
Explore how to secure cloud services by first securing internal IT, examine cloud service models, and draft a comprehensive cloud services agreement, then migrate securely with practice questions.
Learn how cloud services provide ubiquitous, on-demand access to a shared pool of configurable resources via virtualization, with scalable SaaS, PaaS, and IaaS across multi-tenant architectures.
Explore software as a service, platform as a service, and infrastructure as a service, and examine private, community, public, and external clouds, including multitenant and disaster recovery considerations.
Explore deployment models from private internal cloud to public external, detailing security and multitenant considerations. Understand how enterprises combine internal, external, and community deployments to meet diverse computing needs.
Explore private, community, public, and hybrid cloud models, and learn how ownership, management, location, capital expenses, operational expenses, cost savings, scalability, and disaster recovery shape risk.
Explore distributed processing as a reverse cloud, where volunteers donate idle computer cycles to a central project control, using BOINC and Berkeley Open Infrastructure for Network Computing to tackle datasets.
Build a cloud with a three-server cluster, shared storage, and a hypervisor to host virtual machines as a platform as a service, with heartbeat coordination, stateful sessions, and live migration.
Build an internal cloud by clustering bare-metal hardware and running virtual machines with operating systems for infrastructure as a service, platform as a service, and software as a service.
Evaluate internal cloud builds with VMware or Hyper-V virtualization and external cloud options from AWS and Microsoft, including encryption key management and free tiers.
Secure internal infrastructure to safely move information assets to the cloud, establishing governance, risk management, data protection, the CIA triad, fault tolerance, least-privilege provisioning, monitoring, and incident response.
Define a governance framework of policies and standards to manage enterprise risk, compliance, and operational efficiency, guided by laws and industry best practices, with annual security awareness training.
Explore the governance framework of the enterprise information security policy and its policy subsets, including acceptable use, hiring and termination, data classification, risk management, incident response, business continuity, and sanctions.
Engage in risk management by identifying and quantifying threats—from nature, man-made, technical, to supply systems—then implement preventive and recovery controls through due diligence and do care.
Learn to conduct a risk assessment by inventorying information assets, valuing them, and prioritizing protections. Identify vulnerabilities and threats, quantify risk, and apply preventive, response, and recovery controls.
Assess the risk and present to management; implement administrative, physical, and technical controls to mitigate, transfer, or avoid risk, deter the bad thing, and monitor effectiveness.
Design and implement a security program that enforces administrative, physical, and technical controls, trains users, and monitors and audits for anomalies to protect data confidentiality, integrity, and availability.
Apply confidentiality, integrity, and availability by using least-privilege file permissions, encryption, dlp, and physical controls; verify integrity with hashes and ensure availability through clustering, raid, and backups, plus colocation.
Explore physical security and network safeguards, including triple-A (authentication, authorization, auditing), patching, configuration controls, least-privilege user provisioning, and approved applications to protect data and assets.
Protect sensitive data by safeguarding intellectual property, patents, trade secrets, and personal information, while complying with PCI DSS and preserving confidentiality, integrity, and availability.
Identify data assets, set classification levels, and label data and media. Define protection criteria based on confidentiality, integrity, and availability, and assign roles from owners to custodians to enforce controls.
Explore strong authentication, multi-factor and mutual authentication, and strict authorization with least privilege, separation of duties, and auditing to protect cloud infrastructure.
Learn how to harden servers by running only essential services, patching systems, removing unused software, enforcing least privilege, reducing user accounts, and implementing host-based firewall rules.
Improve system hardening with signature-based antivirus and anomaly detection, host-based intrusion protection, and software fingerprinting, plus vulnerability and configuration scans and real-time remote logging.
Establish and enforce configuration control across servers, devices, and BYOD endpoints. Document, audit, and compare configurations, and implement a formal change approval process to mitigate misconfigurations and security risks.
Train every employee on security awareness before they access systems. Document attendance, refresh annually, and address privileged users, laptops, wireless, and telecommuters with strong passwords and encryption.
Focus on safety first, teaching fire drills, CPR, and defibrillator use before enterprise protection. It also covers policies, monitoring, enforcement, and assigned roles for incident response.
Master secure user provisioning by creating and removing accounts, assigning privileges with least-privilege controls, enforcing approvals, pre-hire background checks, multi-factor authentication, remote access safeguards, auditing, and separation of duties.
Learn to monitor and audit cloud infrastructure with 24/7 automated logging, target audits for privileged users, and respond to anomalies and incidents with a planned incident response and policy enforcement.
