Course : Cloud Computing Security

Seminar - 2d - 14h00 - Ref. OUD
Price : 1720 € E.T.

Cloud Computing Security






INTER
IN-HOUSE
CUSTOM

Seminar in person or remote class
Disponible en anglais, à la demande

Ref. OUD
  2d - 14h00
1720 € E.T.







Course schedule

1
Introduction to Cloud Computing security

  • Definition of Cloud Computing (NIST, Burton Group).
  • Major providers and main faults already observed.
  • SecaaS (Security as a Service).
  • The keys to a secure architecture in the Cloud.

2
Virtual environment security

  • How virtualization helps security.
  • Specific threats and vulnerabilities.
  • Three security integration models: Virtual DataCenter, Hardware Appliance and Virtual Appliance.
  • Virtualization-specific security solutions.

3
Secure network access to the Cloud

  • Vulnerabilities and issues in access security.
  • Native security in IP v4, IPsec and IP v6.
  • Protocols: PPTP, L2TP, IPsec and VPN SSL.
  • Access to Cloud via the secure Web (https).
  • Vulnerabilities of Cloud clients (PC, tablets, smartphones) and browsers.

4
Work of the Cloud Security Alliance (CSA)

  • Security Guidance for Critical Areas of Focus in Cloud Computing.
  • The thirteen areas of security. The seven main threats.
  • The GRC integrated suite.
  • CloudAudit, Cloud Controls Matrix, Consensus Assessments Initiative Questionnaire, Cloud Trust Protocol.
  • CCSK certification (Certificate of Cloud Security Knowledge).

5
Cloud Computing security according to ENISA

  • Cloud risk assessment and management using the ISO 27005 standard.
  • The thirty-five risks identified by ENISA. ENISA recommendations for government Cloud security.

6
NIST recommendations for security

  • Guidelines for security and confidentiality in public cloud computing.
  • Analysis of the NIST 800-144 and NIST 800-146 standards.

7
Testing Cloud security

  • What security label for suppliers: Cobit, ISO2700x, or ISO 15401 common criteria?
  • How do you audit security in the Cloud?
  • Cloud-oriented security testing tools (Metasploit & VASTO, openVAS, xStorm, etc.).

8
Legal aspects

  • Private cloud to public cloud: Legal consequences. Responsibilities of various players.
  • Regulatory compliance (PCI-DSS, CNIL, SOX...).
  • Precautions for writing a contract.


Customer reviews
4,4 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
ENZO C.
16/06/26
5 / 5

I found the course content to be very clear and well-structured. The trainer was thorough and always made sure we had fully understood his explanations. He explained things clearly and adjusted the pace so that everyone could keep up.
LY-TIGN H.
16/06/26
3 / 5

A lot of the slides were skimmed over. The answers to the questions were a bit vague. The case studies were good.
ODON R.
07/10/25
5 / 5

Complete, understandable, sufficient.



Publication date : 03/01/2024



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 29 Sep., 29 Sep., 24 Nov., 24 Nov.

2027 : 24 June, 24 June, 14 Oct., 14 Oct., 9 Dec., 9 Dec.

PARIS LA DÉFENSE
2026 : 1 Oct., 18 Nov.

2027 : 24 June, 14 Oct., 9 Dec.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.