Cloud Security Architecture for Solutions Architects Training Course

10 days Cyber Security Certificate on completion
Course codeSD-CS-050
Duration10 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during assurance reviews. That requires more than adding identity controls or enabling encryption after a build is complete. Architects must make early decisions about trust boundaries, tenant isolation, network paths, data classification, logging coverage, third-party integrations and resilience that determine the organisation’s exposure long after deployment. This course addresses the practical challenge of designing security into cloud solution architectures across IaaS, PaaS, containers and serverless services.

Participants learn to translate threat, regulatory and operational requirements into architecture decisions and traceable security controls. The course covers shared responsibility, zero-trust design, identity and access architecture, secure network segmentation, secrets management, encryption key strategies, workload protection, cloud-native logging, incident-response design and policy-as-code. Participants use threat modelling, control mapping and architecture review methods to assess a reference cloud solution, identify attack paths, select proportionate mitigations and document design trade-offs for engineering teams and risk stakeholders.

Instructor-led sessions combine architecture walkthroughs, facilitated design reviews, cloud security case studies and hands-on modelling exercises. Each participant develops a security architecture pack for a realistic cloud-hosted service, including a context diagram, data-flow diagram, threat model, control matrix, target-state architecture and prioritised remediation roadmap. The final day includes a design assurance presentation in which participants defend their recommendations against cost, delivery, compliance and operational constraints. Participants receive a certificate on completion.

The programme is designed for solutions architects working with cloud migrations, digital products, enterprise platforms or major application modernisation initiatives. It is particularly valuable where architects need to give delivery teams clear, implementable guardrails rather than high-level security statements.

Course objectives

By the end of this course, participants will be able to:

  • Create cloud security context and data-flow diagrams that define trust boundaries, assets and external dependencies
  • Apply STRIDE threat modelling to identify attack paths and prioritise mitigations for a cloud solution
  • Design least-privilege IAM patterns using federated access, role separation and privileged-access controls
  • Specify network segmentation, private connectivity and ingress-egress controls for multi-tier cloud workloads
  • Map architecture controls to NIST SP 800-53 and Cloud Controls Matrix requirements using a traceability matrix
  • Evaluate encryption, key management, secrets handling and data-residency options for classified data
  • Define logging, detection, incident-response and evidence-retention requirements for cloud workloads
  • Produce a security architecture pack and remediation roadmap suitable for architecture review approval

Benefits of attending

For you

  • Build a defensible method for explaining why a cloud security control belongs in a solution design
  • Create threat models and control matrices that strengthen architecture review submissions
  • Gain practical language for negotiating security, delivery speed, resilience and cost trade-offs with stakeholders
  • Recognise insecure cloud design patterns before they become expensive implementation or audit issues
  • Leave with a reusable security architecture pack structure for future migration and product initiatives

For your organisation

  • Reduce late-stage redesign by identifying trust-boundary, identity and data-protection gaps during architecture definition
  • Create more consistent cloud security decisions across projects through reusable control and review patterns
  • Improve audit readiness with traceable links between requirements, architecture controls and implementation evidence
  • Lower exposure to credential misuse, public-data access and weak network isolation through stronger design standards
  • Enable faster security assurance reviews by giving architects a shared vocabulary, artefacts and decision criteria

Target competencies

Cloud threat modellingZero-trust architectureIAM design patternsControl traceabilitySecurity logging designArchitecture risk assessment

Who should attend

  • Solutions Architects — who must embed security decisions into cloud solution designs before engineering delivery begins
  • Cloud Architects — who define landing zones, connectivity patterns and reusable platform guardrails
  • Enterprise Architects — who need to govern security standards across application portfolios and cloud programmes
  • Technical Architects — who translate security requirements into implementable patterns for delivery teams
  • Security Architects — who review cloud designs and need a consistent method for challenging architecture decisions
  • Lead Developers and Engineering Managers — who own application architecture decisions affecting cloud risk

Requirements and prerequisites

Participants should have practical experience reading solution architecture diagrams and discussing cloud services such as virtual networks, compute, storage, managed databases and identity services. Familiarity with at least one major cloud platform, preferably AWS or Microsoft Azure, is assumed, along with a working understanding of TCP/IP, web applications, APIs, authentication and basic encryption terminology. Participants should be able to interpret an IAM policy or role assignment at a high level. Prior coding, penetration-testing experience, advanced cryptography knowledge and an existing security certification are not required. The course teaches architecture-level decisions rather than platform administration.

