CSA - Firebrand's training for CSA's Certified Cloud Security Knowledge (CCSK) exam

Varighet

Varighet:

Bare 2 dager

Metode

Metode:

klasserommet / på nett / Hybrid

Neste dato

Neste dato:

16/12/2021 (Torsdag)

Overview

On this 2-day accelerated Firebrand course for CSA's Certificate of Cloud Security Knowledge (CCSK) exam, you'll validate your understanding of the best practices surrounding cloud security. This Firebrand course, designed to deliver knowledge equivalent to the CSA's CCSK Basic and the CCSK Plus, aims to ensure that you have a demonstrated awareness of the security threats facing your cloud infrastructure.

On this Firebrand course you'll cover:

  • A comprehensive review of cloud security fundamentals
  • The major domains in the latest Guidance document from Cloud Security Alliance (CSA)
  • Recommendations from the European Network and Information Security Agency (ENISA)
  • Expanded material and hands-on tasks in a series of exercises that include bringing a fictional organisation securely into the cloud.

Firebrand's unique Lecture | Lab | Review technique combines both theoretical knowledge with practical, hands-on skills. This technique will accelerate your learning and ensure you have the ability to apply your new found knowledge as soon as you return to work.

As part of Firebrand' own course, you'll be prepared for and sit the CSA Certificate of Cloud Security Knowledge (CCSK) exam. This is covered by your Certification Guarantee.

This course is aimed at a broad range of professionals with responsibilities related to cloud computing and security.

Her er 8 grunner til hvorfor du skal gjennomføre ditt CCSK hos Firebrand Training:

  1. Du blir utdannet og sertifisert på bare 2 dager. Hos oss får du din utdanning og sertifisering på rekordtid, en sertifisering du også gjennomfører der og da som en integrert del av den intensive, akselererte utdanningen.
  2. Alt er inkludert. Et engangsbeløp dekker alt kursmaterial, eksamen, kost og losji og tilbyr den mest kostnadseffektive måten å gjennomføre ditt CCSK kurs og sertifisering på. Og dette uten noen uannonserte ytterligere kostnader.
  3. Du klarer sertifiseringen første gangen eller kan gå kurset om igjen kostnadsfritt. Det er vår garanti. Vi er sikre på at du vil klare din CCSK sertifisering første gangen. Men skulle du mot formodning ikke gjøre det kan du innen et år komme tilbake og kun betale for eventuelle overnattinger og din eksamen. Alt annet er gratis.
  4. Du lærer deg mer.Tradisjonelle utdanningsdager varer fra kl. 09.00 til 16.00 med lange lunsj- og kaffepauser. Hos Firebrand Training får du minst 12 timers effektiv og fokusert kvalitetsutdanning hver dag sammen med din instruktør, uten private eller arbeidsrelaterte, forstyrrende momenter.
  5. Du lærer deg CCSK raskere. Vi kombinerer de tre innlæringsmetodene (Presentasjon |Øving| Diskusjon) slik at vi gjennomfører kurset på en måte som sikrer at du lærer deg raskere og lettere.
  6. Du er i sikre hender.Vi har utdannet og sertifisert 108.090 personer, vi er partner med alle de store navn i bransjen og vi har vunnet atskillige utmerkelser, bla. a. "Årets Learning Partner 2010, 2011, 2012, 2013 og 2015” fra Microsoft Danmark og med en vekst på 1430 % siden 2009 er vi årets Gazelle prisvinner på Sjælland, Danmark.
  7. Du lærer deg ikke bare teorien. Vi har videreutviklet CCSK kursen og tilbyr flere praktiske øvelser og sikrer på den måten, at du kan bruke dine ferdigheter for å løse daglige praktiske problemstillinger.
  8. Du lærer av de beste. Våre instruktører på CCSK er de beste i bransjen og tilbyr en helt unik blanding av kunnskap, praktisk erfaring og pasjon for å lære bort.