Monitor events for anomalies, escalate to incident investigation, contain and eradicate breaches, analyze outcomes, and apply lessons learned to strengthen the cloud security program.
Establish a governance framework with documented policies, due diligence, and cloud service agreements to govern providers, enforce security controls and data loss prevention, ensure training, monitoring, and regulatory compliance.
Plan cloud use by safeguarding confidentiality, integrity, and availability with proper controls and authorized users and systems; compare private and public clouds and verify data location and uptime commitments.
Plan for cloud use by standardizing data with normalization and deduplication, implement triple-a controls, encrypt data with key escrow, and consult security readiness tools and ISO 27000 controls.
Implement security controls for cloud use by enforcing data classifications and policies, while applying data loss prevention, tokenization, and secure destruction to protect confidentiality, integrity, and availability.
Learn how the enterprise connect zone uses a reverse proxy, Active Directory, and federated identity management to authenticate, authorize, and manage BYOD device access to cloud services.
Explore securing cloud services by enforcing strong isolation in multi-tenant environments, hardening hypervisors and hosts, and applying secure coding and OWASP guidelines to web applications.
Explore security as a service to balance internal and outsourced controls, covering identity and access management, data loss prevention, encryption, host and network monitoring, and security assessments.
Implement administrative, physical, and technical controls for cloud use, secure data at rest, in transit, and in processing, and establish logging, monitoring, auditing, encryption, dlp, vpn, tls.
Conduct thorough due diligence on the cloud service provider and its subproviders to verify they meet your security objectives, certifications, and remediation history, including SAML, OpenID, and X.500 directory services.
Develop a cloud services agreement anchored in a governance framework that binds third-party providers to commitments, penalties, prudent management, monitoring, breach notification, and business continuity and disaster recovery.
Define and enforce NDA, confidentiality, nondisclosure, ownership, and guaranteed access clauses in cloud service agreements, with penalties, e-discovery readiness, regulatory compliance, and multi-layered security controls.
Define data protection controls for data at rest, in transit, and during processing, including encryption and multi-tenant isolation; ensure redundancy with backups and tested restores for rpo and rto.
Learn to implement data fault tolerance through RAID arrays, real-time journaling, and disk shadowing across multi-location setups; ensure portable, interoperable data with periodic backups.
Learn how to achieve system fault tolerance and redundancy with cluster arrays of hypervisors, heartbeat networks, VM migration, RAID, second power grids, UPS, generators, and multi-site co-location.
Ensure connectivity fault tolerance and redundancy with multiple high-speed connections and mesh routing, plus federated identity management, reverse proxies, encryption standards, co-location, tenant isolation, and timely patching.
Develop a cloud services agreement that enforces configuration management, change control, and regular vulnerability scans and assessments, with incident notification and penalties for breaches.
Examine how cloud service providers must implement continuous logging, monitoring, incident response plans, breach notification, remediation participation, prudent management, risk assessment, and disaster recovery to ensure business continuity.
Monitor and audit cloud service provider activities with real-time access, reporting, and inspections to protect confidentiality, integrity, and availability of information assets and ensure uptime and security.
Implement cloud services cautiously by auditing, testing, and monitoring providers; enforce incident response, key escrow, data loss prevention, and data classification to protect confidentiality, integrity, and availability.
Perform on-site inspections, auditing, and testing of the physical environment hosting cloud services to ensure due diligence, while monitoring usage, security events, and compliance against the service agreement.
Coordinate with the cloud service provider to contain, eradicate, and recover from incidents, validate eradication, and secure a three-person key escrow for encryption keys.
Enforce cloud service agreements by monitoring provider performance and addressing violations with the legal department. Monitor users against an acceptable use policy and apply administrative, physical, and technical controls.
Securely migrate to cloud services by first hardening the internal network, selecting saas/paas/iaas models, and implementing governance, risk management, and phased migration.
Data security is as important as ever, and the industry-wide move to cloud-based infrastructure comes with its own requirements and concerns.
Throughout this course, expert author David Miller will teach you how to secure and maintain your IT assets in the cloud. You will start by learning how to secure the infrastructure, including risk assessment and management, sensitive data, and data classification. From there, David will show you how to prepare for cloud use, including web app security, security as a service, and security controls. This video tutorial also teaches you about the cloud services agreement, and what you should consider including in your cloud services agreement. Finally, you will learn how to stay secure in the cloud and maintain your IT assets securely. Once you have completed this computer based training course, you will be fully capable of securing your own IT assets in the cloud.