Cloud Security Controls for Cybersecurity Analysts Training Course

5 days Cloud Computing Certificate on completion
Course codeSD-CC-019
Duration5 days
LevelFoundation to Intermediate
CategoryCloud Computing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Cybersecurity analysts are increasingly expected to investigate alerts, validate cloud configurations, assess identity exposure and explain control gaps to cloud engineering teams. Traditional network-centric monitoring is not enough when access is granted through IAM policies, workloads run in ephemeral containers and misconfigurations can expose storage or management interfaces within minutes. This course equips analysts to evaluate whether cloud security controls are operating effectively across AWS and Azure environments, prioritise findings by business impact and produce evidence that supports remediation decisions.

Participants work through the control areas most relevant to operational cloud defence: shared-responsibility boundaries, identity and privileged access, network segmentation, encryption and key management, logging, cloud posture management, workload protection and incident response. They learn to interpret IAM policies, test security-group and network-security-group exposure, query cloud audit trails, map controls to the CIS benchmarks, and use Azure Policy, Microsoft Defender for Cloud and AWS IAM Access Analyzer to identify weaknesses. The course also develops the practical judgement needed to distinguish a configuration exception from a credible attack path.

Delivery combines instructor-led technical briefings with guided console-based analysis, realistic misconfiguration cases and team-based investigations. Participants analyse cloud evidence, document control failures and practise framing remediation recommendations for security, platform and application owners. Each participant leaves with a completed cloud security control assessment pack: a scoped control matrix, prioritised findings register, evidence checklist and 90-day remediation plan that can be adapted for their own environment.

The programme is suited to analysts moving into cloud security work and to security teams that need a repeatable method for assuring public-cloud controls without requiring participants to be cloud architects or developers.

Course objectives

By the end of this course, participants will be able to:

  • Map AWS and Azure shared-responsibility models to an analyst-owned cloud control assessment scope
  • Review IAM roles, policies and privileged access paths using least-privilege analysis and AWS IAM Access Analyzer
  • Assess security group and network security group rules for internet exposure, segmentation failures and risky management access
  • Validate encryption, key-management and secret-handling controls against defined data protection requirements
  • Query cloud audit evidence to investigate suspicious identity, configuration and workload activity
  • Configure and evaluate policy-based compliance checks with Azure Policy and Microsoft Defender for Cloud
  • Prioritise cloud control findings using exploitability, asset criticality and compensating-control evidence
  • Produce a cloud security control assessment pack containing findings, remediation owners, evidence and target dates

Benefits of attending

For you

  • Build credible evidence-based cloud findings rather than reporting generic configuration concerns
  • Develop practical experience interpreting IAM, network and audit-log controls across AWS and Azure
  • Gain a reusable assessment pack for demonstrating cloud assurance capability in analyst roles
  • Improve the quality of remediation conversations with cloud engineers through precise control evidence
  • Strengthen readiness for cloud security analyst, SOC cloud monitoring and security assurance responsibilities

For your organisation

  • Establish a consistent method for testing cloud identity, network, logging and data protection controls
  • Reduce exposure from excessive permissions, public-facing services and incomplete audit coverage
  • Improve prioritisation of cloud findings by linking technical weaknesses to exploitable attack paths
  • Create clearer remediation ownership and evidence requirements between security and cloud operations teams
  • Increase the value of existing AWS and Azure security tooling through more capable analyst use

Target competencies

Cloud control assessmentIAM policy analysisConfiguration risk triageCloud audit investigationPolicy compliance monitoringRemediation evidence reporting

Who should attend

  • Cybersecurity Analysts — who need to assess cloud alerts, configurations and control effectiveness
  • SOC Analysts — who investigate cloud identity, audit-log and workload security events
  • Cloud Security Analysts — who require a repeatable assessment method across AWS and Azure
  • Information Security Analysts — who translate cloud control gaps into risk and remediation actions
  • GRC Analysts — who collect evidence and map cloud controls to recognised security benchmarks
  • Cloud Operations Engineers — who need to understand how analysts test and report control weaknesses

Requirements and prerequisites

Participants should understand core cybersecurity concepts including authentication, authorisation, least privilege, network ports, logging, vulnerability risk and incident escalation. Familiarity with the purpose of AWS IAM, Azure RBAC, security groups or network security groups is helpful, but deep administration experience is not assumed. Participants should be comfortable navigating a web console, reading basic policy statements and working with spreadsheets. No programming, cloud architecture certification, SIEM engineering or prior hands-on AWS or Azure account administration is required. Complete beginners to cloud computing should first learn basic cloud service and deployment terminology.

