Cloud Security Architecture, Global Privacy & Sector Compliance

Multi-cloud perimeter hardening, international privacy statutes, FinTech, and DevSecOps

Tackle complex, highly regulated perimeters. Perform technical security reviews across AWS, Azure, and GCP using the Cloud Security Alliance (CSA) CCM v4; navigate international privacy frameworks including EU/UK GDPR, NDPA/NDPR, and Saudi PDPL; implement strict payment and health regulations (PCI DSS v4.0, SWIFT CSP, HIPAA, HITRUST); and enforce DevSecOps maturity via BSIMM and OWASP SAMM.

$149 $29 81% OFF
2.6 CEU Credits
26 Study Hours (4 Weeks)
Advanced
4 Modules
24 Hands-on Labs
Course Tuition
$149 $29 81% OFF
CEU Credits 2.6 CEUs
Study Workload Breakdown (26 Hours):
Architectural Reading & Theory: 8 hrs
Hands-on Labs & Coding Drills: 18 hrs
Live Mentorship Cohort $150

Prefer live accountability? Join a guided 4–6 week cohort with weekly live faculty calls, 1-on-1 code reviews & capstone grading. Subsidized by Savadub Limited CSR.

Join Cohort ($150)
Subsidized Tuition: This course is made accessible at $29 through the Corporate Social Responsibility (CSR) endowment from Savadub Limited and partner sponsors.

Course Prerequisites

Part of Academy Track:
Enterprise GRC & Information Security Engineering Stage 3 of 5 Courses in this track progression.
Access Lab Materials on LMS
Competency Matrix

What You Will Master

Implement PCI DSS v4.0 network segmentation and cryptographic key rotation
Conduct Data Protection Impact Assessments (DPIAs) and cross-border transfer reviews
Benchmark multi-tenant cloud environments against CIS Foundations and CSA CCM
Embed security controls directly into Terraform and Kubernetes manifests
Detailed Syllabus

Curriculum Modules (4 Modules)

Explore the structured module breakdown, lesson outcomes, and practical lab exercises.

01

Module 1: Multi-Cloud Security Reviews & Benchmark Engineering

6 Lessons • ~6.5 Study Hours (0.65 CEUs)
~6.5 hrs 0.65 CEUs

Welcome to Module 1: Multi-Cloud Security Reviews & Benchmark Engineering. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A complete guide to AWS security reviews β€” covering IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, CIS Benchmarks for AWS, and how to build a continuously secure AWS environment aligned to SOC 2 and ISO 27001.; A complete guide to Azure security reviews β€” covering Azure AD/Entra ID, NSGs, Defender for Cloud, Sentinel, CIS Benchmarks for Azure, and how to align your Azure environment to SOC 2, ISO 27001, and GDPR.; A complete guide to Google Cloud Platform security reviews β€” covering IAM, VPC, Cloud Audit Logs, Security Command Center, Chronicle, CIS Benchmarks for GCP, and achieving SOC 2 and ISO 27001 compliance on GCP..

01
AWS Security Review β€” IAM, S3, GuardDuty & Security Hub Hardening

A complete guide to AWS security reviews β€” covering IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, CIS Benchmarks for AWS, and how to build a continuously secure AWS environment aligned to SOC 2 and ISO 27001.

~65 min Lab Exercise
02
Azure Security Review β€” Entra ID, Network Security & Defender for Cloud

A complete guide to Azure security reviews β€” covering Azure AD/Entra ID, NSGs, Defender for Cloud, Sentinel, CIS Benchmarks for Azure, and how to align your Azure environment to SOC 2, ISO 27001, and GDPR.

~65 min Lab Exercise
03
Google Cloud Security Review β€” Organization Policies, VPC SC & SCC

A complete guide to Google Cloud Platform security reviews β€” covering IAM, VPC, Cloud Audit Logs, Security Command Center, Chronicle, CIS Benchmarks for GCP, and achieving SOC 2 and ISO 27001 compliance on GCP.

~65 min Lab Exercise
04
Cloud Security Assessment β€” Multi-Cloud Architecture & Baseline Evaluation

A complete guide to cloud security assessments β€” what they cover, how to assess IAM, network, data, logging, and compliance controls across AWS, Azure, and GCP, and how to build a continuous cloud security posture.

