|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/security-best-practices-in-google-cloud
课程评论:没有评论
课程名称:Google Cloud 安全最佳实践 课程概述:本自学导向的培训课程为参与者提供了关于 Google Cloud 安全控制和技术的广泛学习。通过录制的讲座、演示和动手实验,参与者将探索和部署安全 Google Cloud 解决方案的组成部分,包括云存储访问控制技术、安全密钥、客户自备加密密钥、API 访问控制、作用域、保护虚拟机、加密和签署的 URL。此外,课程还涵盖了 Kubernetes 环境的安全性。 课程大纲: 1. **欢迎来到 Google Cloud 安全最佳实践**: 本课程将基于之前的“管理 Google Cloud 中的安全”课程奠定的基础,学习如何实施安全“最佳实践”,以降低系统、软件和数据遭受恶意攻击的风险。 2. **计算引擎安全:技术与最佳实践**: 本模块将讨论服务账户、IAM 角色和 API 作用域如何适用于计算引擎。还将讨论管理虚拟机登录及如何使用组织策略设置适用于组织层级所有资源的约束。同时回顾计算引擎的最佳实践,提供保护计算引擎的建议,并涵盖使用客户自备加密密钥对持久磁盘进行加密。 3. **云数据安全:技术与最佳实践**: 本模块讨论如何控制云存储存储桶上的 IAM 权限和访问控制列表,审计云数据,包括发现和修复可以公开访问的数据,如何使用签名的云存储 URL 和签名政策文档,以及静态数据加密。此外,还将介绍 BigQuery IAM 角色和授权视图,以展示如何管理数据集和表的访问权限。 4. **应用安全:技术与最佳实践**: 本模块讨论应用安全技术和最佳实践,展示如何使用 Web 安全扫描器识别应用程序中的漏洞,并探讨身份和 OAuth 钓鱼问题。最后,学习如何使用身份感知代理(IAP)控制对云应用程序的访问。 5. **安全 Google Kubernetes Engine:技术与最佳实践**: 保护 Google Kubernetes Engine 中的工作负载涉及多个层次,包括容器镜像的内容、容器运行时、集群网络和对集群 API 服务器的访问。本模块将学习如何安全设置身份验证和授权,如何加强集群、保护工作负载,以及监控以确保其正常运行。 通过本课程,参与者将掌握在 Google Cloud 上实施安全最佳实践所需的知识和技能。
Name:Welcome to Security Best Practices in Google Cloud
Description:Welcome to Security Best Practices in Google Cloud! In this course we will build upon the foundations laid during the earlier course in this series, Managing Security in Google Cloud. In this section, expect to learn more about how to implement security "best practices" to lower the risk of malicious attacks against your systems, software and data.
Name:Securing Compute Engine: Techniques and Best Practices
Description:In this module we will start with a discussion of service accounts, IAM roles and API scopes as they apply to compute engine. We will also discuss managing VM logins, and how to use organization policies to set constraints that apply to all resources in your organization's hierarchy. Next, we will review compute engine best practices to give you some tips for securing compute engine.Lastly, we will cover encrypting persistent disks with Customer-Supplied Encryption keys.
Name:Securing Cloud Data: Techniques and Best Practices
Description:In this module we discuss controlling IAM permissions and access control lists on Cloud Storage buckets, auditing cloud data, including finding and remediating data that has been set to publicly accessible, how to use signed Cloud Storage URLs and signed policy documents, and encrypting data at rest. In addition, BigQuery IAM roles and authorized views will be covered to demonstrate managing access to datasets and tables. The module will conclude with an overview of storage best practices
Name:Application Security: Techniques and Best Practices
Description:In this module we will discuss application security techniques and best practices. We will see how Web Security Scanner can be used to identify vulnerabilities in your applications, and dive into the subject of Identity and Oauth phishing. Lastly, you will learn how Identity-Aware Proxy, or IAP, can be used to control access to your cloud applications.
Name:Securing Google Kubernetes Engine: Techniques and Best Practices
Description:Protecting workloads in Google Kubernetes Engine involves many layers of the stack, including the contents of your container image, the container runtime, the cluster network, and access to the cluster API server. In this module, you will learn how to securely set up your Authentication and Authorization, how to harden your clusters, secure your workloads, and monitor everything to make sure it stays in good health.
This self-paced training course gives participants broad study of security controls and techniques on Google Cloud. Through recorded lectures, demonstrations, and hands-on labs, participants explore and deploy the components of a secure Google Cloud solution, including Cloud Storage access control technologies, Security Keys, Customer-Supplied Encryption Keys, API access controls, scoping, shielded VMs, encryption, and signed URLs. It also covers securing Kubernetes environments.