NIST Cybersecurity Framework for Cloud Security Training Course

5 days Cloud Computing Certificate on completion
Course codeSD-CC-024
Duration5 days
LevelIntermediate to Advanced
CategoryCloud Computing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Cloud programmes often accumulate controls without a clear way to demonstrate that identity, data protection, monitoring, recovery, and supplier responsibilities work together. Security architects and cloud leaders must translate NIST Cybersecurity Framework (CSF) outcomes into cloud-specific decisions across shared-responsibility boundaries, multiple accounts or subscriptions, managed services, and regulated data. This course provides a repeatable method for assessing cloud security posture, prioritising gaps, and presenting an improvement roadmap that technical teams and risk stakeholders can act on.

Participants apply NIST CSF 2.0 Govern, Identify, Protect, Detect, Respond, and Recover functions to AWS, Microsoft Azure, and cloud-agnostic architectures. They map cloud assets and business services, define current and target profiles, connect CSF outcomes to NIST SP 800-53 Rev. 5 controls, assess identity and logging configurations, and build meaningful cloud security metrics. The course also addresses third-party cloud services, incident responsibilities, resilience testing, risk treatment, and evidence required for governance and assurance.

Instructor-led briefings are combined with architecture reviews, scenario-based risk workshops, control-mapping exercises, and guided use of cloud security posture findings. Working in teams, participants analyse a representative cloud environment and develop a CSF-aligned cloud security improvement plan. Each participant leaves with a completed cloud CSF profile, prioritised gap register, control-to-evidence matrix, and 90-day implementation roadmap, alongside a certificate of completion. The course is suited to professionals who already work with cloud platforms or security governance and need to make NIST CSF operational rather than treat it as a policy reference.

Course objectives

By the end of this course, participants will be able to:

  • Map cloud business services, assets, data flows, and shared-responsibility boundaries to NIST CSF 2.0 outcomes
  • Create current-state and target-state NIST CSF cloud security profiles for a defined workload portfolio
  • Translate NIST CSF outcomes into applicable NIST SP 800-53 Rev. 5 control families and implementation evidence
  • Assess cloud identity, network, encryption, logging, and backup configurations against a risk-based control baseline
  • Build a prioritised cloud security gap register using risk scenarios, control maturity, ownership, and remediation effort
  • Define detection, incident response, and recovery playbooks that assign responsibilities between customer and cloud provider
  • Design cloud security metrics and executive reporting measures linked to CSF outcomes and risk treatment decisions
  • Produce a 90-day NIST CSF-aligned cloud security improvement roadmap with accountable owners and measurable milestones

Benefits of attending

For you

  • Gain a practical method for leading NIST CSF cloud assessments instead of relying on generic control checklists
  • Build credible evidence for cloud security architecture, governance, or GRC leadership responsibilities
  • Learn to explain cloud shared-responsibility risks clearly to engineering teams, executives, auditors, and suppliers
  • Create reusable CSF profiles, gap registers, and control-evidence matrices for future cloud reviews
  • Strengthen eligibility for cloud security architect, security governance, and cyber risk management roles

For your organisation

  • Establish a common NIST CSF vocabulary for cloud engineering, security operations, risk, and audit teams
  • Prioritise cloud security remediation using business impact, control gaps, ownership, and implementation effort
  • Reduce overlooked shared-responsibility exposures across SaaS, PaaS, IaaS, and managed cloud services
  • Improve audit and customer-assurance readiness through traceable mappings from CSF outcomes to control evidence
  • Produce an actionable 90-day roadmap that directs cloud security investment toward measurable risk reduction

Target competencies

CSF profile designCloud risk assessmentControl evidence mappingShared-responsibility analysisSecurity metrics designRemediation roadmap planning

Who should attend

  • Cloud Security Architects — who must turn security principles into consistent controls across cloud workloads
  • Cybersecurity Managers — who need a defensible framework for prioritising cloud security investment and reporting risk
  • Cloud Platform Engineers — who implement identity, logging, network, and policy guardrails across accounts or subscriptions
  • GRC and Risk Managers — who map cloud control evidence to enterprise risk, assurance, and regulatory requirements
  • Security Operations Leads — who need cloud-native detection, response, and recovery responsibilities defined clearly
  • Internal Auditors — who assess whether cloud controls and provider responsibilities meet NIST CSF expectations

Requirements and prerequisites

Participants should have practical familiarity with cloud computing concepts, including IaaS, PaaS, SaaS, virtual networks, identity and access management, encryption, logging, backups, and the cloud shared-responsibility model. Experience reviewing cloud architecture diagrams, security policies, risk registers, or audit evidence is expected. Familiarity with either AWS or Microsoft Azure is useful, but deep administrator-level platform skills are not required. Participants should understand basic cybersecurity risk concepts such as threats, vulnerabilities, controls, and residual risk. No coding, penetration-testing experience, formal NIST certification, or prior use of AWS Security Hub or Microsoft Defender for Cloud is required.

