
Learn to design a holistic cloud security architecture using a health clinic example, applying NIST CSF to prove HIPAA and GDPR compliance, resilience, and governance.
Learn holistic cloud security architecture through a practical health clinic example, mapping business and regulatory requirements to security measures with the Cloudsarc methodology, defense in depth, and risk assessment.
Explore cloud security architecture, its methodology and the NIST cybersecurity framework, emphasizing a holistic, integrated approach with layer defenses, least privilege, isolation, and zero trust across cloud delivery models.
Define the Cloudsarc methodology that blends NIST, SABSA, CSA, and CCM into a top-down, defense-in-depth cloud security architecture with risk assessment, compliance mapping, and traceability.
Apply the NIST CSF 2.0 to cloud security by aligning governance with the six functions—identify, protect, detect, respond, and recover—and shared responsibility in healthcare.
Explore security architecture in the cloud, introduce the Cloudsarc methodology, and apply the NIST cybersecurity framework to map business and regulatory requirements to cloud security requirements.
Analyze the Cloudsarc health clinic case to map business and regulatory requirements, including HIPAA and GDPR, to a cloud security architecture that protects EMR data for desktop and mobile use.
Navigate GDPR and HIPAA compliance for cloud health data, detailing data subject rights, data protection by design, breach notification, and the roles of encryption, data processing agreements, and risk assessments.
Map business and regulatory needs to NIST CSF categories to define security requirements for the Cloudsarc health clinic, ensuring traceability, encryption, and strong authentication for EMR access.
Explore the Cloudsarc health clinic example and map business and regulatory requirements to security requirements, covering GDPR and HIPAA compliance and preparing security measures.
Map business and regulatory requirements to security measures in the Cloudsarc health clinic using the NIST CSF subcategories, covering identity, strong authentication, access control, traceability, and data protection.
Map the logical security architecture to cloud services across major providers, covering authentication, access control, monitoring, logging, backup, and encryption at rest and in transit.
Map security requirements to security measures represented by NIST CSF subcategories, assign responsibility to cloud customer, provider, or both, and align these measures with cloud security components.
Identify, analyze, and prioritize risks to minimize adverse effects on the organization through risk management and risk assessment, protecting health data and ensuring business continuity for the health clinic.
Learn the six-step risk assessment process based on the nist guide for conducting risk assessments, identifying threats, vulnerabilities, likelihood, and impact to protect electronic health information in cloud environments.
Explore how risk mitigation reduces threats in cloud security architecture for health records by applying NIST CSF mitigations and recovery and monitoring measures.
Explore cloud risk management with threats, vulnerabilities, and a practical risk assessment using a risk matrix, mapped to the NIST CSF subcategories.
Develop a cloud security strategy to plan adoption, balance business and security needs with cost, and outline risk mitigation for a cloud-first, secure health IT services.
Define a cloud security strategy driven by business objectives and regulatory needs, balancing risk management with resilience, governance, and zero trust controls across cloud services.
Develop a cloud security strategy aligned with business objectives, risk and operational considerations, and set goals to enable defense in depth and make your cloud environment more resilient against adversaries.
Explore defense in depth as a layered security model for cloud environments, defining responsibilities between provider and customer within a two-dimensional matrix aligned with the NIST CSF functions.
Explore defense in depth layers for cloud security, including governance, risk and compliance, identity and access management, cloud center of excellence, security operations, endpoints, and data protection.
Map security requirements to NIST CSF subcategories and visualize defense in depth across five functions to assess coverage, gaps, and risk assessments for mitigations.
Explore cloud defense in depth by aligning architectural layers with NIST CSF functions to visualize coverage, supporting compliance and security architecture documentation.
Use a methodology to build a holistic security architecture that proves GDPR and HIPAA compliance, maps NIST CSF to regulations, and supports procurement and budgeting decisions.
Present a downloadable NIST CSF to GDPR and HIPAA mapping workbook, showing lookups in the privacy framework and visualizing responsibilities for governance, risk, and compliance stakeholders.
Map the NIST CSF to HIPAA using the worksheet, showing PR.AC-1 mappings to HIPAA administrative and technical safeguards, and visualize emergency access procedures for cloud EMR.
The security architecture specification acts as a guiding, editable cloud compliance and resilience document, detailing background, methodology, scope, and chaptered architecture results aligned with NIST CSF and HIPAA/GDPR mappings.
Summarize the security architecture work using the specification template. Map measures to HIPAA and GDPR with the worksheets for compliance mapping, and prepare to adapt the Cloudsarc methodology.
Adapt the cloud security methodology to your company’s needs, map regulatory requirements to current security measures, and mature the defence in depth across development lifecycle and security operations.
Map regulatory and business requirements for a cloud health clinic to security controls using the CSF and NIST framework, with CSA mappings and GDPR and HIPAA compliance worksheets.
Keep the security architecture a living document that adapts to cloud changes, applying change management, risk assessments, application security testing, and penetration tests, with illustrations and risk matrices for stakeholders.
Adopt a flexible methodology tailored to your needs, map sources, and manage growth while communicating with stakeholders and tailoring documentation to your audience.
Learn to design a holistic, resilient, compliant cloud security architecture by deriving requirements from regulatory and business needs, performing risk assessments, and mapping defenses to cloud services.
In this course you will learn how to master security architecture for the cloud. You will be using a methodology based on NIST Cybersecurity Framework 2.0 to take your architecture from business- and regulatory requirements all the way to components and capabilities that can be implemented in the public cloud.
The course will teach you how to map requirements to security measures and perform risk assessments. You will learn to master security strategy for the cloud and build a resilient security posture using a defense in depth strategy. You will also be able to prove compliance to regulations like GDPR and HIPAA using the methodology presented in the course. An important learning objective is also to create structured security architecture documentation.
This course is based on a Health Clinic example and has a hands-on focus for learning. After course completion, you can use all the provided methods and templates from the course in your own work. The resulting components and capabilities can be implemented in any cloud platform, but the course does not cover a cloud platform specific technical implementation of the architecture.
Course contents:
2,5 hours of video lectures
6 hands-on assignments
6 Quizzes
10 downloadable templates:
Requirements mapping template
Security requirements mapping template
Requirements mapping visualization template
Risk assessment template
Cloud security strategy template
Defense in depth assessment template and defense in depth circle template
Compliance mapping workbook
GDPR and HIPA visualization templates
Security architecture specification template