Training methodology

The course is delivered through instructor-led architecture briefings, guided whiteboard design sessions and hands-on analysis of a cloud-hosted customer service platform. Participants model data flows in Microsoft Threat Modeling Tool, inspect IAM and network design choices, map controls to NIST SP 800-53 and use Terraform examples to examine policy-as-code guardrails. Small groups conduct architecture review boards, challenge proposed mitigations and document justified trade-offs. The final sessions focus on assembling and presenting an individual security architecture pack and a 90-day application plan for the participant’s own environment.

Course outline

Day 1: Cloud security architecture foundations

  • Business drivers for cloud security architecture decisions
  • Shared responsibility across IaaS, PaaS, SaaS and serverless services
  • Architecture viewpoints, stakeholders and security quality attributes
  • Cloud asset identification and data classification methods
  • Trust boundaries in hybrid and multi-cloud solution diagrams
  • Security architecture principles and reusable design patterns
  • Risk appetite, assumptions and architecture decision records

Workshop: Participants analyse a customer portal brief and produce an initial asset inventory, security assumptions log and context diagram.

Day 2: Threat modelling cloud solutions

  • STRIDE threat modelling for cloud-hosted systems
  • Data-flow diagram notation and process decomposition
  • Attack surface analysis for APIs, portals and integrations
  • Threat libraries for identity, storage and management planes
  • Threat prioritisation using likelihood, impact and exploitability
  • Mitigation selection and residual-risk documentation
  • Microsoft Threat Modeling Tool workflows and reporting

Workshop: Participants build a data-flow diagram and STRIDE threat model in Microsoft Threat Modeling Tool for a public-facing application.

Day 3: Identity and zero-trust access design

  • Zero-trust principles for workforce, workload and partner access
  • Federation, single sign-on and conditional access architecture
  • Least-privilege role design and separation of duties
  • Privileged access management and just-in-time administration
  • Workload identities, managed identities and service accounts
  • Cross-account and cross-tenant access patterns
  • IAM policy review for privilege escalation risks

Workshop: Participants design an IAM role model for administrators, developers, CI/CD pipelines and third-party support personnel.

Day 4: Network and platform protection

  • Hub-and-spoke, transit and segmented virtual network patterns
  • Public ingress, private endpoints and service exposure decisions
  • Security groups, network security groups and firewall policy design
  • DNS, egress control and outbound traffic inspection
  • Web application firewalls, API gateways and DDoS protection
  • Hybrid connectivity and on-premises trust extension risks
  • Container, Kubernetes and serverless network considerations

Workshop: Participants produce a segmented network architecture for a three-tier service with partner API access and private data services.

Day 5: Data protection and secrets architecture

  • Data classification and handling requirements in cloud services
  • Encryption in transit, at rest and in use
  • Customer-managed keys, provider-managed keys and key hierarchy design
  • Hardware security modules, key rotation and key recovery controls
  • Secrets vault patterns for applications and automation pipelines
  • Tokenisation, masking and anonymisation design choices
  • Data residency, backup protection and secure deletion requirements

Workshop: Participants create a data protection design specifying encryption, key ownership, secrets flows, retention and recovery controls.

Day 6: Secure cloud delivery and policy-as-code

  • Infrastructure-as-code security architecture principles
  • Terraform module design and secure variable handling
  • Policy-as-code guardrails and preventive control patterns
  • CI/CD identity design and pipeline credential minimisation
  • Image provenance, dependency risk and software supply-chain controls
  • Configuration drift detection and exception management
  • Security gates for architecture, build and deployment stages

Workshop: Participants review a Terraform deployment pattern and define policy checks, secret-handling controls and pipeline permissions.

Day 7: Detection, response and operational resilience

  • Cloud logging architecture across control, data and workload planes
  • Security event normalisation and SIEM integration requirements
  • Detection use cases for identity abuse and data exfiltration
  • Alert triage, escalation paths and incident response runbooks
  • Forensic readiness, evidence integrity and log retention
  • Resilience patterns for ransomware, regional failure and destructive actions
  • Security metrics, control health and operational ownership

Workshop: Participants define a logging and incident-response design for a compromised workload identity scenario.

Day 8: Governance, assurance and control mapping

  • NIST SP 800-53 control families for cloud architecture
  • Cloud Security Alliance Cloud Controls Matrix domains
  • Control inheritance in cloud landing zones and managed services
  • Architecture control matrices and requirement traceability
  • Evidence design for audits, certifications and customer assurance
  • Third-party service assessment and shared-responsibility analysis
  • Risk acceptance, compensating controls and exception governance

Workshop: Participants map a target architecture to selected NIST SP 800-53 and Cloud Controls Matrix controls and identify evidence owners.

Day 9: Architecture review and design trade-offs

  • Security architecture review board preparation
  • Evaluating reference architectures and anti-patterns
  • Cost, usability, latency and security trade-off analysis
  • Multi-account and multi-subscription landing zone decisions
  • SaaS integration, vendor risk and API security review
  • Migration security risks and phased remediation planning
  • Architecture decision records and executive risk communication

Workshop: Participants conduct a peer architecture review and produce prioritised findings, accepted risks and design decision records.

Day 10: Capstone security architecture pack

  • Security architecture pack structure and quality criteria
  • Consolidating threat model findings into target-state controls
  • Prioritising remediation by risk, dependency and delivery effort
  • Defining implementation work packages and control owners
  • Measuring architecture conformance after deployment
  • Presenting security design decisions to technical and business stakeholders
  • Ninety-day application planning for workplace adoption

Workshop: Participants present their completed security architecture pack, control matrix and 90-day remediation roadmap to a simulated design assurance board.

Tools & standards covered

Microsoft Threat Modeling Tool, Terraform, NIST SP 800-53, Cloud Security Alliance Cloud Controls Matrix

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand common cloud building blocks such as virtual networks, compute, storage, managed databases and identity services. The course does not assume that you are a cloud administrator, but it does move quickly beyond introductory cloud terminology.

A laptop capable of accessing browser-based course materials is recommended for classroom participants and required for live online delivery. You do not need your own cloud subscription; practical exercises use provided scenarios, templates and tool demonstrations rather than personal production environments.

Yes, security architects and cloud security engineers benefit when they need to assess or influence solution designs. The emphasis remains on the architect’s decisions, artefacts and trade-offs rather than operating a SOC or performing penetration tests.

This course focuses on designing secure solutions before and during delivery, using threat models, control matrices, architecture patterns and review methods. It is not a product configuration course and does not train participants to memorise a single cloud provider’s certification objectives.

Participants can use the supplied architecture pack structure to add trust boundaries, threat analysis, control ownership and evidence requirements to active designs. The methods are applicable to new cloud builds, migrations, SaaS integrations and platform landing-zone reviews.

You leave with a completed security architecture pack for the capstone scenario, including diagrams, a threat model, control traceability matrix and remediation roadmap. You also receive reusable templates and a 90-day plan for applying the approach in your own architecture practice.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

FortiGate Firewall Security Policy Administration Training Course

FortiGate administrators are expected to turn network access requirements into firewall rules that protect services without interrupting bus…

5 Days Certificate

Cyber Security Governance for Government and Public Sector Teams Training Course

Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…

5 Days Certificate

Cyber Security Compliance for Healthcare Organisations Training Course

Healthcare organisations must protect electronic protected health information (ePHI) while keeping clinical, administrative and patient-faci…

5 Days Certificate

Microsoft Sentinel Threat Detection Training Course

Security operations teams often collect more telemetry than they can investigate effectively. Microsoft Sentinel can centralise alerts, inci…