
In this video we will cover:
Governance, Risk management & Compliance
Why move to the cloud?
What problem does cloud computing solve?
In this video you will learn:
Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources.
What is essential is that we must determine why we are moving into the cloud before making any changes. There are many things that cloud computing can provide to a business, but the decisions made must match the company's needs.
We encourage you to learn more about CCSP Domain 1 Introduction to Cloud by watching this video. See you in the next video.
I highly recommend that you download the two attachments here. One is domain 1 from my book Cloud Guardians. The other is the guidance 4.0 from the CSA. I HIGHLY recommend that you read that. All of it ;).
In this video we will cover:
Governance, Risk management & Compliance
Where does Security start for Clouds?
Why do we need a Corporate Security Strategy?
Where is Data going to be?
ISMS (Information Security Management System)
In this video you will learn:
The security implemented within a business must forward the company. The corporate strategy and governance guide the security strategy and governance. This guidance must include the cloud and the corporation's relationship to the cloud.
Risk management should drive all decisions within the business.
Corporations must comply with laws and regulations within today's fast-changing threat environment. Audits are used to verify the correct level of compliance is in place.
Information security professionals should plan to get in and out of the cloud. CCSPs should do this planning before any move into the cloud is made.
We encourage you to learn more about GRC CCSP Domain 1 by watching this complete video. See you in the Next Video.
Explore deployment models in cloud computing, including public clouds, private clouds, community clouds, and hybrid configurations. Understand how location, ownership, and management shape multi-tenancy and shared services.
In this video we will cover:
Three different service models are known as (SaaS), (PaaS) and (IaaS).
IaaS Shared Responsibility Model.
PaaS Shared Responsibility Model.
SaaS Shared Responsibility Model.
MSP VS. CSP
Who builds the Cloud?
In this video you will learn:
Cloud computing has three different service models, each satisfying a unique set of business requirements. These three models are known as Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS).
A shared responsibility model is a cloud security framework that dictates the security obligations of a cloud computing provider and its users to ensure accountability.
MSPs manage technology and infrastructure, usually for private clouds, while CSPs offer the general public access to technology and infrastructure.
Cloud administrators build a cloud structure according to the architect's design, and a cloud storage administrator builds the cloud data storage according to the architect's design.
We encourage you to learn more about CCSP Service Models by watching this complete video. See you in the Next Video.
In this video we will cover:
Cloud and Its Contracts
In this video you will learn:
In (ISC)² courses and their books focus on service level agreements but there are a lot of other pieces to the contract. One is a master services agreement, which establishes the roles and responsibilities of each other. SLA is something specific like bandwidth or reliability. A privacy level agreement is called a data processing agreement under GDPR in Europe. A PLA informs the cloud provider that you will be storing personal data or (PII) in the cloud and what you expect of their security controls.
We encourage you to learn more about The cloud and its contracts by watching this complete video. See you in the Next Video.
In this video we will cover:
Cloud Infrastructure
What we need to build a Cloud.
Storage Area Network
Virtualization
Who runs the Cloud?
Hypervisor Type 1, Hypervisor Type 2
Containers
Application Virtualization
In this video you will learn:
Creating a cloud infrastructure requires a lot of time, effort, and money. The CapEx is spent by the cloud provider leaving the OpEx to the cloud customer.
Virtualization is what makes it possible for a cloud provider to sell IaaS, PaaS, and SaaS. For this to work we need compute, storage, and network services.
You will learn about Hypervisor and its types, containers, and virtualized applications.
We encourage you to learn more about Building the Cloud by watching this complete video. See you in the Next Video.
In this video we will cover:
Cloud Security
ISO 27002
NIST SP 800-53
ISO 27017
General Grouping Of Controls
Control Types
Control Categories
In this video you will learn:
We need to control the clouds that we build. Security controls can be found in two documents: ISO 27002 and NIST SP 800-53. In theory, these documents contain all security controls.
ISO 27017 is the code of practice for Information Security Controls based on ISO/IEC 27002. It is a subset of all the controls that are found inside ISO/IEC 27002 that apply to cloud environments.