Benefits

Curriculum

On this Firebrand Course, you'll cover the following topics:

Domain 1: Cloud Computing Concepts and Architectures

  • Defining Cloud Computing
  • Definitional Model
    • Essential Characteristics
    • Service Models
    • Deployment Models
  • Reference and Architecture Models
    • Infrastructure as a Service
    • Platform as a Service
    • Software as a Service
  • Logical Model
  • Cloud Security and Compliance Scope and Responsibilities
  • Cloud Security Models
    • A Simple Cloud Security Process Model
  • Governing in the Cloud
  • Operating in the Cloud

Domain 2: Governance and Enterprise Risk Management

  • Governance
    • Tools of Cloud Governance
  • Enterprise Risk Management
  • The Effects of Service Model and Deployment Model
    • Service Models
    • Deployment Models
    • Cloud Risk Management Trade-Offs
    • Cloud Risk Management Tools

Domain 3: Legal Issues, Contracts and Electronic Discover

  • Legal Frameworks Governing Data Protection and Privacy
    • Common Themes
    • Required Security Measures
    • Restrictions to Cross-border Data Transfers
    • Regional Examples – GDPR, NIS Directive, US Federal and State Laws
  • Contracts and Provider Selection
    • Internal Due Diligence
    • Monitoring, Testing, and Updating
    • External Due Diligence
    • Contract Negotiations
    • Reliance on Third-Party Audits and Attestations
  • Electronic Discovery
    • Possession, Custody and Control
    • Relevant Cloud Applications and Environment
    • Searchability and E-Discovery Tools
    • Preservation
    • Data Retention Laws and Record Keeping Obligations
    • Collection
    • Direct Access
    • Native Production
    • Authentication
    • Cooperation Between Provider and Client in E-Discovery
    • Response to a Subpoena or Search Warrant
    • More Information

Domain 4: Compliance and Audit Management

  • Compliance
    • How Cloud Changes Compliance
  • Audit Management
    • How Cloud Changes Audit Management

Domain 5: Information Governance

  • Cloud Information Governance Domains
  • The Data Security Lifecycle
    • Locations and Entitlements
    • Functions, Actors, and Controls

Domain 6: Management Plane and Business Continuity

  • Business Continuity and Disaster Recovery in the Cloud
    • Architect for Failure
  • Management Plane Security
    • Accessing the Management Plane
    • Securing the Management Plane
    • Management Plane Security When Building/Providing a Cloud Service
  • Business Continuity and Disaster Recovery
    • Business Continuity Within the Cloud Provider
    • Business Continuity for Loss of the Cloud Provider
    • Business Continuity For Private Cloud and Providers

Domain 7: Infrastructure Security

  • Cloud Network Virtualisation
  • How Security Changes With Cloud Networking
    • Challenges of Virtual Appliances
    • SDN Security Benefits
    • Microsegmentation and the Software Defined Perimeter
    • Additional Considerations for Cloud Providers or Private Clouds
    • Additional Considerations for Cloud Providers or Private Clouds
  • Cloud Compute and Workload Security
    • How Cloud Changes Workload Security
    • Immutable Workloads Enable Security
    • The Impact of Cloud on Standard Workload Security Controls
    • Changes to Workload Security Monitoring and Logging
    • Changes to Vulnerability Assessment
    • Cloud Storage Security

Domain 8: Virtualisation and Containers

  • Major Virtualisation Categories Relevant to Cloud Computing
    • Compute
  • Network
    • Monitoring and Filtering
    • Management Infrastructure
    • Cloud Overlay Networks
  • Storage
  • Containers

Domain 9: Incident Response

  • Incident Response Lifecycle
  • How the Cloud Impacts IR
    • Preparation
    • Detection and Analysis
    • Containment, Eradication and Recovery
    • Post-mortem

Domain 10: Application Security

  • Introduction to the Secure Software Development Lifecycle and Cloud Computing
  • Secure Design and Development
  • Secure Deployment
    • Impact on Vulnerability Assessment
    • Impact on Penetration Testing
    • Deployment Pipeline Security
    • Impact of Infrastructure as Code and Immutable
  • Secure Operations
  • How Cloud Impacts Application Design and Architectures
  • Additional Considerations for Cloud Providers
  • The Rise and Role of DevOps
    • Security Implications and Advantages

