of VMs

14: Security as a Service

  • 10 categories
  • Barriers to developing full confidence in security as a service (SECaaS)
  • Deployment of Security as a Service in a regulated industry prior SLA
  • Logging and reporting implications
  • How can web security as a service be deployed
  • What measures do Security as a Service providers take to earn the trust of their customers
  • ENISA Cloud Computing: Benefits, Risks and Recommendations for Information Security
  • Isolation failure
  • Economic Denial of Service
  • Licensing Risks
  • VM hopping
  • Five key legal issues common across all scenarios
  • Top security risks in ENISA research
  • OVF
  • Underlying vulnerability in Loss of Governance
  • User provisioning vulnerability
  • Risk concerns of a cloud provider being acquired
  • Security benefits of cloud
  • Risks
  • Data controller vs data processor definitions in Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring


Course Syllabus

1: Architecture


1: Architecture
  • NIST Definitions
  • Essential Characteristics
  • Service Models
  • Deployment Models
  • Multi-Tenancy
  • CSA Cloud Reference Model
  • Jericho Cloud Cube Model
  • Cloud Security Reference Model
  • Cloud Service Brokers
  • Service Level Agreements

  • NIST Definitions

  • Essential Characteristics

  • Service Models

  • Deployment Models

  • Multi-Tenancy

  • CSA Cloud Reference Model

  • Jericho Cloud Cube Model

  • Cloud Security Reference Model

  • Cloud Service Brokers

  • Service Level Agreements

  • 2: Governance and Enterprise Risk Management


    2: Governance and Enterprise Risk Management
    • Contractual Security Requirements
    • Enterprise and Information Risk Management
    • Third Party Management Recommendations
    • Supply chain examination
    • Use of Cost Savings for Cloud

  • Contractual Security Requirements

  • Enterprise and Information Risk Management

  • Third Party Management Recommendations

  • Supply chain examination

  • Use of Cost Savings for Cloud

  • 3: Legal Issues: Contracts and Electronic Discovery


    3: Legal Issues: Contracts and Electronic Discovery
    • Consideration of cloud-related issues in three dimensions
    • E-Discovery considerations
    • Jurisdictions and data locations
    • Liability for activities of subcontractors
    • Due diligence responsibility
    • Federal Rules of Civil Procedure and electronically stored information
    • Metadata
    • Litigation hold

  • Consideration of cloud-related issues in three dimensions

  • E-Discovery considerations

  • Jurisdictions and data locations

  • Liability for activities of subcontractors

  • Due diligence responsibility

  • Federal Rules of Civil Procedure and electronically stored information

  • Metadata

  • Litigation hold

  • 4: Compliance and Audit Management


    4: Compliance and Audit Management
    • Definition of Compliance
    • Right to audit
    • Compliance impact on cloud contracts
    • Audit scope and compliance scope
    • Compliance analysis requirements
    • Auditor requirements

  • Definition of Compliance

  • Right to audit

  • Compliance impact on cloud contracts

  • Audit scope and compliance scope

  • Compliance analysis requirements

  • Auditor requirements

  • 5: Information Management and Data Security


    5: Information Management and Data Security
    • Six phases of the Data Security Lifecycle and their key elements
    • Volume storage
    • Object storage
    • Logical vs physical locations of data
    • Three valid options for protecting data
    • Data Loss Prevention
    • Detection Data Migration to the Cloud
    • Encryption in IaaS, PaaS & SaaS
    • Database Activity Monitoring and File Activity Monitoring
    • Data Backup
    • Data Dispersion
    • Data Fragmentation

  • Six phases of the Data Security Lifecycle and their key elements

  • Volume storage

  • Object storage

  • Logical vs physical locations of data

  • Three valid options for protecting data

  • Data Loss Prevention

  • Detection Data Migration to the Cloud

  • Encryption in IaaS, PaaS & SaaS

  • Database Activity Monitoring and File Activity Monitoring

  • Data Backup

  • Data Dispersion

  • Data Fragmentation

  • 6: Interoperability and Portability


    6: Interoperability and Portability
    • Definitions of Portability and Interoperability
    • Virtualization impacts on Portability and Interoperability
    • SAML and WS-Security
    • Size of Data Sets
    • Lock-In considerations by IaaS, PaaS & SaaS delivery models
    • Mitigating hardware compatibility issues

  • Definitions of Portability and Interoperability

  • Virtualization impacts on Portability and Interoperability

  • SAML and WS-Security

  • Size of Data Sets

  • Lock-In considerations by IaaS, PaaS & SaaS delivery models

  • Mitigating hardware compatibility issues

  • 7: Traditional Security, Business Continuity, and Disaster Recovery


    7: Traditional Security, Business Continuity, and Disaster Recovery
    • Four D's of perimeter security
    • Cloud backup and disaster recovery services
    • Customer due diligence related to BCM/DR
    • Business Continuity Management/Disaster Recovery due diligence
    • Restoration Plan
    • Physical location of cloud provider

