Course Code: cl-cls
Duration: 21 hours
Overview:

Migrating to the cloud introduces immense benefits for companies and individuals in terms of efficiency and costs. With respect to security, the effects are quite diverse, but it is a common perception that using cloud services impacts security in a positive manner. Opinions, however, diverge many times even on defining who is responsible for ensuring the security of cloud resources.

Covering IaaS, PaaS and SaaS, first the security of the infrastructure is discussed: hardening and configuration issues as well as various solutions for authentication and authorization alongside identity management that should be at the core of all security architecture. This is followed by some basics regarding legal and contractual issues, namely how trust is established and governed in the cloud.

The journey through cloud security continues with understanding cloud-specific threats and the attackers’ goals and motivations as well as typical attack steps taken against cloud solutions. Special focus is also given to auditing the cloud and providing security evaluation of cloud solutions on all levels, including penetration testing and vulnerability analysis.

The focus of the course is on application security issues, dealing both with data security and the security of the applications themselves. From the standpoint of application security, cloud computing security is not substantially different from general software security, and therefore basically all OWASP-enlisted vulnerabilities are relevant in this domain as well. It is the set of threats and risks that makes the difference, and thus the training is concluded with the enumeration of various cloud-specific attack vectors connected to the weaknesses discussed beforehand.

Participants attending this course will

  • Understand basic concepts of security, IT security and secure coding
  • Understand major threats and risks in the cloud domain
  • Learn about elementary cloud security solutions
  • Get information about the trust and the governance regarding the cloud
  • Have a practical understanding of cryptography
  • Get extensive knowledge in application security in the cloud
  • Learn Web vulnerabilities beyond OWASP Top Ten and know how to avoid them
  • Understand the challenges of auditing and evaluating cloud systems for security
  • Learn how to secure the cloud environment and infrastructure
  • Get sources and further readings on secure coding practices

Audience

Developers, Managers, Professionals

Course Outline:
  • IT security and secure coding
  • Threats and risks in the clouds
  • Cloud security solutions
  • Trust and governance
  • Practical cryptography
  • Common implementation mistakes
  • Web application security
  • Security audit in the cloud
  • Securing the cloud environment
  • Data security in the cloud
  • Knowledge sources
Sites Published:

United Arab Emirates - Application Security in the Cloud

Qatar - Application Security in the Cloud

Egypt - Application Security in the Cloud

Saudi Arabia - Application Security in the Cloud

South Africa - Application Security in the Cloud

Brasil - Application Security in the Cloud

Canada - Application Security in the Cloud

中国 - Application Security in the Cloud

香港 - Application Security in the Cloud

澳門 - Application Security in the Cloud

台灣 - Application Security in the Cloud

USA - Application Security in the Cloud

Österreich - Application Security in the Cloud

Schweiz - Application Security in the Cloud

Deutschland - Application Security in the Cloud

Czech Republic - Application Security in the Cloud

Denmark - Application Security in the Cloud

Estonia - Application Security in the Cloud

Finland - Application Security in the Cloud

Greece - Application Security in the Cloud

Magyarország - Application Security in the Cloud

Ireland - Application Security in the Cloud

Luxembourg - Application Security in the Cloud

Latvia - Application Security in the Cloud

España - Seguridad de Aplicaciones en la Nube

Italia - Application Security in the Cloud

Lithuania - Application Security in the Cloud

Nederland - Application Security in the Cloud

Norway - Application Security in the Cloud

Portugal - Application Security in the Cloud

România - Application Security in the Cloud

Sverige - Application Security in the Cloud

Türkiye - Application Security in the Cloud

Malta - Application Security in the Cloud

Belgique - Application Security in the Cloud

France - Application Security in the Cloud

日本 - Application Security in the Cloud

Australia - Application Security in the Cloud

Malaysia - Application Security in the Cloud

New Zealand - Application Security in the Cloud

Philippines - Application Security in the Cloud

Singapore - Application Security in the Cloud

Thailand - Application Security in the Cloud

Vietnam - Application Security in the Cloud

India - Application Security in the Cloud

Argentina - Seguridad de Aplicaciones en la Nube

Chile - Seguridad de Aplicaciones en la Nube

Costa Rica - Seguridad de Aplicaciones en la Nube

Ecuador - Seguridad de Aplicaciones en la Nube

Guatemala - Seguridad de Aplicaciones en la Nube

Colombia - Seguridad de Aplicaciones en la Nube

México - Seguridad de Aplicaciones en la Nube

Panama - Seguridad de Aplicaciones en la Nube

Peru - Seguridad de Aplicaciones en la Nube

Uruguay - Seguridad de Aplicaciones en la Nube

Venezuela - Seguridad de Aplicaciones en la Nube

Polska - Application Security in the Cloud

United Kingdom - Application Security in the Cloud

South Korea - Application Security in the Cloud

Pakistan - Application Security in the Cloud

Sri Lanka - Application Security in the Cloud

Bulgaria - Application Security in the Cloud

Bolivia - Seguridad de Aplicaciones en la Nube

Indonesia - Application Security in the Cloud

Kazakhstan - Application Security in the Cloud

Moldova - Application Security in the Cloud

Morocco - Application Security in the Cloud

Tunisia - Application Security in the Cloud

Kuwait - Application Security in the Cloud

Oman - Application Security in the Cloud

Slovakia - Application Security in the Cloud

Kenya - Application Security in the Cloud

Nigeria - Application Security in the Cloud

Botswana - Application Security in the Cloud

Slovenia - Application Security in the Cloud

Croatia - Application Security in the Cloud

Serbia - Application Security in the Cloud

Bhutan - Application Security in the Cloud

Nepal - Application Security in the Cloud

Uzbekistan - Application Security in the Cloud