~65 min Lab Exercise
05
CSA Cloud Controls Matrix (CCM) β€” Cloud Security Assurance & STAR Certification

A complete guide to the CSA Cloud Controls Matrix (CCM) β€” what it covers, how it maps to other standards, how to complete the CAIQ, and how cloud providers use STAR certification to demonstrate security assurance.

~65 min Lab Exercise
06
CIS Controls v8 Assessment β€” Implementation Groups (IG1-IG3) & Safeguards

A complete guide to CIS Controls Version 8 β€” the 18 controls, three implementation groups, how to conduct a CIS Controls assessment, and how to use CIS Benchmarks to harden your systems.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 2: Global Data Privacy Laws & Cross-Border Compliance. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Everything organisations need to know about GDPR compliance β€” the six principles, lawful bases, data subject rights, controller and processor obligations, DPIA requirements, breach notification, and building a sustainable compliance program.; A complete guide to UK GDPR β€” how it differs from EU GDPR, the role of the ICO, international transfer mechanisms post-Brexit, and what organisations processing UK personal data must do to stay compliant.; A complete guide to Nigeria's Data Protection Act 2023 β€” how it evolves from NDPR, the new NDPC regulator, enhanced data subject rights, and what organisations must do to transition their compliance programs..

01
EU GDPR Compliance β€” Lawful Bases, Data Protection Officers & Cross-Border Transfers

Everything organisations need to know about GDPR compliance β€” the six principles, lawful bases, data subject rights, controller and processor obligations, DPIA requirements, breach notification, and building a sustainable compliance program.

~65 min Lab Exercise
02
UK GDPR Compliance β€” Post-Brexit Regulatory Architecture & ICO Enforcement

A complete guide to UK GDPR β€” how it differs from EU GDPR, the role of the ICO, international transfer mechanisms post-Brexit, and what organisations processing UK personal data must do to stay compliant.

~65 min Lab Exercise
03
Nigeria Data Protection Act (NDPA 2023) β€” Statutory Mandates & Regulatory Oversight

A complete guide to Nigeria's Data Protection Act 2023 β€” how it evolves from NDPR, the new NDPC regulator, enhanced data subject rights, and what organisations must do to transition their compliance programs.

~65 min Lab Exercise
04
NDPR Compliance β€” Operational Framework & Annual Regulatory Audit Filings

Everything Nigerian organisations and international businesses processing Nigerian personal data need to know about NDPR compliance β€” NITDA registration, lawful basis, data subject rights, audit requirements, and building a sustainable data governance framework.

~65 min Lab Exercise
05
Saudi Arabia Personal Data Protection Law (PDPL) β€” SDAIA Requirements

Everything organisations need to know about Saudi Arabia's Personal Data Protection Law β€” key requirements, the SDAIA regulator, processing rules, cross-border transfer restrictions, and building a compliant data governance program.

~65 min Lab Exercise
06
UAE Personal Data Protection Law (Federal Decree-Law No. 45/2021) β€” Compliance Guide

A complete guide to the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection β€” what it covers, who it applies to, key requirements, sector-specific considerations, and how to build a UAE PDPL compliance program.

~65 min Lab Exercise
07
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016) β€” Governance Guide

A complete guide to Qatar's Law No. 13 of 2016 on Personal Data Privacy Protection β€” what it covers, key requirements, the role of the Ministry of Communications, and how to build a compliant data protection program for Qatar operations.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 3: High-Assurance Regulated Sectors β€” Fintech & Healthcare. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A comprehensive guide to PCI DSS v4.0 β€” the 12 requirements, SAQ types, QSA assessment process, network segmentation, the major changes from v3.2.1, and how to achieve and maintain compliance as a merchant or service provider.; A complete guide to the SWIFT Customer Security Programme β€” mandatory controls, the CSCF framework, community standard controls, the annual attestation process, and how to achieve and maintain CSP compliance as a SWIFT correspondent.; Everything covered entities and business associates need to know about HIPAA compliance β€” the Privacy Rule, Security Rule, Breach Notification Rule, risk analysis requirements, technical safeguards, and how to build a sustainable HIPAA compliance program..

