
Learn cloud computing through the NIST definition. Understand its five essential characteristics and the service models IaaS, PaaS, SaaS, plus deployment options private, public, and hybrid.
Explore the five cloud characteristics: self-service, broad network access, on-demand service, rapid elasticity, and measured service, and how they guide cloud adoption for customers, enterprises, and providers.
explore the first cloud characteristic: on demand self-service, allowing users to provision resources without provider interaction. observe how organizations request storage or compute via self-service portals.
Access cloud resources across mobile phones, tablets, and laptops through broad network access, enabling management via standard mechanisms on heterogeneous platforms.
Explore how cloud providers pool computing resources across multitenant environments, enable on-demand delivery of storage, memory, and networks, and ensure location independence with regional data centers and compliance considerations.
Rapid elasticity automatically provisions and releases resources to scale outward and inward with demand, offering seemingly unlimited capacity and reducing capital expenditure.
Understand measured service in cloud computing, where providers meter storage, processing, and bandwidth usage, report consumption, and charge customers only for what they use.
Explore infrastructure as a service, where providers manage virtualization, networking, and storage, while you control operating systems, middleware, and applications, yielding pay-as-you-go, reduced capex, and disaster recovery configurations.
Platform as a service provides a vendor-managed platform and runtime for developers to build, deploy, and manage applications over the internet with no capex.
Explore software as a service, where the vendor manages all layers from application to networking, offering lower control but high manageability with examples like Dropbox and Office 365.
Understand public cloud basics, its multitenant infrastructure, and on-demand scalability from providers like AWS and Azure, with benefits such as lower cost, maintenance by providers, pay-per-use, and built-in load balancing.
Understand the private cloud, where resources are exclusive to one organization—on-site or via a provider—offering dedicated data control, enhanced security, and scalable, non-multitenant operations.
Hybrid cloud blends private on premise infrastructure with public cloud to balance control and scalability, moving data between private and public clouds for high volume workloads and sensitive data.
Explore the shared responsibility model for cloud security, clarifying which controls lie with the provider and which with the customer across IaaS, PaaS, and SaaS, including data security and compliance.
Explore the cloud service agreement, define expectations between the cloud service customer and provider, and outline terms, acceptable use, breach handling, privacy, and SLA considerations.
Understand why a cloud service agreement is essential to align customer and provider expectations, detailing data location, privacy, integrity, backups, exit options, breach handling, and forensics.
Explore the major artifacts of a cloud service agreement, including the customer service agreement, acceptable use policy, and service level agreement.
Customer agreements define relationship between the customer and the cloud service provider, outlining roles, responsibilities, and governing processes. Customers must understand terms such as master agreement and terms of service.
Understand the acceptable use policy as a cloud service provider rule that restricts illegal or improper use and prohibits certain activities, outlining expectations across cloud service models.
Define service level agreements (SLA) to set availability, reliability, and performance expectations with cloud providers, and ensure governance through service level reports and financial penalties.
Define the cloud SLA essentials, including uptime, downtime, high availability, fault tolerance, monitoring, incident notification, audits, certifications, business continuity and disaster recovery, and penalties for outages.
Identify and manage cloud asset discovery challenges by achieving complete visibility of cloud infrastructure, including instances and databases, to enable timely vulnerability scans, patching, and security governance.
Acquire complete cloud asset discovery and visibility across regions using automated inventory, agent-based or agentless scans, and CMDB integration to enable governance and secure patching.
Install the Qualys Cloud Agent on cloud virtual machines to simplify discovery, asset inventory, and vulnerability reporting, with silent updates and no reboots while sending configuration snapshots to a database.
Deploy the cloud agent in base images to automate asset discovery, security compliance monitoring, and inventory reporting. It enables automatic activation on new instances and centralized dashboards for continuous visibility.
Integrate secure configuration management into cloud DevSecOps with secure pipelines, code scanning, and baseline controls. Monitor developer activities, manage secrets with hardware security modules, and log incidents.
Assess CSP incident response and security notification by reviewing organizational and cloud provider plans, notification channels, and responsibilities in breach scenarios.
Explore cloud incident response with the CSP, covering roles and responsibilities, incident categorization, communication channels, logging via cloud trail, monitoring, and SLA penalties, and correlation with tools such as Splunk.
Explore accessing time-synchronized audit logs for cloud forensics, clarify CSP support and customer responsibilities across cloud service models, and outline contract and DOJ obligations for incident notification and metadata handling.
Assess cloud deployment models: public, private, hybrid, community, and their security concerns; align with legal requirements, assess risk, and apply controls to protect data across on-premises and off-premises environments.
Explore multitenant cloud architecture, identify isolation and data visibility risks, and apply encryption, defense in depth, and shared responsibility with security groups to prevent cross-tenant access.
Vendor lock-in occurs when switching providers is costly, tying you to a single cloud provider. Mitigate risks with a multi-cloud strategy, open standards, and due diligence on vendor exit terms.