Training methodology

The course uses instructor-led analysis of NIST CSF 2.0 alongside cloud architecture scenarios and structured working sessions. Participants map a representative multi-cloud workload, examine configuration and posture-management findings, and debate control ownership across customer and provider teams. Small groups build CSF profiles, assess risk scenarios, and convert technical observations into evidence, metrics, and remediation priorities. The final day is an application-planning workshop in which each participant adapts the course templates to a real or representative organisational cloud environment.

Course outline

Day 1: NIST CSF 2.0 and cloud governance foundations

  • NIST CSF 2.0 functions, categories, and outcomes
  • Govern function and cloud security accountability
  • Cloud shared-responsibility models for IaaS, PaaS, and SaaS
  • Cloud service inventory and business-service mapping
  • Data classification and cloud data-flow analysis
  • Risk appetite, tolerance, and cloud risk scenarios
  • Current-state and target-state CSF profile structure

Workshop: Participants create an initial CSF scope statement and current-state profile for a representative cloud-hosted business service.

Day 2: Protecting cloud identities, data, and workloads

  • Identity governance, least privilege, and privileged access management
  • Multi-factor authentication and conditional access controls
  • Cloud network segmentation and security group design
  • Encryption key management and secrets management
  • Secure configuration baselines and policy-as-code guardrails
  • Workload protection for virtual machines, containers, and serverless services
  • NIST SP 800-53 Rev. 5 control mapping for protective safeguards

Workshop: Participants map identity, data, network, and workload safeguards to CSF Protect outcomes and identify missing implementation evidence.

Day 3: Cloud detection, monitoring, and risk assessment

  • Cloud logging architecture and log-retention requirements
  • Security information and event management integration patterns
  • AWS Security Hub findings and security standards
  • Microsoft Defender for Cloud recommendations and secure score
  • Cloud security posture management operating models
  • Threat modelling for exposed cloud services and identity compromise
  • Risk scoring, gap-register design, and remediation prioritisation

Workshop: Participants analyse cloud posture findings and produce a prioritised gap register with risk ratings, owners, and proposed treatments.

Day 4: Responding to and recovering from cloud incidents

  • NIST CSF Respond and Recover outcomes in cloud operations
  • Cloud incident classification and escalation criteria
  • Customer and provider incident-response responsibilities
  • Cloud forensic evidence collection and chain-of-custody considerations
  • Containment actions for compromised identities and workloads
  • Backup, restore, resilience, and disaster-recovery testing
  • Post-incident review and CSF profile improvement

Workshop: Teams run a cloud account-compromise tabletop exercise and produce an incident responsibility matrix, containment plan, and recovery actions.

Day 5: Assurance, measurement, and implementation roadmap

  • Cloud supplier due diligence and contractual security requirements
  • Control evidence collection for audit and customer assurance
  • CSF outcome mapping to NIST SP 800-53 Rev. 5 controls
  • Cloud security key risk indicators and key performance indicators
  • Executive reporting using risk, maturity, and remediation measures
  • Target-profile gap analysis and investment sequencing
  • Ninety-day cloud security roadmap development

Workshop: Participants present a CSF-aligned cloud security improvement roadmap containing target outcomes, evidence needs, accountable owners, milestones, and metrics.

Tools & standards covered

NIST Cybersecurity Framework 2.0, NIST SP 800-53 Rev. 5, AWS Security Hub, Microsoft Defender for Cloud

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior formal NIST CSF training is required, but participants should already understand basic cybersecurity risk and cloud concepts. The course introduces the structure and application of NIST CSF 2.0 before moving into profile development, control mapping, and roadmap planning.

No production cloud access is required. Exercises use instructor-provided architecture scenarios, sample configuration evidence, and representative findings from AWS Security Hub and Microsoft Defender for Cloud.

Yes. The core method is cloud-agnostic and uses NIST CSF 2.0 to organise governance and control decisions across providers. AWS and Azure examples show how platform-specific findings can support the same CSF outcomes.

This course focuses on the management method that connects cloud controls to risk, accountability, evidence, and improvement priorities. It does not train participants to administer every cloud service or configure individual platform features in depth.

You can use the CSF profile, gap register, control-evidence matrix, and roadmap templates to assess a cloud application, business unit, or platform programme. The approach supports security reviews, audit preparation, cloud migration governance, and remediation planning.

Participants leave with a completed example cloud CSF profile, a prioritised gap register, an incident responsibility matrix, and a 90-day improvement roadmap. These deliverables can be adapted to an organisational cloud environment after the course.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cloud Computing

5 Days Certificate

AWS Cloud Infrastructure Management Training Course

AWS infrastructure teams must provision secure, reliable environments while controlling spend, responding to incidents and meeting internal …

5 Days Certificate

Cloud Architecture for Solutions Architects Training Course

Solutions architects must turn ambiguous business requirements into cloud designs that are secure, resilient, cost-aware and deliverable by …

5 Days Certificate

Pulumi Cloud Infrastructure Automation Training Course

Cloud teams often inherit manually created environments, inconsistent naming, undocumented access settings and deployment scripts that canno…

5 Days Certificate

Datadog Cloud Monitoring and Observability Training Course

Cloud teams often have metrics in one dashboard, logs in another, incomplete service ownership, and alerts that fire without identifying the…