  • Four D's of perimeter security

  • Cloud backup and disaster recovery services

  • Customer due diligence related to BCM/DR

  • Business Continuity Management/Disaster Recovery due diligence

  • Restoration Plan

  • Physical location of cloud provider

  • 8: Data Center Operations


    8: Data Center Operations
    • Relation to Cloud Controls Matrix
    • Queries run by data center operators
    • Technical aspects of a Provider's data center operations for customers
    • Logging and report generation in multi-site clouds

  • Relation to Cloud Controls Matrix

  • Queries run by data center operators

  • Technical aspects of a Provider's data center operations for customers

  • Logging and report generation in multi-site clouds

  • 9: Incident Response


    9: Incident Response
    • Factor allowing for more efficient and effective containment and recovery in a cloud
    • Main data source for detection and analysis of an incident
    • Investigating and containing an incident in an Infrastructure as a Service environment
    • Reducing the occurrence of application level incidents
    • How often should incident response testing occur
    • Offline analysis of potential incidents

  • Factor allowing for more efficient and effective containment and recovery in a cloud

  • Main data source for detection and analysis of an incident

  • Investigating and containing an incident in an Infrastructure as a Service environment

  • Reducing the occurrence of application level incidents

  • How often should incident response testing occur

  • Offline analysis of potential incidents

  • 10: Application Security


    10: Application Security
    • Identity, entitlement, and access management (IdEA)
    • SDLC impact and implications
    • Differences in S-P-I models
    • Consideration when performing a remote vulnerability test of a cloud-based application
    • Categories of security monitoring for applications
    • Entitlement matrix

  • Identity, entitlement, and access management (IdEA)

  • SDLC impact and implications

  • Differences in S-P-I models

  • Consideration when performing a remote vulnerability test of a cloud-based application

  • Categories of security monitoring for applications

  • Entitlement matrix

  • 11: Encryption and Key Management


    11: Encryption and Key Management
    • Adequate encryption protection of data in the cloud
    • Key management best practices, location of keys, keys per user
    • Relationship to tokenization, masking, anonymization and cloud database controls

  • Adequate encryption protection of data in the cloud

  • Key management best practices, location of keys, keys per user

  • Relationship to tokenization, masking, anonymization and cloud database controls

  • 12: Identity, Entitlement, and Access Management


    12: Identity, Entitlement, and Access Management
    • Relationship between identities and attributes
    • Identity Federation
    • Relationship between Policy Decision Point (PDP) and Policy Enforcement Point (PEP)
    • SAML and WS-Federation
    • Provisioning and authoritative sources

  • Relationship between identities and attributes

  • Identity Federation

  • Relationship between Policy Decision Point (PDP) and Policy Enforcement Point (PEP)

  • SAML and WS-Federation

  • Provisioning and authoritative sources

  • 13: Virtualization


    13: Virtualization
    • Security concerns for hypervisor architecture
    • VM guest hardening, blind spots, VM Sprawl, data Commingling, instant-on gaps
    • In-Motion VM characteristics that can create a serious complexity for audits
    • How can virtual machine communications bypass network security controls
    • VM attack surfaces
    • Compartmentalization of VMs

  • Security concerns for hypervisor architecture

  • VM guest hardening, blind spots, VM Sprawl, data Commingling, instant-on gaps

  • In-Motion VM characteristics that can create a serious complexity for audits

  • How can virtual machine communications bypass network security controls

  • VM attack surfaces

  • Compartmentalization of VMs

  • 14: Security as a Service


    14: Security as a Service
    • 10 categories
    • Barriers to developing full confidence in security as a service (SECaaS)
    • Deployment of Security as a Service in a regulated industry prior SLA
    • Logging and reporting implications
    • How can web security as a service be deployed
    • What measures do Security as a Service providers take to earn the trust of their customers
    • ENISA Cloud Computing: Benefits, Risks and Recommendations for Information Security
    • Isolation failure
    • Economic Denial of Service
    • Licensing Risks
    • VM hopping
    • Five key legal issues common across all scenarios
    • Top security risks in ENISA research
    • OVF
    • Underlying vulnerability in Loss of Governance
    • User provisioning vulnerability
    • Risk concerns of a cloud provider being acquired
    • Security benefits of cloud
    • Risks
    • Data controller vs data processor definitions in Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring

  • 10 categories

  • Barriers to developing full confidence in security as a service (SECaaS)

  • Deployment of Security as a Service in a regulated industry prior SLA

  • Logging and reporting implications

  • How can web security as a service be deployed

  • What measures do Security as a Service providers take to earn the trust of their customers

  • ENISA Cloud Computing: Benefits, Risks and Recommendations for Information Security

  • Isolation failure

  • Economic Denial of Service

  • Licensing Risks

  • VM hopping

  • Five key legal issues common across all scenarios

  • Top security risks in ENISA research

  • OVF

  • Underlying vulnerability in Loss of Governance

  • User provisioning vulnerability

  • Risk concerns of a cloud provider being acquired

  • Security benefits of cloud

  • Risks

  • Data controller vs data processor definitions in Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring

  • "

    Cloud Computing Security Knowledge

    Special Emagister price

    £ 195 £ 495 VAT inc.