01
PCI DSS 4.0 β€” The 12 Principal Requirements for Cardholder Data Security

A comprehensive guide to PCI DSS v4.0 β€” the 12 requirements, SAQ types, QSA assessment process, network segmentation, the major changes from v3.2.1, and how to achieve and maintain compliance as a merchant or service provider.

~65 min Lab Exercise
02
SWIFT Customer Security Programme (CSP) β€” Mandatory Controls & Independent Assessment

A complete guide to the SWIFT Customer Security Programme β€” mandatory controls, the CSCF framework, community standard controls, the annual attestation process, and how to achieve and maintain CSP compliance as a SWIFT correspondent.

~65 min Lab Exercise
03
HIPAA Compliance β€” Security Rule, Privacy Rule, Breach Notification & Business Associates

Everything covered entities and business associates need to know about HIPAA compliance β€” the Privacy Rule, Security Rule, Breach Notification Rule, risk analysis requirements, technical safeguards, and how to build a sustainable HIPAA compliance program.

~65 min Lab Exercise
04
HITRUST CSF β€” Multi-Framework Healthcare Security & Privacy Certification

A complete guide to HITRUST CSF certification β€” what the Common Security Framework covers, the three assurance levels (e1, i1, r2), how to prepare for assessment, and why HITRUST is the gold standard for healthcare vendor assurance.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 4: Application Security, DevSecOps & Security Maturity. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A complete guide to Secure SDLC β€” how to integrate security requirements, threat modelling, code review, SAST/DAST, and penetration testing into every phase of your development lifecycle to produce more secure software faster.; A practical guide to DevSecOps β€” how to integrate security tooling, processes, and culture into your CI/CD pipeline, infrastructure as code, and release process to build security at speed.; A complete guide to OWASP Top 10 2021 β€” what each vulnerability is, real-world exploitation examples, how to detect it, and how to remediate and build lasting defences into your development lifecycle..

01
Secure SDLC β€” Embedding Security Controls from Architecture Design to Production

A complete guide to Secure SDLC β€” how to integrate security requirements, threat modelling, code review, SAST/DAST, and penetration testing into every phase of your development lifecycle to produce more secure software faster.

~65 min Lab Exercise
02
DevSecOps Pipeline Security Review β€” Automated SAST, DAST, SCA & Secrets Gating

A practical guide to DevSecOps β€” how to integrate security tooling, processes, and culture into your CI/CD pipeline, infrastructure as code, and release process to build security at speed.

~65 min Lab Exercise
03
OWASP Top 10 β€” Critical Web Application Vulnerabilities & Engineering Remediation

A complete guide to OWASP Top 10 2021 β€” what each vulnerability is, real-world exploitation examples, how to detect it, and how to remediate and build lasting defences into your development lifecycle.

~65 min Lab Exercise
04
OWASP API Security Top 10 β€” Protecting Modern REST & GraphQL Endpoints

A deep dive into the OWASP API Security Top 10 2023 β€” what each API vulnerability is, how attackers exploit it, and how to build defences into your API design, development, and operations.

~65 min Lab Exercise
05
BSIMM Assessment β€” Benchmarking Software Security Initiatives Against Industry Peers

A complete guide to BSIMM (Building Security In Maturity Model) β€” how it works, the 121 activities across 12 practices, how a BSIMM assessment is conducted, and how to use BSIMM data to prioritise your software security programme.

~65 min Lab Exercise
06
OWASP SAMM β€” Measuring & Maturing Software Security Programmes

A complete guide to OWASP SAMM (Software Assurance Maturity Model) β€” the five business functions, fifteen security practices, maturity levels, and how to use SAMM assessments to build a roadmap for software security improvement.

~65 min Lab Exercise
07
Cybersecurity Maturity Assessment β€” Enterprise Gap Analysis & Strategic Roadmapping

A complete guide to cybersecurity maturity assessments β€” what they measure, the frameworks used (NIST CSF, CIS Controls, CMM), how assessments are conducted, and how to use results to build a prioritised security improvement roadmap.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

GRC & Information Security Progression

Continue advancing through the sequential curriculum stages of this academy track:

Enroll in GRC-301 on LMS