Using SABSA to Architect Cloud Security
1h 11mIntermediate2021-04-01
Authors

Malcolm Shore
Cybersecurity Expert, Former Director of GCSB
Course details
The security required for cloud deployments is quite different from the security applied to on-site infrastructure. In order to ensure the most effective cloud security, cloud deployments should be properly architected. In this course, instructor Malcolm Shore shows how to do this using the SABSA enterprise security architecture. Malcolm goes over strategy, planning, and the ongoing architectural management processes needed to maintain the architecture and keep it relevant. He walks you through establishing a conceptual architecture, threat modeling, and risk management, then explains how the elements of the contextual and conceptual layers work together to provide a conceptual architecture suitable for the cloud. Malcolm covers how to create the logical architecture and align security services with attributes. He concludes with a description of cloud-delivered security services and a review of what you covered in the course.
Skills covered
SABSACloud SecurityNetwork SecurityCybersecurityCloud ComputingOne-Off
Concepts
0. Introduction
- 01 - Architecting business requirements to deliver a secure cloud deployment
- 02 - What you should know
1. Introducing Security Architecture
- 03 - Why business has moved to the cloud
- 04 - Security architectures for the cloud
- 05 - SABSA strategy and planning
- 06 - SABSA attributes
- 07 - The lower layers of design
- 08 - The service management matrix
2. SABSA Conceptual Analysis
- 09 - Establishing a conceptual architecture
- 10 - Threat modeling for cloud
- 11 - Risk management with SABSA
- 12 - Using attributes to collect lower layer risks
- 13 - Thinking clouds with SABSA
- 14 - Tiers of the CAT
- 15 - A cloud-enhanced conceptual architecture
3. SABSA Design for the Cloud
- 16 - Creating the logical architecture
- 17 - Aligning security services with attributes
- 18 - Cloud delivered security services
- 19 - The SABSA journey to the cloud
Conclusion
- 20 - What's next