Cloud Security Foundations: Design, Operate, and Recover
About this course
This intermediate course gives security practitioners, cloud engineers, application owners, and technical managers a vendor-neutral way to reason about cloud security. Learners examine the real control decisions behind a secure cloud environment: where provider responsibility ends, how accounts and identities are separated, how configurations are made repeatable, how events become evidence, and how recovery works when a control fails.
The course does not teach a single provider console. It teaches durable patterns that apply across infrastructure, platform, and software services. By the end, learners can assess a cloud workload, identify the most important trust boundaries and failure modes, and build a proportionate security improvement plan.
What you'll learn
- ✓ Explain shared responsibility and map the provider, customer, and application-owner controls for a cloud workload.
- ✓ Design identity, account, network, and data boundaries that reduce blast radius without making operations unworkable.
- ✓ Establish configuration, telemetry, and response practices that make cloud control effectiveness visible and repeatable.
- ✓ Produce a risk-based cloud resilience and improvement plan with tested recovery outcomes and accountable owners.
Before you begin
You will get more from this course if these foundations are already familiar.
- Basic cybersecurity and networking knowledge — Learners should understand accounts, networks, applications, access controls, logging, and common security threats.
Course content
Module 1: 1. Cloud Responsibility and Boundaries
Establish the shared-responsibility and boundary models needed to reason about cloud risk before selecting tools or provider-specific settings.
Shared Responsibility Is a Design Decision
Understand what cloud providers operate, what customers must configure, and why responsibility changes with the service model.
Accounts, Identities, Networks, and Data Boundaries
Use deliberate boundaries to reduce the blast radius of an identity error, exposed workload, or unsafe integration.
Module 2: 2. Secure Configuration and Visibility
Make cloud controls repeatable through secure defaults and make their outcomes visible through useful telemetry, detection, and response design.
Secure Configuration and Change Control
Build repeatable secure defaults and manage cloud change as a reviewed, testable process rather than an accumulation of console settings.
Cloud Telemetry, Detection, and Response
Turn cloud control-plane events, workload signals, and configuration changes into investigation-ready evidence and response decisions.
Module 3: 3. Resilience, Recovery, and Improvement
Design recovery as a tested security capability and use findings from exercises and incidents to prioritize durable cloud-security improvements.
Cloud Resilience and Recoverable Security Controls
Design backups, recovery access, and restoration tests that survive the same identity or configuration failure that affects the primary workload.
Build a Risk-Based Cloud Security Roadmap
Convert a cloud-workload assessment into sequenced improvements with explicit outcomes, owners, dependencies, evidence, and review dates.
Module 4: Cloud Workload and SaaS Security
Apply cloud-security thinking to running workloads, SaaS tenants, and the integrations that connect them.
Protect Cloud Workloads at Runtime
Constrain workload behavior through trusted inputs, service identity, network limits, runtime evidence, and clean redeployment.
Govern SaaS Tenants and Third-Party Integrations
Govern SaaS tenant posture and connected applications from data-sharing decisions through verified revocation.