Identify how data location in the cloud, regions, availability zones, and data centers, affects security, jurisdiction, contracts, and cross-border legal issues.
Explore data sensitivity and legal obligations in cloud adoption by assessing data location, access controls, encryption in transit and at rest, key management, and a defense-in-depth approach with cloud vendors.
Manage cloud encryption keys with a dedicated key management service to protect keys and secrets, enforce rule-based access, and separate duties from the cloud provider using remote or cloud-based management.
Explore remote key management service concepts, highlighting customer control of encryption keys, regulatory considerations, and the choice between cloud-based key management and on-premises HSM solutions.
Explore client-side key management, where the customer maintains complete control of encryption keys, performs processing locally, and the cloud provider holds no keys or detailed user data.
Discover Azure Key Vault as a cloud secret solution that stores secrets, keys, and certificates. Learn how hardware security modules and software storage support access controls and FIPS level requirements.
Provision an Azure Key Vault by selecting a subscription, resource group, and region, configure access policies and networking, then manage keys, secrets, and certificates inside the vault.
Learn to create a new key in Key Vault, choose RSA or elliptic curve, set activation and expiration, and assign app permissions to access and use the key.
Explore media sanitisation in cloud through crypto shredding, which destroys data by deleting encryption keys so encrypted volumes become unreadable and protect against unauthorized access.
Explore storage account security by examining access keys, including primary and secondary keys, how they authenticate access to storage objects, and why rotating keys improves security and availability.
Create an Azure storage account by selecting subscription and resource group, naming the account, and configuring performance, kind, networking, and secure transfer; then review containers, tables, and queues.
Explore methods to secure an Azure storage account with authentication, authorization, and keys or shared access signatures. Outline encryption in transit and at rest, plus key management and access controls.
Explore Azure storage security layers, from management plane access and RBAC to data plane controls, network restrictions, and encryption in transit and at rest, including storage keys.
Secure data plane access to storage accounts with role-based access control, tokens, shared access signatures, service-level and account-level signatures, storage keys, and policy-based controls across blob, table, and file storage.
Examine the limitations of storage account keys for authorization, including blanket access and no time-limited control, and contrast with shared access signatures offering granular, time-bound access to specific services.
Learn to access a storage account with access keys and switch to shared access signatures to restrict access to specific blobs, files, queues, and tables via Storage Explorer.
Learn to create a storage account, handle access keys, store keys as secrets instead of hard coding, and implement RBAC with service principals for secure access.
Explore shared access signatures in Azure storage to grant granular, time-bound access to blobs, tables, and queues with start times, expiry, and permissions, including policy-based stored access policies.
Learn to securely access storage accounts using shared access signature keys to grant time-bound, IP-restricted access to blob containers, with connection strings and Azure Storage Explorer.
Learn how cloud logging and monitoring capture data points to detect incidents, improve performance and security, and enhance customer experience through integrated alerts across apps and infrastructure.
Explore azure monitor and how it collects activity logs, resource logs, and application logs to deliver insights and alerts. Learn how log analytics supports troubleshooting and security across azure resources.
Master Azure Monitor metrics and logs, including platform, guest OS, and application metrics, plus activity and diagnostic logs, and learn to correlate them for alerting and security insights.
Configure metrics with Azure Monitor for a storage account, set the scope, select metrics like transactions and ingress/egress, and pin visuals to a dashboard for monitoring.
Discover the Azure Security Center overview, using advanced analytics to prevent, detect, and respond to threats across VMs, databases, and networks, with compliance recommendations for firewalls, patches, and just-in-time access.
Discover Azure security center options across overview, policy and compliance, security hygiene, and advanced global defense. Learn how threat detection, workflow automation, and siem integrations strengthen your environment.
Learn to navigate data communications and alerts in Security Center, apply category-based networking, identity, auditing, and vulnerabilities recommendations, and set email alerts for high-severity issues.
Assess cloud service provider security posture through audits and reports to ensure data confidentiality and integrity, verify control effectiveness, and meet regulatory standards like ISO 27001.
Explore how to verify AWS and Microsoft audit reports across regulations and customer needs, access the Service Trust reports, review ISO 27001, SOC, and FedRAMP disclosures, and assess controls.
Understand information management legal responsibilities across cloud providers, customers, and end users, including subcontractor oversight, data center jurisdiction, encryption standards, and end-user misuse monitoring.
Explore the three main categories of cloud legal issues—functional, jurisdictional, and contractual—and how data location, regulations, and contracts influence responsibilities and risk.
Discover how Azure Security Center scans your environment against standards like ISO 27001 and SOC, delivers regulatory compliance dashboards, and provides actionable recommendations to improve your security posture.
Explore e-discovery in the cloud, including electronic stored information, multitenant data dispersion, and cloud service models, and learn to manage legal holds and contract terms with providers.
Why Cloud Security?
