Cloud Security Fundamentals
This programme introduces participants to the security challenges and best practices specific to cloud environments. Covering AWS, Azure, and Google Cloud in context, participants will learn how to assess cloud security posture, apply identity and access controls, and understand shared responsibility in cloud deployments. Suitable for IT professionals, system administrators, and security staff moving into cloud roles.
The session is built around the shared responsibility model, because most cloud breaches trace back to a misunderstanding of where the provider's obligations end and the customer's begin. Participants work through identity and access management, network controls, encryption at rest and in transit, logging and monitoring, and the configuration errors that cause the majority of real incidents, including public storage and over-permissioned service accounts. Malaysian regulatory context is covered where it applies, including PDPA obligations for personal data held in cloud services and the cross-border considerations that follow from choosing a region.
HRD Corp SBL-Khas Claimable
Modules
Introduction to Cloud Computing and Security
Cloud service models (IaaS, PaaS, SaaS), deployment types, and the shared responsibility model. Understanding what the cloud provider secures and what you are responsible for.
Identity and Access Management in the Cloud
IAM policies, roles, groups, and permissions across AWS, Azure, and GCP. Principle of least privilege, multi-factor authentication, and service account security.
Network Security in the Cloud
Virtual private clouds (VPCs), security groups, network access control lists, and securing communication between cloud services and on-premises systems.
Data Security and Encryption
Encrypting data at rest and in transit. Key management services, data classification, and preventing unauthorised access to cloud storage and databases.
Monitoring, Logging and Incident Response
Cloud-native monitoring tools, log aggregation, setting alerts for suspicious activity, and responding to cloud security incidents.
Cloud Security Compliance and Governance
ISO 27001, CIS Benchmarks, and Malaysian regulatory requirements in cloud deployments. Cloud security posture management (CSPM) basics.
Key Outcomes
- Explain the shared responsibility model for major cloud platforms
- Configure IAM policies applying the principle of least privilege
- Identify and remediate common cloud misconfigurations
- Apply encryption and data security controls in cloud environments
- Use cloud-native monitoring tools to detect suspicious activity
- Assess a cloud environment against basic compliance and governance requirements
Final Activity
Cloud Security Audit Exercise. Participants are given a simulated cloud environment configuration and must identify misconfigurations, excessive permissions, and unencrypted resources. Findings are documented in a structured audit report.
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Minimum enrolment 3 participants
Duration 2 Days
Level Intermediate (basic IT or networking knowledge required)
Certificate included Yes