|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/google-cloud-security-best-practices-f/
课程评论:没有评论
课程名称:Google Cloud Security Best Practices 概述:本课程《Google Cloud Security Best Practices》是针对云专业人士、安全工程师、架构师、系统管理员和合规官的深入实践指南,旨在帮助他们保护在Google Cloud Platform(GCP)上的工作负载。随着云环境的复杂性不断增加,采取积极的结构化安全态度已成为必要。本课程为学习者提供了构建、管理和扩展GCP安全云环境所需的概念理解和技术实施技能。 课程内容首先明确GCP的共享责任模型,阐明Google管理的安全控制和客户责任之间的界限。接下来,涵盖了GCP的本地安全服务,如Cloud IAM、Cloud KMS、VPC服务控制、Cloud审计日志和安全指挥中心,这些服务旨在加强云安全架构的不同方面。 课程深入探讨了云安全的基础支柱,包括身份、网络、数据和操作,教授如何在GCP服务中应用关键原则,如最少特权、深度防御和零信任。学习者将通过模块获得实践知识,包括确保IAM政策不允许访问个人电子邮件帐户、启用多因素身份验证(MFA)、强制管理帐户的安全密钥和防止用户管理服务帐户密钥的使用。 课程还涵盖了关键主题,如服务帐户权限限制、自动KMS密钥轮换和防止Cloud Storage以及BigQuery数据集的公共访问。网络层最佳实践包括启用VPC流日志、阻止项目范围内的SSH密钥、禁用虚拟机实例上的串行端口和IP转发。此外,学生将学习如何启用OS登录以实现集中式SSH访问、配置Cloud审计日志、设置日志传输和定义日志保留策略。 数据保护主题包括强制App Engine使用HTTPS、要求Cloud SQL使用SSL、限制公共IP访问和启用自动备份以防止数据丢失。每个模块都包含明确的实施步骤,确保学生可以直接应用所学内容,通过GCP控制台或gcloud CLI进行操作。 通过本课程的学习,学生将能够设计和维护与现代云安全框架和合规标准(如CIS基准、ISO 27001、NIST 800-53、PCI-DSS和HIPAA)一致的安全GCP环境。本课程对于任何希望在GCP中大规模实现安全的团队都是必不可少的。
This course, Google Cloud Security Best Practices, is an in-depth, practical guide designed for cloud professionals, security engineers, architects, system administrators, and compliance officers who want to secure their workloads on Google Cloud Platform (GCP). As cloud environments grow increasingly complex, adopting a proactive and structured security posture is no longer optional-it is essential. This course equips learners with both the conceptual understanding and the technical implementation skills needed to build, manage, and scale secure cloud environments in GCP.We begin by demystifying the Shared Responsibility Model in GCP, establishing a clear understanding of which security controls are managed by Google and which fall under the customer's responsibility. This is followed by an overview of GCP's native security services, such as Cloud IAM, Cloud KMS, VPC Service Controls, Cloud Audit Logging, and Security Command Center, each designed to strengthen different aspects of the cloud security architecture.The course dives deep into the foundational pillars of cloud security-Identity, Network, Data, and Operations-and teaches how to apply key principles like least privilege, defense in depth, and zero trust across GCP services. Students will gain hands-on knowledge through modules that include ensuring IAM policies don't allow access to personal email accounts, enabling multi-factor authentication (MFA), enforcing security keys for admin accounts, and preventing the use of user-managed service account keys.We also cover crucial topics such as service account permission restriction, automated KMS key rotation, and preventing public access to Cloud Storage and BigQuery datasets. Network-level best practices include enabling VPC Flow Logs, blocking project-wide SSH keys, and disabling serial port and IP forwarding on VM instances. Additionally, students will learn how to enable OS Login for centralized SSH access, configure Cloud Audit Logs, set up log sinks, and define log retention policies.Data protection topics cover enforcing HTTPS for App Engine, requiring SSL for Cloud SQL, restricting public IP access, and enabling automated backups to safeguard against data loss. Each module includes clear implementation steps, ensuring students can directly apply what they learn using the GCP Console or gcloud CLI.By the end of this course, learners will be able to design and maintain a secure GCP environment that aligns with modern cloud security frameworks and compliance standards such as CIS Benchmarks, ISO 27001, NIST 800-53, PCI-DSS, and HIPAA. This course is essential for any team seeking to operationalize security at scale within GCP.