1 of 23

Enhancing Cloud Security Enterprise

Anna Campbell Schorr

Training Program Director

A Guide to Cloud Security Alliance's Educational Pathways

PRESENTED BY

2 of 23

Agenda

Why Cybersecurity? Why Cloud?

Why Cloud Security Alliance?

CSA Training Portfolio

Become a Training Partner and/or Instructor

1

2

3

4

2

3 of 23

Why Cybersecurity?

3

4 of 23

Why Cloud?

4

5 of 23

Cybersecurity education is essential to protecting critical infrastructure.

  • Growing Need: High Demand & High Salaries: U.S. The Department of Labor predicts that information technology and cybersecurity jobs will be among the fastest-growing and highest-paying over the next decade.
  • Make an Impact: Cybersecurity has impacts that extend beyond the digital world and into the physical one.
  • Dynamic Field: Cybersecurity evolves quickly so you will always be learning and developing new skills.

5

6 of 23

6

7 of 23

Partnerships

7

8 of 23

8

9 of 23

9

10 of 23

Training Portfolio

Certificate of Cloud Security Knowledge (CCSK)

Certificate of Competence in Zero Trust (CCZT)

Security, Trust, Assurance and Risk (STAR) Lead Auditor

Certificate of Cloud Auditing Knowledge (CCAK)

Advanced Cloud Security Practitioner (ACSP)

Cloud Infrastructure Security Training

1

2

3

4

5

6

10

11 of 23

Certificate of Cloud Security Knowledge (CCSK)

The CCSK sits at a higher level. It summarizes knowledge across domains, gives value to managers and consultants who work with a broader range of technologies, and covers such aspects as risk management, vendor management, architecture, and multi-cloud.

- Nikolay Akatyev, VP of Internal Security and IT, Horangi Cyber Security

  • 94% of students found the CCSK relevant to their careers
  • 20,000+ global passholders
  • Optional Labs Included!

https://cloudsecurityalliance.org/education/ccsk/

.

11

12 of 23

Certificate of Competence in Zero Trust (CCZT)

Vendor Neutrality

Best Practices

Expert Driven

Innovative work around the Software Defined Perimeter by CSA Research and an extensive volunteer community of �industry leaders

Foundational Zero Trust guidance from authoritative sources, such as NIST �and CISA

Collaboration and leadership from renowned Zero Trust experts such as John Kindervag, the founder of Zero Trust

The industry’s first authoritative Zero Trust training and certificate

12

13 of 23

Security, Trust, Assurance & Risk (STAR) Lead Auditor

“Coalfire and Coalfire certification, the accredited certification body arm of Coalfire, began offering STAR™ attestation and certification services as part of its product catalog in response to increasing customer requests. As part of feedback reviews, Coalfire determined that many of our clients were seeking guidance pertaining to assurance programs that would address compliance in the cloud. While other baseline security standards can be vague when addressing shared responsibilities between the cloud provider and cloud user, the Cloud Controls Matrix (CCM) understands that relationship and enforces design requirements for both parties before rating the degree of conformity for any given objective” -David Forman, VP of Coalfire

2,300+ Registries!

https://cloudsecurityalliance.org/star/

13

14 of 23

Certificate of Cloud Auditing Knowledge (CCAK)

*The Financial Brand article “More Consumers Prefer Contactless Payments for Pandemic Purchases”

**107% 2016 and 2019: “Increase in USA cloud computing jobs.” - Indeed article "The Best Jobs of 2020", February 27, 2020 �

Consumer Benefits

  • 78% of consumers prefer contactless transactions–a key Cloud feature.*

Job Growth

  • Cloud migration is driving demand for multiple audits to mitigate risk.
  • 107% Increase in USA cloud computing jobs, 2016-2019.**

Cloud Benefits

  • Remote access
  • Cost Savings
  • Increased Collaboration
  • Disaster Recovery
  • Automatic Updates
  • Sustainability

14

15 of 23

Advanced Cloud Security Practitioner (ACSP)

Build

Implement

Leverage

Architect an enterprise-scale secure cloud. Build a deployment pipeline, integrate it into an existing application stack, and code a variety of security automation controls.

Manage enterprise security at cloud scale. Configure a production-quality account with multiple virtual networks and core security controls.

Build secure applications and run operations at the speed of cloud utilizing DevSecOps and automation.

15

16 of 23

  • Top Threats
  • Cloud Key Management Foundations I & 11
  • Micro-Services & Containers Fundamentals I & 11
  • Container Lifecycle Management & Assurance
  • Container Architecture Risks & Mitigations
  • DevSecOps: Collective Responsibility
  • DevSecOps: Bridging Compliance & Dev.
  • DevSecOps: Automation
  • DevSecOps: Pragmatic Implementation

& MORE! Artificial Intelligence, etc.

https://knowledge.cloudsecurityalliance.org/

16

17 of 23

Why Cybersecurity Training? Why now?

Evolving Technology

Workforce�Development

Security Gaps

Emergence of AI

Computer technology continues to shift towards an open but untrusted infrastructure

Skills gaps are widening with rapidly evolving cybersecurity threats. CSA’s Training provides a strategy for individuals and organizations to develop the necessary skills to keep up

CSA’s Training can help address gaps in traditional security models and facilitate a more mature and sustainable approach to security

Rapid availability of AI tools makes implementing a cybersecurity strategy critical

17

18 of 23

Benefits

CPE Credits

Earn towards CPE credits or other continuing education credits

Digital Badge

Showcase your knowledge and validate your expertise across all digital forums

Professional Advancement

Gain a competitive edge in the job market

Authoritative Source

CSA facilitates the integration of trusted experts, sources and tools

18

19 of 23

Training Delivery Options

Self-Paced

Instructor Led

Virtual Instructor Led

If you want training but have a hard time fitting in a regular course and need something flexible enough for your schedule and budget then our self-paced training may be a good fit.

You get the opportunity to interact with an instructor face to face, ask questions and learn in the same room with other students.

For individuals who work best when they can ask questions. May also be an option for companies with a tight travel budget.

19

20 of 23

Training Partners & Authorized Instructors

  1. Career Advancement: Enhance your professional profile and increase your value in the industry.
  2. Industry Recognition: Gain credibility and establish yourself as an authority in the field.
  3. Knowledge Sharing and Impact: Educate and empower professionals and contribute to building a stronger cloud.

Contact Us! Training@cloudsecurityalliance.org

https://cloudsecurityalliance.org/education/instructors/

https://cloudsecurityalliance.org/education/training-partners/

20

21 of 23

Success Stories

“I took a CCSK class from Peter. He prepares well, engages the class, and covers all the important facets of cloud computing. Peter's class was the only boot camp I've actually enjoyed taking. I recently took and passed the CCSP exam, and felt that much of what I needed to successfully navigate the test was covered in depth by the CCSK class. Thank you for the great class!” - Student

“Zero Trust is the future of information security. “Investing in Zero Trust and the CCZT is an investment in our organization’s future. Through the CCZT, our team was able to gain invaluable insights into Zero Trust best practices. Professionals seeking validation on their understanding and implementation of Zero Trust should strongly consider obtaining the CCZT.” - Rob LaMagna-Reiter VP, Information Security & Compliance, and CISO, Hudl

21

22 of 23

Call to Action: Get Involved!

Questions? Thank you for your time today!

22

23 of 23

Questions?

Thank you for your time today.

23