Cloud Security Architecture, Global Privacy & Sector Compliance
Multi-cloud perimeter hardening, international privacy statutes, FinTech, and DevSecOps
Tackle complex, highly regulated perimeters. Perform technical security reviews across AWS, Azure, and GCP using the Cloud Security Alliance (CSA) CCM v4; navigate international privacy frameworks including EU/UK GDPR, NDPA/NDPR, and Saudi PDPL; implement strict payment and health regulations (PCI DSS v4.0, SWIFT CSP, HIPAA, HITRUST); and enforce DevSecOps maturity via BSIMM and OWASP SAMM.
Course Prerequisites
- Enterprise Compliance Frameworks & Audit Readiness and foundational cloud infrastructure knowledge (AWS/Azure/GCP).
Part of Academy Track:
What You Will Master
Curriculum Modules (4 Modules)
Explore the structured module breakdown, lesson outcomes, and practical lab exercises.
Module 1: Multi-Cloud Security Reviews & Benchmark Engineering
6 Lessons • ~6.5 Study Hours (0.65 CEUs)Welcome to Module 1: Multi-Cloud Security Reviews & Benchmark Engineering. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A complete guide to AWS security reviews β covering IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, CIS Benchmarks for AWS, and how to build a continuously secure AWS environment aligned to SOC 2 and ISO 27001.; A complete guide to Azure security reviews β covering Azure AD/Entra ID, NSGs, Defender for Cloud, Sentinel, CIS Benchmarks for Azure, and how to align your Azure environment to SOC 2, ISO 27001, and GDPR.; A complete guide to Google Cloud Platform security reviews β covering IAM, VPC, Cloud Audit Logs, Security Command Center, Chronicle, CIS Benchmarks for GCP, and achieving SOC 2 and ISO 27001 compliance on GCP..
AWS Security Review β IAM, S3, GuardDuty & Security Hub Hardening
A complete guide to AWS security reviews β covering IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, CIS Benchmarks for AWS, and how to build a continuously secure AWS environment aligned to SOC 2 and ISO 27001.
Azure Security Review β Entra ID, Network Security & Defender for Cloud
A complete guide to Azure security reviews β covering Azure AD/Entra ID, NSGs, Defender for Cloud, Sentinel, CIS Benchmarks for Azure, and how to align your Azure environment to SOC 2, ISO 27001, and GDPR.
Google Cloud Security Review β Organization Policies, VPC SC & SCC
A complete guide to Google Cloud Platform security reviews β covering IAM, VPC, Cloud Audit Logs, Security Command Center, Chronicle, CIS Benchmarks for GCP, and achieving SOC 2 and ISO 27001 compliance on GCP.
Cloud Security Assessment β Multi-Cloud Architecture & Baseline Evaluation
A complete guide to cloud security assessments β what they cover, how to assess IAM, network, data, logging, and compliance controls across AWS, Azure, and GCP, and how to build a continuous cloud security posture.
CSA Cloud Controls Matrix (CCM) β Cloud Security Assurance & STAR Certification
A complete guide to the CSA Cloud Controls Matrix (CCM) β what it covers, how it maps to other standards, how to complete the CAIQ, and how cloud providers use STAR certification to demonstrate security assurance.
CIS Controls v8 Assessment β Implementation Groups (IG1-IG3) & Safeguards
A complete guide to CIS Controls Version 8 β the 18 controls, three implementation groups, how to conduct a CIS Controls assessment, and how to use CIS Benchmarks to harden your systems.
Module 2: Global Data Privacy Laws & Cross-Border Compliance
7 Lessons • ~7.6 Study Hours (0.76 CEUs)Welcome to Module 2: Global Data Privacy Laws & Cross-Border Compliance. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Everything organisations need to know about GDPR compliance β the six principles, lawful bases, data subject rights, controller and processor obligations, DPIA requirements, breach notification, and building a sustainable compliance program.; A complete guide to UK GDPR β how it differs from EU GDPR, the role of the ICO, international transfer mechanisms post-Brexit, and what organisations processing UK personal data must do to stay compliant.; A complete guide to Nigeria's Data Protection Act 2023 β how it evolves from NDPR, the new NDPC regulator, enhanced data subject rights, and what organisations must do to transition their compliance programs..
EU GDPR Compliance β Lawful Bases, Data Protection Officers & Cross-Border Transfers
Everything organisations need to know about GDPR compliance β the six principles, lawful bases, data subject rights, controller and processor obligations, DPIA requirements, breach notification, and building a sustainable compliance program.
UK GDPR Compliance β Post-Brexit Regulatory Architecture & ICO Enforcement
A complete guide to UK GDPR β how it differs from EU GDPR, the role of the ICO, international transfer mechanisms post-Brexit, and what organisations processing UK personal data must do to stay compliant.
Nigeria Data Protection Act (NDPA 2023) β Statutory Mandates & Regulatory Oversight
A complete guide to Nigeria's Data Protection Act 2023 β how it evolves from NDPR, the new NDPC regulator, enhanced data subject rights, and what organisations must do to transition their compliance programs.
NDPR Compliance β Operational Framework & Annual Regulatory Audit Filings
Everything Nigerian organisations and international businesses processing Nigerian personal data need to know about NDPR compliance β NITDA registration, lawful basis, data subject rights, audit requirements, and building a sustainable data governance framework.
