Cloud Computing Security Knowledge CCSK Online Course
The CCSK (Cloud Computing Security Knowledge) course covers fundamental cloud security to be ready for the Cloud Security Alliance exam.
Original price was: £144.00.£71.00Current price is: £71.00. inc VAT
- Instant online access
- Study at your own pace
- Secure checkout
What the Cloud Computing Security Knowledge CCSK course covers
Everything in Cloud Computing Security Knowledge CCSK is delivered online and on demand - no classroom, no cohort, no waiting list. The material is split into 14 modules you can stop and restart at will. The 12 months of access matter more than they sound: refresher reading before an inspection or an appraisal is free.
The material takes in Architecture, NIST Definitions, Essential Characteristics and Service Models. Another 10 modules follow, and the Modules tab lists every one of them.
There are no entry requirements, and it is pitched at people who need the subject for work rather than at exam candidates. We list 37 Cybersecurity courses, of which 12 sit at Professional development. Completing it earns a certificate you can download - useful as evidence of training, and not the same thing as a graded qualification.
What this course is not: There is no CPD accreditation attached, which matters only if somebody has specifically asked you for it.
Full course details from the training provider
The Cloud Computing Security Knowledge class provides students thorough coverage of cloud security fundamentals and prepares them to take the Cloud Security Alliance CCSK certification exam. The course begins with a detailed description of cloud computing and then expands into all major domains such as; Governance and Risk Management, the Cloud Architectural Framework and Business Continuity/Disaster Recovery
Upon completing this course, the students will be experts in the following topics:
- Pass the CCSK Exam
- Understanding cloud computing security challenges
- Cloud computing security controls recommendation
- Elasticity, Resiliency and Measured Usage
- Understand the cloud computing architectural framework
Course Outline
1: Architecture
- NIST Definitions
- Essential Characteristics
- Service Models
- Deployment Models
- Multi-Tenancy
- CSA Cloud Reference Model
- Jericho Cloud Cube Model
- Cloud Security Reference Model
- Cloud Service Brokers
- Service Level Agreements
2: Governance and Enterprise Risk Management
- Contractual Security Requirements
- Enterprise and Information Risk Management
- Third Party Management Recommendations
- Supply chain examination
- Use of Cost Savings for Cloud
3: Legal Issues: Contracts and Electronic Discovery
- Consideration of cloud-related issues in three dimensions
- eDiscovery considerations
- Jurisdictions and data locations
- Liability for activities of subcontractors
- Due diligence responsibility
- Federal Rules of Civil Procedure and electronically stored information
- Metadata
- Litigation hold
4: Compliance and Audit Management
- Definition of Compliance
- Right to audit
- Compliance impact on cloud contracts
- Audit scope and compliance scope
- Compliance analysis requirements
- Auditor requirements
5: Information Management and Data Security
- Six phases of the Data Security Lifecycle and their key elements
- Volume storage
- Object storage
- Logical vs physical locations of data
- Three valid options for protecting data
- Data Loss Prevention
- Course Syllabus
- Detection Data Migration to the Cloud
- Encryption in IaaS, PaaS & SaaS
- Database Activity Monitoring and File Activity Monitoring
- Data Backup
- Data Dispersion
- Data Fragmentation
6: Interoperability and Portability
- Definitions of Portability and Interoperability
- Virtualization impacts on Portability and Interoperability
- SAML and WS-Security
- Size of Data Sets
- Lock-In considerations by IaaS, PaaS & SaaS delivery models
- Mitigating hardware compatibility issues
7: Traditional Security, Business Continuity, and Disaster Recovery
- Four D’s of perimeter security
- Cloud backup and disaster recovery services
- Customer due diligence related to BCM/DR
- Business Continuity Management/Disaster Recovery due diligence
- Restoration Plan
- Physical location of cloud provider
8: Data Center Operations
- Relation to Cloud Controls Matrix
- Queries run by data center operators
- Technical aspects of a Provider’s data center operations for customers
- Logging and report generation in multi-site clouds
9: Incident Response
- Factor allowing for more efficient and effective containment and recovery in a cloud
