Chat with us, powered by LiveChat

Cloud Security

This subject is available under ICMS undergraduate degrees, please click the button below to find an undergraduate course for you.

Subject Code:

CYB203A

Subject Type:

Specialisation 

Credit Points:

3 credit points 

Pre-requisite/Co-requisite: 

CYB101A Cyber Security Essentials 

ICT102A Network Fundamentals 

Course level of study pre-requisite: a total of 12 credit points including ICT101A, ICT102A, ICT103A and DAT101A from level 100 core subjects prior to enrolling into level 200 core and specialisation subjects

Subject Level:

200

Subject Rationale:

Organisations are migrating their valuable data and mission-critical services to the cloud due to the strategic and operational benefits it offers, such as flexibility, accessibility, efficiency, scalability, and maintainability. Considering their low cost, high performance, all-inclusive, and on-demand nature, cloud platforms are widely adopted by businesses globally in various settings. 

The popularity and the widespread use of cloud solutions amongst organisations have significantly increased cloud attacks by cybercriminals, causing considerable losses to businesses and disruption to cloud service providers. Therefore, building an adequate cloud security posture is essential for organisations to safeguard their valuable assets and optimise their cyber resilience.  

This subject introduces students to cloud computing fundamentals from a cybersecurity perspective, examining the associated systems, models, and technologies. Students will explore cloud architectures, services, and applications, concentrating on their security essentials to safeguard organisational data confidentiality, integrity, and availability. 

Using industry tools, techniques, and best practices, students will apply contemporary security mechanisms to safeguard a cloud environment. Through hands-on activities, they will gain the practical skills necessary to mitigate risks and threats inherent in a cloud ecosystem. Students will also examine the need for risk management, business continuity, and disaster recovery in cloud operations to control service disruption. 

Learning Outcomes:

a)  Describe cloud security technologies and paradigms, including associated architectures, models, services, and applications.

b)  Evaluate cloud infrastructures and inherent components and classify security risks, threats, and vulnerabilities for mitigation.

c)  Apply security techniques and mechanisms in a cloud environment in line with secure cloud infrastructure characteristics to mitigate cyber security risks and threats.

d)  Examine a cloud environment or application and identify appropriate risk management strategies to enhance business continuity and disaster recovery.

e)  Explore real-world cloud computing and their impact on data confidentiality, integrity, and availability.

Student Assessment:

Broad Topics to be Covered:

Topic: 
Week 1: Fundamentals and Applications of Cloud Computing  

  • Introduction to cloud computing and its role in solving business problems 
  • Virtualisation, cloud, and computing models  
  • Cloud computing architectures 
  • Confidentiality, integrity, availability (CIA) and cloud 
  • Privacy in cloud 
  • Cloud computing governance: policy and regulations 
Week 2: Cloud Infrastructure and Virtualisation in Cloud Computing 

  • IAAS 
  • Cloud asset management (network, storage, servers and data) 
  • Network, storage, and server virtualisation 
  • Protecting the Hypervisor and virtual machine 
Week 3: Cloud Models, Workloads, Management, and Monitoring 

  • Cloud models 
  • Private, public, and hybrid cloud features 
  • Cloud workload theory and categories 
  • Fundamentals of cloud setup and management 
  • Cloud monitoring tools and techniques 
Week 4: Cloud Computing and Information Security 

  • Cloud computing security architecture  
  • Trusted cloud 
  • Identity management, account lifecycle and single sign on 
  • Access control 

Privacy in the cloud 

Week 5: Cloud Infrastructure Security and API Security 

  • Protecting the cloud 
  • Physical security of the cloud 
  • Content protection in the cloud 
  • APIs from different cloud providers 
  • API security challenges 
Week 6: Cloud Vendors and Solutions in Infrastructure Services 

  • AWS, Microsoft Azure, Google Cloud Platform 
  • RackSpace and its security solutions 
  • Service Level Agreements in Public and Private Cloud (IaaS, PaaS) 
Week 7: Cloud Vendors and Solutions in Application services 

  • Office 365 Security 
  • Zimbara and its security solutions for cloud- A case study 
  • Zoho and its security solutions – A case study 
  • Service Level Agreements (SLAs) in SaaS 
  • Infrastructure lifecycle management in the cloud 
Week 8: Cloud Threat Management 

  • A cloud security reference model 
  • Cloud security alliance 
  • Cloud morphing strategies 
  • Common threats and vulnerabilities 
  • Secure cloud software requirements 
Week 9: Cloud Monitoring, Auditing and Billing 

  • Cloud monitoring requirements 
  • Cloud logs and security monitoring 
  • Cloud monitoring solutions by vendors 
  • Auditing for virtualisation and network 
  • Cloud models and billing 
  • Cloud computing groups and consortiums 
Week 10: Risk Management and Compliance in Cloud 

  • Governance in the cloud 
  • Cloud computing risk issues (service providers’ risks) 
  • Global regulations and cloud 
  • Cloud life cycle management  
  • Adaption of standards in cloud computing with ISO and NIST 
Week 11: Disaster Recovery and Business Continuity in Cloud 

  • Disaster recovery and cloud computing 
  • Business continuity and cloud computing 
  • Backups, snapshots and restoration of cloud systems 
  • Changes and challenges in DR and BCP for cloud 

 

Please note that these topics are often refined and subject to change so for up to date weekly topics and suggested reading resources, please refer to the Moodle subject page.