Cloud Services for Public Sector Digital Teams Training Course
| Course code | SD-CC-021 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cloud Computing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Public-sector digital teams must modernise citizen-facing services while protecting sensitive data, sustaining continuity, meeting procurement obligations and demonstrating that cloud decisions are defensible. The challenge is not simply selecting AWS, Azure or Google Cloud services: it is designing operating controls, identity models, cost accountability and supplier arrangements that stand up to scrutiny from security teams, auditors, service owners and procurement colleagues. This course helps experienced practitioners turn cloud adoption from a series of technical deployments into a governed service capability.
Participants examine how to assess workloads for cloud suitability, establish landing-zone controls, classify data, design identity and access patterns, and select resilient architectures for public services. They practise applying shared-responsibility models, NIST SP 800-53 control mappings, CIS Benchmarks, infrastructure as code and FinOps cost-management practices. The course also addresses multi-supplier governance, evidence for assurance reviews, incident responsibilities, exit planning and portability risks.
Teaching combines instructor-led architecture briefings with hands-on design workshops built around a realistic public-service platform. Working in teams, participants create policy-as-code controls, workload migration decisions, risk registers, service-level measures and cost-allocation rules. Each participant leaves with a completed Public Sector Cloud Adoption Blueprint: a reusable pack containing a target operating model, landing-zone checklist, workload assessment matrix, control-evidence plan and 90-day implementation roadmap.
The course is designed for technical and operational professionals who already contribute to cloud, security, digital service or supplier decisions and need to connect platform engineering choices with public-sector accountability.
Course objectives
By the end of this course, participants will be able to:
- Assess public-sector workloads using a structured cloud suitability and migration decision matrix
- Design a landing-zone control model covering accounts, subscriptions, networks, identity and logging
- Map cloud security controls to NIST SP 800-53 requirements and auditable evidence sources
- Configure policy-as-code guardrails using Azure Policy, Terraform and tagging standards
- Apply data classification, residency and retention requirements to cloud storage and analytics designs
- Create a FinOps cost-allocation model using tagging, budgets, unit costs and anomaly review routines
- Evaluate supplier responsibilities through shared-responsibility, service-level and exit-plan analysis
- Produce a Public Sector Cloud Adoption Blueprint with a prioritised 90-day implementation roadmap
Benefits of attending
For you
- Build credible cloud architecture recommendations that address public accountability as well as technical performance
- Gain practical experience converting security and governance requirements into deployable guardrails
- Improve confidence when challenging supplier assumptions about responsibility, resilience and exit options
- Create reusable templates for workload assessment, control evidence, tagging and cloud cost reviews
- Demonstrate readiness for senior cloud architecture, platform governance or digital service leadership responsibilities
For your organisation
- Establish more consistent landing-zone controls across programmes, departments and delivery suppliers
- Reduce avoidable security and audit risk through clearer ownership, evidence collection and policy enforcement
- Improve cloud investment decisions by linking workload value, migration effort, risk and ongoing consumption cost
- Strengthen procurement and supplier governance with explicit service measures, shared responsibilities and exit criteria
- Accelerate delivery of resilient digital services through repeatable architecture and operating-model patterns
Target competencies
Who should attend
- Cloud Architects — who must design governed platforms for sensitive and citizen-facing services
- Digital Service Managers — who need to balance delivery speed, resilience, accessibility and accountability
- IT Infrastructure Managers — who are moving estates from data centres into managed cloud environments
- Cyber Security Architects — who must translate control requirements into cloud-native guardrails and evidence
- Data and Information Governance Leads — who oversee classification, retention, residency and lawful handling of public data
- Commercial and Vendor Managers — who evaluate cloud supplier obligations, consumption models and exit arrangements
Requirements and prerequisites
Participants should have practical experience supporting, designing or governing IT services and understand core concepts including virtual networks, identity and access management, encryption, backups, service availability and basic risk assessment. Familiarity with at least one cloud platform, such as Azure, AWS or Google Cloud, is expected; participants should be able to recognise services such as virtual machines, object storage, managed databases and IAM roles. Basic spreadsheet use is helpful for cost exercises. Prior coding expertise, Terraform experience, formal security certification and deep hands-on administration are not required, although the course moves beyond introductory cloud terminology.