- Main data source for detection and analysis of an incident
- Investigating and containing an incident in an Infrastructure as a Service environment
- Reducing the occurrence of application level incidents
- How often should incident response testing occur
- Offline analysis of potential incidents
10: Application Security
- Identity, entitlement, and access management (IdEA)
- SDLC impact and implications
- Differences in S-P-I models
- Consideration when performing a remote vulnerability test of a cloud-based application
- Categories of security monitoring for applications
- Entitlement matrix
11: Encryption and Key Management
- Adequate encryption protection of data in the cloud
- Key management best practices, location of keys, keys per user
- Relationship to tokenization, masking, anonymization and cloud database controls
12: Identity, Entitlement, and Access Management
- Relationship between identities and attributes
- Identity Federation
- Relationship between Policy Decision Point (PDP) and Policy Enforcement Point (PEP)
- SAML and WS-Federation
- Provisioning and authoritative sources
13: Virtualization
- Security concerns for hypervisor architecture
- VM guest hardening, blind spots, VM Sprawl, data comingling, instant-on gaps
- In-Motion VM characteristics that can create a serious complexity for audits
- How can virtual machine communications bypass network security controls
- VM attack surfaces
- Compartmentalization of VMs
14: Security as a Service
- 10 categories
- Barriers to developing full confidence in security as a service (SECaaS)
- Deployment of Security as a Service in a regulated industry prior SLA
- Logging and reporting implications
- How can web security as a service be deployed
- What measures do Security as a Service providers take to earn the trust of their customers
- ENISA Cloud Computing: Benefits, Risks and Recommendations for Information Security
- Isolation failure
- Economic Denial of Service
- Licensing Risks
- VM hopping
- Five key legal issues common across all scenarios
- Top security risks in ENISA research
- OVF
- Underlying vulnerability in Loss of Governance
- User provisioning vulnerability
- Risk concerns of a cloud provider being acquired
- Security benefits of cloud
- Risks
- Data controller vs data processor definitions in Infrastructure as a Service (IaaS), who is responsible for guest systems monitor
Learning outcomes
- 1: Architecture
- NIST Definitions
- Essential Characteristics
- Service Models
- Deployment Models
- Multi-Tenancy
- CSA Cloud Reference Model
- Jericho Cloud Cube Model
- Cloud Security Reference Model
- Cloud Service Brokers
- Service Level Agreements
- 2: Governance and Enterprise Risk Management
- Contractual Security Requirements
- Enterprise and Information Risk Management
Get instant access and start learning today.
Modules
Course certificate
Upon completion of your training course, you will receive a Certificate of completion displaying your full name, course completed as well as the date of completion. You can print this out or save it digitally to showcase your accomplishment.
Frequently asked questions
How long does Cloud Computing Security Knowledge CCSK take?
The provider does not state a study time for this one, and nothing in it is timed. Stopping mid-module is fine; it remembers where you got to. Access lasts 12 months from purchase.
Do I need any experience or prior training?
No. There are no entry requirements and nothing to sit before you begin.
Do I get a certificate?
Yes, and you do not have to wait for it in the post: it is a download.
Is Cloud Computing Security Knowledge CCSK an accredited qualification?
No. It is professional training with a certificate of completion rather than a regulated qualification. That is the right thing for evidencing training, and the wrong thing if a job advert specifically demands an accredited award.
When can I start?
Immediately after checkout. You need a device with a browser and an internet connection; no software, no downloads, no waiting for a course date.
Course reviews
Only verified purchasers can submit a review. Reviews are not written, rewarded or edited by us.
Only logged in customers who have purchased this product may leave a review.
IT Cloud Certification Training Bundle
That works out at about £36.00 per course.
- CompTIA Cloud Essentials
- Cloud Computing Security Knowledge CCSK Online Course
- CompTIA Cloud+ Certification (Exam CVO-001)
- EXIN Cloud Training
Reviews
There are no reviews yet.