Controls can be divided into safeguards and countermeasures. There are three types of controls: administrative, technical, and physical. The controls we choose should be tested and vetted.
We encourage you to learn more about Securing The Cloud by watching this complete video. See you in the Next Video.
In this video we will cover:
Control Verification
ISO 15408 Evaluation Assurance Levels
Testing Cryptography Products
FIPS 140-2 Levels
In this video you will learn:
The security controls we choose should be tested and vetted. ISO 15408 Common Criteria is a standardized test methodology so that a situation such as A Cisco FW and a Checkpoint FW can be tested by two different labs in two different countries, but the test results can be compared to determine the best FW for a given use.
There are seven levels of the test. The lowest level is 1 and the highest is seven. If we are testing cryptography specific then it is a different document named FIPS 140-2 and 140-3. A standard for the quality of physical security must be within a cryptographic module within a system. There are four levels of FIPS 140-2. One is the lowest and the four is the highest.
We encourage you to learn more about Control verification by watching this complete video. See you in the Next Video.
In this video we will cover:
A Contract Vs Law
In this video you will learn:
PCI-DSS is not a law or regulation, basically, it’s a contract. It establishes a requirement to meet the Data Security Standards developed by the Payments Cards Industry. PCI-DSS is a contractual agreement with the payment card company to be able to process card charges and it falls under civil or tort law.
We encourage you to learn more about Intro to PCI by watching this complete video. See you in the Next Video.
In this video we will cover:
PCI Requirements 1-3
In this video you will learn:
There are 12 requirements for PCI-DSS. It is highly recommended that you be familiar with the 12 requirements. You should know that building and maintaining a firewall is a part of PCI-DSS requirements, it is not necessary to remember that it is number one on the list though. The second one is: never use vendor-supplied default passwords or configurations. The third is you must protect stored cardholder data.
We encourage you to learn more about PCI Requirements 1-3 by watching this complete video. See you in the Next Video.
In this video we will cover:
PCI Requirements 4-6
In this video you will learn:
The fourth is that you must encrypt cardholder data when it is transmitted over a public network. The fifth is that you should use regularly updated antivirus protection. The sixth requirement is to develop and maintain secure systems and applications.
We encourage you to learn more about PCI Requirements 4-6 by watching this complete video. See you in the Next Video.
In this video we will cover:
PCI Requirements 7-12
In this video you will learn:
Seven - The next requirement is to restrict access to cardholder data on a need-to-know basis.
Eight - You should have a unique ID for all that have access to the cardholder data.
Nine - It is necessary to physically restrict access to cardholder data, which means the server that maintains the cardholder Information should be protected.
Ten - Track and monitor all network and cardholder data access.
Eleven - Also, you should be testing your security systems regularly.
Twelve - The last requirement is to maintain an information security policy.
We encourage you to learn more about PCI Requirements 7-12 by watching this complete video. See you in the Next Video.
In this course we walk through all of the critical concepts within the Cloud Platform & Infrastructure domain. This domain is 17% of the test as of August 2022. I will guide you through all of the concepts that you need to know and advise you on the level of knowledge that you need to get comfortable with.
There are over four hours of video content plus course notes based on information from my book: Cloud Guardians.
We will explore the basics of Governance, Risk management and Compliance and how the cloud affects it in a business.
A solid understanding of the definition of cloud, its deployment models and service categories will be gained through these videos.
An exploration of the threats to the cloud today is in this course. Those controls need to be verified and we use common criteria or ISO 15408. It is also necessary to explore the verification of the physical security with cryptography related products such as Hardware Security Modules (HSM) and Trusted Platform Modules (TPM). That verification is done using FIPS 140-2/-3.
We finish this domain with an exploration of the technologies that are related to the cloud and benefit greatly from all of its offerings.
This domain is the cloud concepts, architecture and design.
The details that are included in (ISC)2's exam outline of encryption and access controls are in Domain 2.
The details from their exam outline about network and virtualization security is in Domains 3 and 5.
The BCP details are in Domain 5.
I cover DevSecOps in Domain 4 - Cloud Application security