Breaches can or do happen in cloud, in fact breaches are happening in cloud. In Marriott Starwood Hotels data breach some 327 million guest records were compromised that contained information such as name, mailing address, phone number, email address, passport number, Starwood Preferred Guest accounting information, date of birth, gender, arrival and departure information, reservation date, and communication preferences.
Note sure if you have heard about the below attacks
Capital One Data Breach wherein New York Times reported the damage at over 80,000 account numbers, 140,000 Social Security numbers, 1 million Canadian Social Insurance Numbers.
Who did it ?
A former Amazon software engineer from Seattle (CSP --Cloud Service Provider Employee )who had been operating online under the handle “Erratic” was arrested after hacking Capital One using a Server-Side Request Forgery attack (SSRF). Former Amazon Employee used the technique to obtain credentials for a role that had access to sensitive information stored in S3.
In cloud Security, we will learn certain best practices in regards to securing data; organizations stand a much better chance of ensuring their data is safe.
Another Breach in Hotel management systems
Autoclerk, a hotel reservations management system, had an unsecured Elasticsearch database hosted in AWS that exposed hundreds of thousands of booking reservations.
The system was heavily utilized by military personnel, and the exposed data revealed sensitive information about travel by military, including high ranking officers and troops being deployed.
Current Scenario
More and more companies are migrating their applications and infrastructure to the cloud, shifting operational aspects to service providers such as Microsoft and Amazon. However, cloud computing is a shared responsibility, especially when it comes to keeping your data, users, and systems safe.
In this course, you will major forms of cloud technology, its benefits and risks, and the cybersecurity standards and body of knowledge required to mitigate those risks.
Learn concepts such as software as a service (SaaS), platform as a service (PaaS), and infrastructure as a service (IaaS).
Different deployment models available in Cloud
What is Cloud Security?
Cloud security, also known as cloud computing security, consists of a set of policies, controls, procedures and technologies that work together to protect cloud-based systems, data and infrastructure.
You will learn Core Cloud Computing Concepts which essential to understand before digging to Cloud Security.
This course has divided in below 8 Major Sections.
1. Cloud Computing Fundamentals
2. Contracts and Agreements in Cloud
3. Vulnerability management and Secure Configuration in Cloud
4. Handling Security Incidents with Cloud Service Provider
5. Key Risks in cloud and their Mitigation
6. Securing Azure Storage
7. Logging and Monitoring in Azure
8. Compliance In Cloud
This is not a complete list; one can check for recommendations by NIST, CSA STAR and implement security in organization as per organization requirements.
What you will learn
1. Cloud Computing Fundamentals
What is Cloud Computing
Details about all 5 Cloud Characteristics in Detail
On Demand Self Service
Broad Network Access
Resource Pooling
Rapid Elasticity
Measured Service
Cloud Deployment Models ( IAAS, PAAS and SAAS)
Cloud Service Models ( Public, Private and Hybrid Cloud)
2. Understand Cloud Agreements/Contracts
In this section, you will learn importance of Contracts. How you can negotiate with Cloud Service providers for items to cover in contract to avoid future penalties. You will learn major artifacts for CSA (Cloud Service Agreement). You will learn important concepts like SLA in CLOUD, Acceptable use policy in Cloud.
3. Cloud Assets and Secure Configuration Management
In this section, you will learn assets discovery issues in cloud, how to have complete asset discovery in cloud for effective security and compliance. You will learn Challenges in Cloud Asset Discovery, SecDevops and secure configuration. You will vulnerability and patch management in cloud.
4. Handling Security Incidents with Cloud Service Provider
In this Section, you will learn what to check in CSP incident response and Security Notification process, Incident response process in a cloud. You will also learn what kind log data / Support can be obtain from CSP during forensics investigations.
5. Key Risks in cloud and their Mitigation
In this Section, you will learn various issues you can consider to protect un-authorized access of data in cloud. You will learn various concerns like Cloud Deployment Model and Security Concerns, Location of data, what kind of Data Sensitivity and Legal Obligations would be there in cloud. How to do Media Sanitization in Cloud. Key management in cloud and many more. You will learn about IAAS, PAAS and SAAS Security issues.
6. Securing Azure Storage
In this section you will learn about the below topics
Azure Storage account overview
Methods for Securing storage accounts
Concept of Management and data Plane
Azure storage Data plane Security.
Limitation of using storage account Keys
Security using SAS Keys
7. Logging and Monitoring in Azure
In this section you will learn about below topics
Azure Security Center Overview
What is Azure Monitor
You will be well versed with all the features of Azure Security center.
Detailed overview of Azure Security center Options
Recommendations and Alerts
Maintain Regulatory compliance using Azure Security center
8. Compliance In Cloud
In this Section, you will learn Information Management Legal Responsibilities, what are different types of legal issues in cloud. E-discovery issues in Cloud, What Regulations to follow in Cloud and Jurisdictional and Location issues in cloud environment.