About this course
Cloud breaches are rarely caused by the cloud provider's infrastructure failing. Far more often, they trace back to a misconfigured storage bucket, an overly permissive access role, or an identity control that was never locked down. This course is built for cloud administrators and technical staff who configure and maintain AWS, Azure, or GCP environments, and it focuses on the specific controls that fall on the customer's side of the shared responsibility line.
The shared responsibility model is the foundational concept in cloud security: the cloud provider secures the underlying infrastructure, physical data centers, host operating systems, and network hardware, while the customer is responsible for securing what they put into the cloud, including data, identity and access management, application configuration, and network controls within their own environment. AWS, Azure, and GCP each describe this differently, but the underlying division of duties is consistent across all three: the provider secures the cloud, the customer secures what's in it.
This distinction matters because misconfiguration and identity failures, not provider-side infrastructure compromise, remain among the most common root causes of cloud security incidents. Administrators who understand exactly where their responsibility begins are better equipped to prioritize the controls that actually reduce risk: least-privilege identity and access management (IAM), encryption of data at rest and in transit, network segmentation, logging and monitoring, and routine configuration audits.
This course is intended for cloud administrators, DevOps engineers, and IT staff responsible for provisioning or maintaining cloud infrastructure. After completing it, learners will be able to explain the shared responsibility model to stakeholders, apply least-privilege principles to IAM roles and permissions, identify common cloud misconfiguration patterns before they become incidents, and build basic logging and monitoring practices into cloud deployments.
Topics covered
- The shared responsibility model across AWS, Azure, and GCP
- Identity and access management (IAM) and least-privilege design
- Common misconfiguration risks: storage, network, and permission settings
- Encryption of data at rest and in transit
- Logging, monitoring, and detecting anomalous cloud activity
- Building configuration review into ongoing cloud operations
Want this tailored to your organization's policies? Build your own with AI or book a demo.