Training methodology

The course uses short instructor-led modules to establish each control domain, followed by guided analysis in AWS and Azure-style lab environments. Participants inspect IAM permissions, network rules, policy results and audit events, then compare their evidence against CIS benchmark expectations. Case studies require teams to decide whether findings represent misconfiguration, accepted risk or active compromise, and to justify their priority. Daily exercises build toward an end-of-course assessment workshop, where each participant creates a control matrix, findings register and practical remediation plan for a defined cloud scenario.

Course outline

Day 1: Cloud security control foundations

  • Cloud service models and security ownership boundaries
  • AWS and Azure shared-responsibility comparison
  • Cloud asset inventory and control-scoping method
  • Control objectives for identity, network, data and logging
  • CIS AWS Foundations Benchmark structure
  • Cloud attack paths from exposed configuration to compromise
  • Risk-based finding classification and evidence standards

Workshop: Participants scope a cloud control review for a fictional business service and produce an initial asset, ownership and evidence checklist.

Day 2: Identity and privileged access controls

  • AWS IAM users, roles, policies and permission boundaries
  • Azure RBAC roles, scopes and managed identities
  • Least-privilege review using effective-permission analysis
  • AWS IAM Access Analyzer external-access findings
  • Privileged access management and break-glass account controls
  • Multi-factor authentication and conditional access evidence
  • Service-account keys, secrets and credential lifecycle risks

Workshop: Participants investigate an excessive-permission scenario and produce a prioritised IAM remediation recommendation with supporting evidence.

Day 3: Network, data and workload protection

  • Security groups and network security groups rule analysis
  • Internet exposure testing for management ports and public endpoints
  • Network segmentation across virtual networks and subnets
  • Encryption at rest, in transit and key-management controls
  • Cloud storage access controls and public-access prevention
  • Workload protection for virtual machines, containers and serverless services
  • Vulnerability and image-risk findings in Microsoft Defender for Cloud

Workshop: Teams assess a deliberately misconfigured application environment and create a network and data protection findings register.

Day 4: Logging, detection and posture management

  • CloudTrail and Azure Activity Log event sources
  • Audit-log retention, integrity and centralisation controls
  • Identity-event investigation using cloud audit evidence
  • Microsoft Defender for Cloud secure score and recommendations
  • Azure Policy definitions, initiatives and compliance results
  • Continuous cloud posture management workflows
  • Alert triage from misconfiguration finding to incident decision

Workshop: Participants investigate a suspicious cloud administration sequence, correlate policy and audit evidence, and write an analyst escalation record.

Day 5: Assessment reporting and remediation planning

  • Cloud control testing procedures and evidence collection
  • Mapping findings to CIS benchmark recommendations
  • Exploitability, business criticality and compensating-control scoring
  • Writing technically actionable remediation statements
  • Assigning remediation owners and target completion dates
  • Exception handling and residual-risk documentation
  • Metrics for cloud control coverage and remediation ageing

Workshop: Participants complete and present a cloud security control assessment pack containing a control matrix, prioritised findings register and 90-day remediation plan.

Tools & standards covered

AWS IAM Access Analyzer, Microsoft Defender for Cloud, Azure Policy, CIS AWS Foundations Benchmark

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course assumes familiarity with core security concepts and basic cloud terminology, not hands-on cloud administration. Guided lab activities introduce the relevant IAM, policy, logging and posture-management features in context.

For live online delivery, participants need a laptop with a current browser and reliable internet connection. Training lab access and case materials are provided; participants do not need to use their employer's cloud tenant or enter production credentials.

Yes. It is designed around analyst tasks: assessing evidence, investigating alerts, identifying attack paths and escalating remediation. It does not teach cloud platform deployment or infrastructure-as-code engineering in depth.

Architecture and administration courses focus on building and operating cloud services. This course focuses on independently testing whether security controls work, interpreting findings and producing defensible risk and remediation evidence.

Participants can adapt the control matrix, evidence checklist and findings register to their own AWS or Azure review cycles. The methods support configuration reviews, audit preparation, alert triage and remediation tracking with cloud operations teams.

You leave with a completed cloud security control assessment pack based on the course scenario. It includes scoped controls, evidence requirements, prioritised findings, assigned remediation actions and a 90-day plan.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cloud Computing

5 Days Certificate

Cloud Governance Skills for IT Managers Training Course

IT managers are expected to enable teams to use cloud services quickly while retaining control of spend, security, data handling and operati…

10 Days Certificate

Cloud Data Platform Engineering for Data Engineers Training Course

Data engineers are increasingly expected to build more than individual pipelines: they must create reliable cloud data platforms that ingest…

5 Days Certificate

Cloud Networking Fundamentals for Infrastructure Teams Training Course

Infrastructure teams increasingly support applications spread across cloud accounts, regions, managed services and on-premises environments.…

5 Days Certificate

Cloud Computing for Healthcare IT Teams Training Course

Healthcare IT teams are under pressure to modernise clinical, administrative and data platforms without exposing protected health informatio…