Cloud breaches are almost never a provider failure — they are a customer identity and configuration failure. Learn to draw the trust boundary, harden everything inside it, and prove it stayed hardened.
Overview
Syllabus
Module 1
- Draw the Boundary: Cloud Security Architecture Foundations
- Service and deployment models
- Security design principles
- Assets, resources and trust boundaries
- Shared responsibility
- Control ownership versus inherited capability
- Common attack surfaces
- Defense in depth
- CNAPP as the umbrella over CSPM, CWPP and CIEM
Module 2
- Identity Is the Control Plane: IAM Architecture
- Identities, roles, permissions and entitlements
- Human versus workload identity
- Least privilege
- Role-based and attribute-based access
- Privileged access and administrative separation
- Stronger authentication including legacy non-SSO paths
- Entitlement management
- Case studies on the 2024 Snowflake tenant breach and the Storm-0558 signing-key compromise
Module 3
- Trust No Network: Cloud Network Security Architecture
- Security zones and trust boundaries
- Virtual networks, subnets, routing and gateways
- Segmentation and microsegmentation
- Inbound and outbound control
- Security groups and filtering
- Protecting management interfaces
- Zero Trust per NIST SP 800-207 and 800-207A
- Service mesh proxy architecture per SP 800-233
Module 4
- Protect the Data: Cloud Data Security & Cryptography
- Classification
- Protection at rest, in transit and in processing per NIST IR 8505
- Encryption across storage, databases and applications
- Key lifecycle management
- Organization-managed versus provider-managed keys, BYOK and HYOK
- Secrets, tokens, certificates and API keys
- Minimization, retention and secure deletion
- Post-quantum cryptography migration
- FIPS 140-3 and SP 800-57 for federal environments
Module 5
- Harden the Foundation: Secure Cloud Configuration
- Baselines using NIST guidance, the CSA Cloud Controls Matrix and CIS Benchmarks
- Insecure defaults and unnecessary services
- Hardening management planes
- Restricting public exposure
- Least functionality
- Configuration drift detection
- Managing approved exceptions
- The FedRAMP 20x model for federal environments