Domain 11: Data Security and Encryption

  • Data Security Controls
  • Cloud Data Storage Types
  • Managing Data Migrations to the Cloud
    • Securing Cloud Data Transfers
  • Securing Data in the Cloud
    • Cloud Data Access Controls
    • Storage (At-Rest) Encryption and Tokenization
    • Key Management (Including Customer-Managed Keys)
  • Data Security Architectures
  • Monitoring, Auditing, and Alerting
  • Additional Data Security Controls
    • Cloud Platform/Provider-Specific Controls
    • Data Loss Prevention
    • Enterprise Rights Management
    • Data Masking and Test Data Generation
  • Enforcing Lifecycle Management Security

Domain 12: Identity, Entitlement, and Access Management

  • How IAM is Different in the Cloud
  • IAM Standards for Cloud Computing
  • Managing Users and Identities for Cloud Computing
  • Authentication and Credentials
  • Entitlement and Access Management
  • Privileged User Management

Domain 13: Security as a Service

  • Potential Benefits and Concerns of SecaaS
  • Major Categories of Security as a Service Offerings
    • Identity, Entitlement, and Access Management Services
    • Cloud Access and Security Brokers (CASB, also known as Cloud Security Gateways)
    • Web Security (Web Security Gateways)
    • Email Security
    • Security Assessment
    • Web Application Firewalls
    • Intrusion Detection/Prevention (IDS/IPS)
    • Security Information & Event Management (SIEM)
    • Encryption and Key Management
    • Business Continuity and Disaster Recovery
    • Security Management
    • Distributed Denial of Service Protection

Domain 14: Related Technologies

  • Big Data
    • Security and Privacy Considerations
    • Data Collection
    • Key Management
    • Security Capabilities
    • Identity and Access Management
    • PaaS
  • Internet of Things (IoT)
  • Mobile
  • Serverless Computing

Exam Track

You'll sit the following exam at the Firebrand Training Centre, covered by your Certification Guarantee:

  • CSA Certificate of Cloud Security Knowledge (CCSK) exam

Additional exam information:

  • 60 online multiple choice questions
  • Time limit: 90 minutes
  • Pass rate: 80%

What's Included

Prerequisites

You should have a basic understanding of security fundamentals, such as firewalls, secure development, encryption and identity management.

Anmeldelser

Vi har lært opp 108.090 personer på 12 år. Vi ba dem om å anmelde vår akselererte opplæring. Akkurat nå har 96,66% angitt at Firebrand overgikk forventningene:

"Another fantastic experience. Thank you so much!"
Anonymous. (6/9/2021 (Mandag) til 9/9/2021 (Torsdag))

"Our tutor was amazing, he explained everything so well, and made the course really interesting, could not praise him enough!"
AF. (6/9/2021 (Mandag) til 9/9/2021 (Torsdag))

"Great training given by the tutor. Clear in his explanations and assisting the attendees where needed. Big thumbs up!"
Anonymous. (6/9/2021 (Mandag) til 8/9/2021 (Onsdag))

"I re-attended the course online after having attended the classroom based program initially. Enjoyed the session, although very content based, the tutor was good at covering all topics and had the chance to go over it again as revision. Would definitely attend future courses with Firebrand and select the same instructor. Very knowledgeable and thorough with his explanation. Made us think differently throughout the course."
Mohan Simkhada, EOL IT Services. (18/6/2021 (Fredag) til 20/6/2021 (Søndag))

"Facilities at training Center are exceptional. We don’t need to worry about anything and can fully concentrate on learning."
Venkatesh Bathineni. (3/9/2021 (Fredag) til 5/9/2021 (Søndag))

Kursdatoer

CSA - Firebrand's training for CSA's Certified Cloud Security Knowledge (CCSK) exam

Start

Slutt

Kapasitet

Registrer deg

16/9/2021 (Torsdag)

17/9/2021 (Fredag)

Ferdig - Gi tilbakemelding

 

16/12/2021 (Torsdag)

17/12/2021 (Fredag)

Ledige plasser

Registrer deg

4/4/2022 (Mandag)

5/4/2022 (Tirsdag)

Ledige plasser

Registrer deg

18/8/2022 (Torsdag)

19/8/2022 (Fredag)

Ledige plasser

Registrer deg

Siste anmeldelser fra studenten vår