
This introduction to network and cloud security provides an overview of core concepts and practical considerations for safeguarding digital infrastructure.
Define cloud computing per nist 800-145 as on-demand self-service access to a pooled, elastic set of resources. Learn the five characteristics and the saas, paas, iaas models across deployment options.
Explore cloud essential characteristics, including measured service with metering and transparency for providers and consumers, and see how elasticity, virtualization, scalability, simplicity, and on-demand self-service drive infrastructure as a service.
Explore platform as a service and software as a service, highlighting multi-language development, scalable hosting, control over deployed apps, vendor lock-in risks, and pay-per-use licensing across cloud applications.
Explore cloud deployment models—private, community, public, and hybrid—and the roles and benefits of cloud computing, including security, cost efficiency, scalable patch management, and improved resiliency.
Explore cloud risk management by identifying assets, assessing risks, and enforcing continuous monitoring to protect enterprise data before moving to the cloud.
Negotiate and enforce cloud service level agreements to ensure uptime, governance, and cost control, while securing transparency, regulatory compliance, audits, and data protection.
Explore the cloud secure data lifecycle—classify, encrypt, store, use, share, archive, and destroy data with access controls and rights management to enforce data loss prevention and governance.
Assess cloud risks and insider threats, emphasize background checks, non-disclosure agreements, and separation of duties with role-based access, while addressing legacy apps and hybrid cloud for security, performance, and availability.
Explore cloud assurance through laws, frameworks, and standards governing security, privacy, and compliance, including the Notorious Nine threats and the Cloud Controls Matrix.
The lecture examines data loss in cloud storage, encryption key loss, audits for compliance, and controls like data governance, risk assessments, resiliency, and incident management with multi-factor authentication.
Explore the insider threat as the number six risk, detailing malicious insiders, audit and ownership controls, policy enforcement, access reviews, and cloud abuse prevention across IaaS, PaaS, and SaaS.
Assess cloud migrations with due diligence to define responsibilities between provider and customer teams, then implement risk assessment and defense in depth to secure data.
Discover how data becomes packets through encapsulation, as each OSI layer adds headers and trailers from application to physical, ensuring proper delivery and interpretability.
Route data packets through the network using destination IP addresses and hierarchical addressing, with IP delivering one-way datagrams and offering no guaranteed delivery or error recovery.
Explore how IP addresses locate devices on a network using IPv4's 32-bit network and host IDs, and how subnet masks define the network portion for routing.
Explore how IP addresses are divided into class A, B, and C by fixed octet counts and starting bits, and how the network ID and host addresses are determined.
Explore IPv6, its 128-bit address space, auto configuration, mobility across networks, and extension headers with flow label and payload length concepts.
Explore the OSI model from physical to application layers, including data formatting, segmentation, and reliable delivery. Identify how devices like transceivers, hubs, bridges, switches, and routers support these layers.
Discover how globally unique public IP addresses are allocated and managed by IANA and regional registries, while private networks use the reserved private address ranges behind NAT.
Explore reserved IPs, including network addresses like 172.16.0.0 that cannot be assigned to devices. Understand broadcast, local loopback, and link-local auto configuration 169.254.0.0/16.
Learn the TCP/IP model and its four layers—network access, internet, transport, and application—where IP, TCP, UDP, and other protocols enable routing, addressing, fragmentation, reassembly, and common internet applications.
Observe dynamic MAC address entries on a switch, generate traffic with pings between Windows and Linux hosts, clear ARP caches, and analyze a three-way handshake using TCP dump.
Explore trunking by configuring interface Gi0/4 as a trunk, verifying the trunk is up, and testing gateway connectivity across the trunk with ping.
Learn to secure and manage a switch by logging in with a password, enable interfaces, and configure unused fast Ethernet ports, then shut them down.
The IT Security Gumbo: Unveiling Network and Cloud Security focuses on the fundamentals of computer networking which takes a focus on routing and switching, the OSI Model, variations of IP's. It also focuses on Cloud Security characteristics, cloud service, the notorious nine, cloud risk and more. We also provide a bonus for our students that will be unveiled once the student is apart of the course.
The Cloud Security Portion features and discusses the following and more:
Data Security in the Cloud
Intrusion Detection and Incident Response
Risk, Audit, and Assessment for the Cloud