Saudi Arabia Personal Data Protection Law (PDPL) β SDAIA Requirements
Everything organisations need to know about Saudi Arabia's Personal Data Protection Law β key requirements, the SDAIA regulator, processing rules, cross-border transfer restrictions, and building a compliant data governance program.
UAE Personal Data Protection Law (Federal Decree-Law No. 45/2021) β Compliance Guide
A complete guide to the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection β what it covers, who it applies to, key requirements, sector-specific considerations, and how to build a UAE PDPL compliance program.
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016) β Governance Guide
A complete guide to Qatar's Law No. 13 of 2016 on Personal Data Privacy Protection β what it covers, key requirements, the role of the Ministry of Communications, and how to build a compliant data protection program for Qatar operations.
Module 3: High-Assurance Regulated Sectors β Fintech & Healthcare
4 Lessons • ~4.3 Study Hours (0.43 CEUs)Welcome to Module 3: High-Assurance Regulated Sectors β Fintech & Healthcare. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A comprehensive guide to PCI DSS v4.0 β the 12 requirements, SAQ types, QSA assessment process, network segmentation, the major changes from v3.2.1, and how to achieve and maintain compliance as a merchant or service provider.; A complete guide to the SWIFT Customer Security Programme β mandatory controls, the CSCF framework, community standard controls, the annual attestation process, and how to achieve and maintain CSP compliance as a SWIFT correspondent.; Everything covered entities and business associates need to know about HIPAA compliance β the Privacy Rule, Security Rule, Breach Notification Rule, risk analysis requirements, technical safeguards, and how to build a sustainable HIPAA compliance program..
PCI DSS 4.0 β The 12 Principal Requirements for Cardholder Data Security
A comprehensive guide to PCI DSS v4.0 β the 12 requirements, SAQ types, QSA assessment process, network segmentation, the major changes from v3.2.1, and how to achieve and maintain compliance as a merchant or service provider.
SWIFT Customer Security Programme (CSP) β Mandatory Controls & Independent Assessment
A complete guide to the SWIFT Customer Security Programme β mandatory controls, the CSCF framework, community standard controls, the annual attestation process, and how to achieve and maintain CSP compliance as a SWIFT correspondent.
HIPAA Compliance β Security Rule, Privacy Rule, Breach Notification & Business Associates
Everything covered entities and business associates need to know about HIPAA compliance β the Privacy Rule, Security Rule, Breach Notification Rule, risk analysis requirements, technical safeguards, and how to build a sustainable HIPAA compliance program.
HITRUST CSF β Multi-Framework Healthcare Security & Privacy Certification
A complete guide to HITRUST CSF certification β what the Common Security Framework covers, the three assurance levels (e1, i1, r2), how to prepare for assessment, and why HITRUST is the gold standard for healthcare vendor assurance.
Module 4: Application Security, DevSecOps & Security Maturity
7 Lessons • ~7.6 Study Hours (0.76 CEUs)Welcome to Module 4: Application Security, DevSecOps & Security Maturity. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A complete guide to Secure SDLC β how to integrate security requirements, threat modelling, code review, SAST/DAST, and penetration testing into every phase of your development lifecycle to produce more secure software faster.; A practical guide to DevSecOps β how to integrate security tooling, processes, and culture into your CI/CD pipeline, infrastructure as code, and release process to build security at speed.; A complete guide to OWASP Top 10 2021 β what each vulnerability is, real-world exploitation examples, how to detect it, and how to remediate and build lasting defences into your development lifecycle..
Secure SDLC β Embedding Security Controls from Architecture Design to Production
A complete guide to Secure SDLC β how to integrate security requirements, threat modelling, code review, SAST/DAST, and penetration testing into every phase of your development lifecycle to produce more secure software faster.
DevSecOps Pipeline Security Review β Automated SAST, DAST, SCA & Secrets Gating
A practical guide to DevSecOps β how to integrate security tooling, processes, and culture into your CI/CD pipeline, infrastructure as code, and release process to build security at speed.
OWASP Top 10 β Critical Web Application Vulnerabilities & Engineering Remediation
A complete guide to OWASP Top 10 2021 β what each vulnerability is, real-world exploitation examples, how to detect it, and how to remediate and build lasting defences into your development lifecycle.
OWASP API Security Top 10 β Protecting Modern REST & GraphQL Endpoints
A deep dive into the OWASP API Security Top 10 2023 β what each API vulnerability is, how attackers exploit it, and how to build defences into your API design, development, and operations.
BSIMM Assessment β Benchmarking Software Security Initiatives Against Industry Peers
A complete guide to BSIMM (Building Security In Maturity Model) β how it works, the 121 activities across 12 practices, how a BSIMM assessment is conducted, and how to use BSIMM data to prioritise your software security programme.
OWASP SAMM β Measuring & Maturing Software Security Programmes
A complete guide to OWASP SAMM (Software Assurance Maturity Model) β the five business functions, fifteen security practices, maturity levels, and how to use SAMM assessments to build a roadmap for software security improvement.
Cybersecurity Maturity Assessment β Enterprise Gap Analysis & Strategic Roadmapping
A complete guide to cybersecurity maturity assessments β what they measure, the frameworks used (NIST CSF, CIS Controls, CMM), how assessments are conducted, and how to use results to build a prioritised security improvement roadmap.
GRC & Information Security Progression
Continue advancing through the sequential curriculum stages of this academy track: