Cloud Security Controls for Cybersecurity Analysts Training Course
| Course code | SD-CC-019 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cloud Computing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Cybersecurity analysts are increasingly expected to investigate alerts, validate cloud configurations, assess identity exposure and explain control gaps to cloud engineering teams. Traditional network-centric monitoring is not enough when access is granted through IAM policies, workloads run in ephemeral containers and misconfigurations can expose storage or management interfaces within minutes. This course equips analysts to evaluate whether cloud security controls are operating effectively across AWS and Azure environments, prioritise findings by business impact and produce evidence that supports remediation decisions.
Participants work through the control areas most relevant to operational cloud defence: shared-responsibility boundaries, identity and privileged access, network segmentation, encryption and key management, logging, cloud posture management, workload protection and incident response. They learn to interpret IAM policies, test security-group and network-security-group exposure, query cloud audit trails, map controls to the CIS benchmarks, and use Azure Policy, Microsoft Defender for Cloud and AWS IAM Access Analyzer to identify weaknesses. The course also develops the practical judgement needed to distinguish a configuration exception from a credible attack path.
Delivery combines instructor-led technical briefings with guided console-based analysis, realistic misconfiguration cases and team-based investigations. Participants analyse cloud evidence, document control failures and practise framing remediation recommendations for security, platform and application owners. Each participant leaves with a completed cloud security control assessment pack: a scoped control matrix, prioritised findings register, evidence checklist and 90-day remediation plan that can be adapted for their own environment.
The programme is suited to analysts moving into cloud security work and to security teams that need a repeatable method for assuring public-cloud controls without requiring participants to be cloud architects or developers.
Course objectives
By the end of this course, participants will be able to:
- Map AWS and Azure shared-responsibility models to an analyst-owned cloud control assessment scope
- Review IAM roles, policies and privileged access paths using least-privilege analysis and AWS IAM Access Analyzer
- Assess security group and network security group rules for internet exposure, segmentation failures and risky management access
- Validate encryption, key-management and secret-handling controls against defined data protection requirements
- Query cloud audit evidence to investigate suspicious identity, configuration and workload activity
- Configure and evaluate policy-based compliance checks with Azure Policy and Microsoft Defender for Cloud
- Prioritise cloud control findings using exploitability, asset criticality and compensating-control evidence
- Produce a cloud security control assessment pack containing findings, remediation owners, evidence and target dates
Benefits of attending
For you
- Build credible evidence-based cloud findings rather than reporting generic configuration concerns
- Develop practical experience interpreting IAM, network and audit-log controls across AWS and Azure
- Gain a reusable assessment pack for demonstrating cloud assurance capability in analyst roles
- Improve the quality of remediation conversations with cloud engineers through precise control evidence
- Strengthen readiness for cloud security analyst, SOC cloud monitoring and security assurance responsibilities
For your organisation
- Establish a consistent method for testing cloud identity, network, logging and data protection controls
- Reduce exposure from excessive permissions, public-facing services and incomplete audit coverage
- Improve prioritisation of cloud findings by linking technical weaknesses to exploitable attack paths
- Create clearer remediation ownership and evidence requirements between security and cloud operations teams
- Increase the value of existing AWS and Azure security tooling through more capable analyst use
Target competencies
Who should attend
- Cybersecurity Analysts — who need to assess cloud alerts, configurations and control effectiveness
- SOC Analysts — who investigate cloud identity, audit-log and workload security events
- Cloud Security Analysts — who require a repeatable assessment method across AWS and Azure
- Information Security Analysts — who translate cloud control gaps into risk and remediation actions
- GRC Analysts — who collect evidence and map cloud controls to recognised security benchmarks
- Cloud Operations Engineers — who need to understand how analysts test and report control weaknesses
Requirements and prerequisites
Participants should understand core cybersecurity concepts including authentication, authorisation, least privilege, network ports, logging, vulnerability risk and incident escalation. Familiarity with the purpose of AWS IAM, Azure RBAC, security groups or network security groups is helpful, but deep administration experience is not assumed. Participants should be comfortable navigating a web console, reading basic policy statements and working with spreadsheets. No programming, cloud architecture certification, SIEM engineering or prior hands-on AWS or Azure account administration is required. Complete beginners to cloud computing should first learn basic cloud service and deployment terminology.
Training methodology
The course uses short instructor-led modules to establish each control domain, followed by guided analysis in AWS and Azure-style lab environments. Participants inspect IAM permissions, network rules, policy results and audit events, then compare their evidence against CIS benchmark expectations. Case studies require teams to decide whether findings represent misconfiguration, accepted risk or active compromise, and to justify their priority. Daily exercises build toward an end-of-course assessment workshop, where each participant creates a control matrix, findings register and practical remediation plan for a defined cloud scenario.
Course outline
Day 1: Cloud security control foundations
- Cloud service models and security ownership boundaries
- AWS and Azure shared-responsibility comparison
- Cloud asset inventory and control-scoping method
- Control objectives for identity, network, data and logging
- CIS AWS Foundations Benchmark structure
- Cloud attack paths from exposed configuration to compromise
- Risk-based finding classification and evidence standards
Workshop: Participants scope a cloud control review for a fictional business service and produce an initial asset, ownership and evidence checklist.
Day 2: Identity and privileged access controls
- AWS IAM users, roles, policies and permission boundaries
- Azure RBAC roles, scopes and managed identities
- Least-privilege review using effective-permission analysis
- AWS IAM Access Analyzer external-access findings
- Privileged access management and break-glass account controls
- Multi-factor authentication and conditional access evidence
- Service-account keys, secrets and credential lifecycle risks
Workshop: Participants investigate an excessive-permission scenario and produce a prioritised IAM remediation recommendation with supporting evidence.
Day 3: Network, data and workload protection
- Security groups and network security groups rule analysis
- Internet exposure testing for management ports and public endpoints
- Network segmentation across virtual networks and subnets
- Encryption at rest, in transit and key-management controls
- Cloud storage access controls and public-access prevention
- Workload protection for virtual machines, containers and serverless services
- Vulnerability and image-risk findings in Microsoft Defender for Cloud
Workshop: Teams assess a deliberately misconfigured application environment and create a network and data protection findings register.
Day 4: Logging, detection and posture management
- CloudTrail and Azure Activity Log event sources
- Audit-log retention, integrity and centralisation controls
- Identity-event investigation using cloud audit evidence
- Microsoft Defender for Cloud secure score and recommendations
- Azure Policy definitions, initiatives and compliance results
- Continuous cloud posture management workflows
- Alert triage from misconfiguration finding to incident decision
Workshop: Participants investigate a suspicious cloud administration sequence, correlate policy and audit evidence, and write an analyst escalation record.
Day 5: Assessment reporting and remediation planning
- Cloud control testing procedures and evidence collection
- Mapping findings to CIS benchmark recommendations
- Exploitability, business criticality and compensating-control scoring
- Writing technically actionable remediation statements
- Assigning remediation owners and target completion dates
- Exception handling and residual-risk documentation
- Metrics for cloud control coverage and remediation ageing
Workshop: Participants complete and present a cloud security control assessment pack containing a control matrix, prioritised findings register and 90-day remediation plan.
Tools & standards covered
AWS IAM Access Analyzer, Microsoft Defender for Cloud, Azure Policy, CIS AWS Foundations Benchmark
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cloud Computing
Cloud Governance Skills for IT Managers Training Course
IT managers are expected to enable teams to use cloud services quickly while retaining control of spend, security, data handling and operati…
Cloud Data Platform Engineering for Data Engineers Training Course
Data engineers are increasingly expected to build more than individual pipelines: they must create reliable cloud data platforms that ingest…
Cloud Networking Fundamentals for Infrastructure Teams Training Course
Infrastructure teams increasingly support applications spread across cloud accounts, regions, managed services and on-premises environments.…
Cloud Computing for Healthcare IT Teams Training Course
Healthcare IT teams are under pressure to modernise clinical, administrative and data platforms without exposing protected health informatio…