
Explore the CCSB global cloud security credential, its six domains and NSA-aligned requirements; learn cloud models—private, public, hybrid—and the four-hour, 225-question exam with a 700–1000 passing score.
Learn how server virtualization uses a hypervisor to host multiple operating systems on a single physical server, enabling consolidation, easy management, and quick backup or replication.
Explain the two hypervisor types, type 1 and type 2; type 1 runs directly on hardware for stronger security, while type 2 sits on a host operating system.
Explore how virtualization simplifies adding and moving servers, enables load balancing and disaster recovery, and explain private, public, and hybrid clouds with IaaS, PaaS, and SaaS.
Explore infrastructure as a service from cloud providers like Amazon Web Services and Microsoft, rent servers on a pay-as-you-go model, and plan backups and disaster recovery.
Learn how cloud features enable on-demand self-service, broad network access, resource pooling, and rapid elasticity with metered service, illustrated by scalable e-commerce deployments.
Explore how cloud infrastructure shifts from traditional computing by emphasizing risk reduction and pay-as-you-go testing with IaaS, containers, and virtual machines, plus scalability and elasticity through virtualization.
Consumption based pricing charges only for used resources as demand grows, auto scaling adds instances and a load balancer during peak events, and unused capacity is released afterward.
Explore the benefits and challenges of cloud computing, and learn how to identify and mitigate security risks posed by global accessibility, using a de-risk framework for nonprofit settings.
Compare infrastructure as a service, platform as a service, and software as a service, focusing on IaaS benefits—on-demand resources, cost savings, and no single point of failure.
Explore infrastructure as a service, platform as a service, and software as a service, highlighting testing, development, hosting in one environment, and remote collaboration with secure, scalable web access.
Explore the key benefits of infrastructure as a service and platform as a service, including pay as you go, scalable usage, automatic load balancing, and reduced ownership costs.
Explore public, private, and hybrid cloud deployment models, weighing risk appetite, cost, and compliance to optimize IaaS, PaaS, and SaaS solutions while balancing data control and governance.
Explore cloud cross-cutting aspects as business-driven technology decisions, weighing private, public, hybrid, and community clouds; align funding and cost choices with overall strategy.
Explore enterprise security and architecture frameworks, including the Open Group architecture framework, and assess data security, privacy, resilience, performance, service level agreements, and regulatory compliance.
Define and implement physical and logical network security controls for cloud environments, including access monitoring, border protections, encryption, and clear data boundaries between CSP and clients.
Learn cryptography and encryption for data in rest and in motion in public cloud, implement ipsec and ssl/tls tunnels, and ensure tenant separation and secure access across providers.
Configure IAM access roles with storage role assignments, using Active Directory, and manage access with reader and backup roles, plus Storage Explorer for keys and encryption.
Explore vendor lock-in, where customers cannot leave or migrate cloud services due to technical or financial constraints, and learn how provider issues hinder data transfer and provider switching.
Explore virtualization security by examining hypervisor roles and type 2 hypervisors, multi-tenant isolation, and risks to data, access, and services.
Implement data security in the cloud by applying data discovery methods—label-based discovery and data mining—led by data owners and data custodians, with support from CISO, CTO, and network administrators.
Master cloud data lifecycle by creating, storing, sharing, archiving, and destroying data with encryption, secure uploads via vpn, access control, and device security for secure cloud collaboration.
Learn how to upload data from workstations to cloud storage, set read access, choose data access frequency, and enable secure transfer and virtual networks to monitor downloads or uploads.
Analyze how data functions, location, and access shape cloud storage architecture, applying lifecycle mapping and controls across volume, file-based, and object-based storage.
Explore how a content delivery network caches data near users to improve bandwidth and delivery quality for streaming, reducing latency across global locations.
Identify threats to storage types, including unauthorized access, data corruption, modification, destruction, and breaches, and implement protections via key management, change management, secure redistribution, and secure storage practices.
Explore encryption in infrastructure as a service, including default Microsoft storage service encryption at rest, using your own key for volume and file-level encryption, and key management considerations.
Explore homomorphic encryption and processing encrypted data without decryption, enabling cloud computing while keeping data encrypted and secure through least privilege and secure remote access.
Tokenization uses two distinct databases—one with live data and a token database mapping each piece to a token, then a token server fetches the matching production data.
Explore data privacy activities such as randomisation, masking, and replacing data with random characters; apply one-way hash functions to obscure data and disclose only partial identifiers, as in banking.
Explore data-center design that blends physical and virtual infrastructure—hardware, servers, storage, networking, and a centralized management layer, with redundancy for power, cooling, and connectivity.
Software defined networking separates the control plane from the data plane and shows how application and infrastructure layers and cloud resources are managed with routing, bandwidth, access control, and metering.
Explore virtualization concepts, comparing type 1 and type 2 hypervisors, and VM security risks like VM hopping, private LANs, and SDN, plus storage resilience with RAID levels and object storage.
Manage hosts remotely using the management plane to allocate virtual resources. Integrate authentication, access control, logging, monitoring, and risk management for secure, global deployments.
Explore policy and organization risk in cloud sourcing, highlighting provider lock-in, compliance and legal risks, and the need for layered compensating controls, backups, and governance.
Explore risk audit and management frameworks to ensure operational risk controls, and learn how business continuity and disaster recovery strategies rely on backups, alternate providers, and rapid synchronization.
Learn to define recovery time objectives and recovery point objectives, prioritize critical systems, and balance uptime and data loss limits for effective business continuity and disaster recovery planning.
Explore cloud application security, including cloud hosting versus traditional hosting, risk analysis, data classification, and access control to protect confidentiality, integrity, and availability across the software lifecycle.
Secure applications by managing data in motion and at rest through the software development lifecycle, using configuration management and addressing vulnerabilities like broken authentication, cross-site scripting, misconfiguration, and data exposure.
Outline a risk management program aligned with NIST identify, protect, detect, respond, and recover functions for infrastructure, emphasizing identity and access management and federation standards including saml and openid connect.
Analyze data center design for cloud operations, including location, compliance, automation, monitoring, consolidation, MTTR, MTBF, and multi-tenant architectures with SDN and IaaS.
Explore how physical design shapes data center capacity and resilience by choosing blade or mainframe servers, planning for expansion, and applying tier 1–4 redundancy with security and environmental protections.
Learn data center hvac and air management to maintain stable temperatures, control cooling with on/off operation, and design air intake, exhaust, supply/return placement, and cable management to reduce costs.
Domain 1• Architectural Concepts & Design Requirements 19%
Domain 2• Cloud Data Security 20%
Domain 3• Cloud Platform & Infrastructure Security 19%
Domain 4• Cloud Application Security 15%
Domain 5• Operations 15%
Domain 6• Legal & Compliance 12%
Who Qualify ?
A minimum of five years cumulative, paid, full-time work experience in information technology
Of which three years must be in information security and one year in one or more of the six domains of the CCSP Common Body of Knowledge (CBK)
Earning CSA’s CCSK Certificate can be substituted for one year of experience in one or more of the six domains of the CCSP CBK.
If you don’t have Necessary experience ,You can take and pass the CCSP exam to earn an Associate of (ISC)² designation.