|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cloud-security-and-compliance-fundamentals-course/
课程评论:没有评论
课程名称:云安全课程:云合规性、审计和法律问题 概述:本云安全课程旨在提供对云计算相关安全和合规要求的全面理解,以及组织在使用云服务时需要关注的法律和监管问题。课程首先介绍云安全的基础知识,包括各种云服务的类型以及在云中保护数据和应用的共享责任模型。您将学习与不同类型云服务(如基础设施即服务(IaaS)、平台即服务(PaaS)和软件即服务(SaaS))相关的安全和合规要求。 在课程中,您将学习保护在云中数据和应用的最佳实践与技术,包括加密、访问控制以及威胁检测与响应。您还将了解帮助组织评估和改善云安全态势的各种工具和资源,包括云安全评估、渗透测试和漏洞管理。此外,课程还涵盖了组织在使用云服务时需要遵循的审计和合规要求,例如SOC2、ISO27001和PCI-DSS。 课程分为五个主要部分: 1. 理解云协议/合同 2. 云资产与安全配置管理 3. 保护数据免受未经授权访问 4. 如何处理云服务提供商的安全事件 5. 法律与合规 在每个部分中,您将学习到以下内容: 1. 理解云协议/合同:合同的重要性、如何与云服务提供商谈判以规避未来的处罚、CSA(云服务协议)的主要文档,以及云中的SLA和可接受使用政策等重要概念。 2. 云资产与安全配置管理:如何有效发现云中的资产、面临的挑战、SecDevOps和安全配置、云中的漏洞和补丁管理。 3. 保护数据免受未经授权访问:保护数据的主要问题,如云部署模型与安全问题、数据位置、数据敏感性和法律义务,以及云中的媒体清理。 4. 如何处理云服务提供商的安全事件:CSP事件响应和通知流程、云中的事件响应过程、在取证调查中可从CSP获取的日志数据和支持。 5. 法律与合规:信息管理的法律责任、云中的法律问题、电子发现问题、云中需要遵循的法规,以及管辖权和位置问题。 本课程适合从事信息安全、IT或相关领域的专业人士,以及任何对如何在云中保护数据和应用程序并遵守与云计算相关的各种法律和监管要求感兴趣的人。课程结束时,您将全面理解云安全和合规性,以及组织在使用云服务时需要注意的法律和监管问题。
This Cloud Security Course is designed to provide a comprehensive understanding of the security and compliance requirements associated with cloud computing, as well as the legal and regulatory issues that organizations need to be aware of when using cloud services.The course starts by introducing the basics of cloud security, including the various types of cloud services available and the shared responsibility model for securing data and applications in the cloud. You will learn about the security and compliance requirements associated with different types of cloud services, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).Throughout the course, you will learn about the best practices and technologies that can be used to secure data and applications in the cloud, including encryption, access controls, and threat detection and response. You will also learn about the various tools and resources that are available to help organizations assess and improve their cloud security posture, including cloud security assessments, penetration testing, and vulnerability management.It will also cover the auditing and compliance requirements such as SOC2, ISO27001, PCI-DSS that organizations need to comply with when using cloud services.This course has divided in 5 Major Sections.1. Understand Cloud Agreements/Contracts2. Cloud Assets and Secure Configuration Management3. Protecting data from UN-Authorized Access4. Handling Security Incidents with Cloud Service Provider5. Legal and ComplianceThis is not a complete list; one can check for recommendations by NIST, CSA STAR and implement security in organization as per their own unique requirement.What you will learn1. Understand Cloud Agreements/ContractsIn this section, you will learn importance of Contracts. How you can negotiate with Cloud Service providers for items to cover in contract to avoid future penalties. You will learn major artifacts for CSA (Cloud Service Agreement). You will learn important concepts like SLA in CLOUD, Acceptable use policy in Cloud.2. Cloud Assets and Secure Configuration ManagementIn this section, you will learn assets discovery issues in cloud, how to have complete asset discovery in cloud for effective security and compliance. You will learn Challenges in Cloud Asset Discovery, SecDevops and secure configuration. You will vulnerability and patch management in cloud.3. Protecting data from UN-Authorized AccessIn this Section, you will learn various issues you can consider protecting un-authorized access of data in cloud. You will learn various concerns like Cloud Deployment Model and Security Concerns, Location of data, what kind of Data Sensitivity and Legal Obligations would be there in cloud. How to do Media Sanitization in Cloud and many more. You will learn about IAAS, PAAS and SAAS Security issues.4. Handling Security Incidents with Cloud Service ProviderIn this Section, you will learn what to check in CSP incident response and Security Notification process, Incident response process in a cloud. You will also learn what kind log data / Support can be obtain from CSP during forensics investigations.5. Legal and ComplianceIn this Section, you will learn Information Management Legal Responsibilities, what are different types of legal issues in cloud. E-discovery issues in Cloud, What Regulations to follow in Cloud and Jurisdictional and Location issues in cloud environment.The course is suitable for professionals working in the field of information security, IT, or related fields, as well as anyone interested in learning more about how to secure data and applications in the cloud and comply with the various legal and regulatory requirements associated with cloud computing. By the end of the course, you will have a comprehensive understanding of cloud security and compliance, as well as the legal and regulatory issues that organizations need to be aware of when using cloud services.