Course Content
Introduction to Cloud Computing
- Cloud Overview
- Cloud Service Models
- Cloud Deployment Models
Managing Cloud Security and Risk
- Impact of Cloud Tiers on Security and Risk
- Standards Organization
- RSA's Cloud Trust model
- Things to Look for in a Cloud Provider
Infrastructure Layer Trust
- Infrastructure Trust Layer Definition
- Disaster Recovery
- Virtualization
- Segmentation and Isolation
- Log Management
- Secure Communications
- Multi-Tenancy
Application Layer Trust
- Application Layer Trust: definition
- Web Application Security
- Application Security Phases and Lifecycle
- SDLC
- PaaS Security Concerns
Information Layer Trust
- Information Layer Trust: Definition
- Data Retention / Destruction
- Data Leakage
- Data Privacy
- Data Encryption and Key Management
- Data Geolocation
- E-Discovery
- Data Portability
- Data Classification
Management
- Management Layer Trust: Definition
- Identity and Access Management
- Contract SLAs
- Roles and Responsibilities
- Provider Viability
- Compliance Monitoring
- Business Continuance
- Provider Supply Chain
- Third-party Risk Assessment
- Software Licensing Risk
Securing Private Clouds
- Enterprise IT Evolution
- Private Cloud Security Primer
Final Lab Exercise
- Hands-on exercise in which Participants are challenged to build a best - in - class vendor data application with minimal assistance