Training methodology
The instructor uses public-service scenarios, including a citizen portal handling sensitive records and a multi-agency data platform, to connect platform choices to governance decisions. Short technical briefings are followed by guided exercises in Terraform, Azure Policy and cloud control design. Teams review architecture diagrams, classify data, challenge supplier terms, calculate consumption costs and prepare assurance evidence. Daily debriefs compare decisions against operational, security and commercial constraints. On the final day, participants assemble and peer-review their own Public Sector Cloud Adoption Blueprint and implementation plan.
Course outline
Day 1: Public-sector cloud strategy and workload decisions
- Public-service outcomes, accountability and cloud operating principles
- Cloud service models and the shared-responsibility boundary
- Workload discovery using application dependency and data-flow mapping
- Cloud suitability assessment criteria for legacy and citizen-facing systems
- The six migration strategies: rehost, replatform, refactor, retire, retain and repurchase
- Public-sector data classification, sovereignty, residency and retention constraints
- Business-case assumptions for cloud value, risk and service continuity
Workshop: Teams assess a legacy case-management service and produce a workload decision matrix with migration recommendation, assumptions and escalation risks.
Day 2: Landing zones, identity and cloud-native guardrails
- Landing-zone architecture for accounts, subscriptions, management groups and environments
- Hub-and-spoke networking, private endpoints and segmentation patterns
- Identity federation, privileged access and least-privilege role design
- Centralised logging, monitoring and immutable audit-trail requirements
- Azure Policy initiatives and deny, audit and deployIfNotExists effects
- Terraform modules, state management and peer-reviewed infrastructure changes
- CIS Benchmarks as configuration baselines for cloud services
Workshop: Participants design a landing-zone control map and write a Terraform-backed guardrail specification for a new digital service environment.
Day 3: Security assurance, privacy and operational resilience
- NIST SP 800-53 control families and cloud control ownership mapping
- Security evidence collection from configuration, logs, tickets and access reviews
- Encryption key management, secrets handling and certificate lifecycle controls
- Data protection impact assessment inputs for cloud-hosted services
- Threat modelling with data-flow diagrams and abuse-case analysis
- Resilience patterns for availability zones, backups, recovery objectives and disaster recovery
- Cloud incident response roles, escalation paths and forensic log retention
Workshop: Teams develop a control-evidence matrix and resilience design for a sensitive citizen-records platform undergoing assurance review.
Day 4: Cloud economics, procurement and supplier governance
- FinOps operating model: inform, optimise and operate phases
- Resource tagging standards for service, owner, environment, programme and cost centre
- Budgets, forecasts, anomaly detection and unit-cost metrics
- Reserved capacity, savings plans and commitment-risk evaluation
- Cloud procurement evaluation criteria beyond headline unit pricing
- Service-level objectives, support models and supplier performance reporting
- Exit planning, portability, escrow considerations and concentration-risk management
Workshop: Participants build a tagging and cost-allocation model, then evaluate two supplier proposals against a cloud service scorecard and exit plan.
Day 5: Target operating model and adoption roadmap
- Cloud target operating model roles across platform, security, service and commercial teams
- Platform product management and internal developer platform service definitions
- Governance cadences for architecture review, risk acceptance and cost optimisation
- DevSecOps delivery controls: pull requests, automated tests and approval workflows
- Cloud service catalogue design and consumption onboarding pathways
- Migration wave planning, dependency sequencing and change-management checkpoints
- Measures for adoption progress, control compliance, resilience and service performance
Workshop: Each participant completes and peer-reviews a Public Sector Cloud Adoption Blueprint containing a target operating model, control plan and prioritised 90-day roadmap.
Tools & standards covered
Terraform, Azure Policy, NIST SP 800-53, CIS Benchmarks
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cloud Computing
Cloud Security Alliance CCM Controls Implementation Training Course
Cloud security programmes often contain sound policies but lack a consistent way to translate cloud risks, provider assurances and technical…
Datadog Cloud Monitoring and Observability Training Course
Cloud teams often have metrics in one dashboard, logs in another, incomplete service ownership, and alerts that fire without identifying the…
Advanced Cloud Architecture and Migration Training Course
Cloud migration programmes fail when application dependencies, data constraints, resilience requirements and operating costs are treated as …
Google Cloud Platform Administration for IT Teams Training Course
Google Cloud administrators must turn project requests into controlled, supportable environments without slowing delivery. That means design…