This program prepares mid-to-senior security practitioners to design, implement, and operate secure cloud architectures across public, private, hybrid, and multi-cloud environments. The curriculum aligns to the six CCSP domains and emphasizes data security, identity, platform/infra controls, secure SDLC, security operations, and legal/risk/compliance in the cloud. Demand for cloud-security talent remains strong and is expected to grow through 2050. CCSP signals capability to design, implement, and govern secure cloud environments- skills employers increasingly require.
By the end of this course, learners will be able to:
Cloud Security Architects/Engineers, Security Analysts/Consultants, DevSecOps and Application Security leads, SOC/IR professionals with cloud responsibilities, IT Risk/Compliance/Audit professionals supporting cloud portfolios.
Module 1 — Cloud Concepts, Architecture & Design
- Â Cloud characteristics, roles, and reference architectures
- Â Service & deployment models; multi-cloud and portability
- Â Shared responsibility, design patterns, secure baselines
- Â Lab: Model a secure multi-tier cloud workload with high availability
Module 2 — Cloud Data Security
- Â Data lifecycle (create/store/use/share/archive/destroy)
- Â Discovery & classification; labeling and mapping
- Â Encryption, tokenization, IRM; keys, secrets, and certificates management
- Â Lab: Build a data classification policy and design a multi-region KMS/secret management plan
Module 3 — Cloud Platform & Infrastructure Security
- Â Compute, storage, networking; management plane hardening
- Â Network segmentation, traffic inspection, zero-trust patterns
- Â Vulnerability assessment and continuous hardening
- Â BC/DR strategies (RTO/RPO), resilience testing
- Â Lab: Design micro-segmented networks and validate control placement
Module 4 — Cloud Application Security
- Â Secure SDLC and DevSecOps in cloud; CI/CD guardrails
- Â Threat modeling (STRIDE/PASTA), SCA/DAST/IAST approaches
- Â API security, supply-chain risk, OSS validation
- Â Lab: Implement a “shift-left” threat model and an assurance checklist for a cloud-native app
Module 5 — Cloud Security Operations
- Â Build/operate control stacks; logging/telemetry, SIEM in cloud
- Â IAM ops (SSO, federation, MFA), secrets rotation
- Â Incident response runbooks; acquisition & preservation considerations
- Â Lab: Create a cloud IR playbook with event collection, triage, and escalation
Module 6 — Legal, Risk & Compliance
- Â Cross-jurisdictional privacy, contractual vs. regulated data
- Â eDiscovery, forensics requirements; audit methodologies in cloud
- Â Risk analysis, supplier assessments, SLAs, and right-to-audit
- Â Workshop: Draft a cloud-specific control & evidence catalog for an audit scenario
End-to-end design review, exam strategy, timed question set with debrief
Who is the ideal candidate for this course?
Mid- to senior-level security practitioners responsible for securing cloud data, applications, and platforms, plus auditors/risk professionals evaluating cloud controls.
What are the course prerequisites?
Hands-on familiarity with security, networking, and cloud services. Exposure to IAM, encryption, and virtualization helps.
Does this course align to the official CCSP domains and weights?
Yes. Content, labs, and drills map directly to the six domains and their published weightings.
Can I take the exam before I have all the required work experience?
Yes. You can pass the exam first and hold Associate of ISC2 status while you complete the required experience.
Does holding CISSP waive CCSP experience?
Yes. An active CISSP waives the entire CCSP experience requirement (endorsement still required).
Does CCSK help with CCSP experience?
Yes. CCSK waives one year toward the CCSP domain experience requirement.
How many CPEs and what fees are required to maintain CCSP?
90 CPEs every three years. Annual Maintenance Fee is required; ISC2 members pay a single AMF each year regardless of the number of ISC2 certifications they hold.
What is the exam retake policy?
If needed: wait 30 days after the first attempt, 60 days after the second, and 90 days for the third and subsequent attempts; up to 4 attempts within any 12-month period.
Will this course include practice questions and a mock exam?
Yes—each domain includes exam-style drills, and a proctored mock exam is delivered in the capstone. (Lecture, guided labs, case studies, exam drills, capstone + mock exam)
Is the training vendor-neutral or focused on a single cloud?
Vendor-neutral with multi-cloud examples (public, private, hybrid) and patterns that transfer across providers.
Do I need programming skills?
Not required. Familiarity with APIs, automation concepts, and secure SDLC is helpful.
What roles does CCSP support?
Cloud Security Architect/Engineer, AppSec lead, DevSecOps engineer, Security Analyst, IR/SOC with cloud scope, IT Risk/Compliance/Audit with cloud portfolios.
How does CCSP differ from CCSK?
CCSK validates foundational cloud-security knowledge; CCSP is a deeper, experience-based certification covering architecture, operations, and governance at senior practitioner level.
If I already hold CISSP, is this course still useful?
Yes. CCSP dives deeper into cloud-specific architecture, data protection, application assurance, and legal/compliance nuances across cloud models.
What are job roles am I qualified for?
Cloud Security Architect; Cloud Security Engineer; Cloud Security Consultant; Cloud SecOps
Engineer / Analyst; Cloud Incident Response Lead; Threat Detection / SIEM Engineer (Cloud);
IAM Engineer / IAM Architect; DevSecOps Engineer (Cloud); Application Security Engineer
(Cloud); Cloud Risk and Compliance Analyst / Auditor
Data Security Engineer (KMS / DLP); Cloud Network Security / Zero-Trust Engineer
Solutions Architect (Security, Pre-Sales); Cloud Forensics and eDiscovery Specialist Cloud Security Program Manager
How does Global IT support students after certification?
How can I contact Global IT for questions or support?
Phone: (866)-GO-GIT-GO OR Email: info@global-itech.com
Real testimonials from our Students!
In the beginning of this year I lost my job as a landscaping and gardening supply store operations manager when the store, Detroit Farm and Garden, went out of business. After reviewing the Web site and visiting a few of the institutions, I decided to enroll at Global Information Technology. I was impressed with this [...] Read more
Zackery Finn
I began taking the Windows 2000 MCSE track in June of 2001. I decided to check out GIT after hearing an ad on the radio, and after viewing the facilities I signed up immediately. I attended classes on Tuesdays and Thursdays until the class ended in February 2002. I chose the MCSE course because I [...] Read more
David Warner
I wanted to take an opportunity to provide an update on my career since deciding to take classes with Global Information Technology. As you know, after nearly 15 years with a major player in the field of IT solutions, I was laid off from my job in December of 2008. After taking stock of what [...] Read more
Robert Franklin
It gives me immense pleasure to recommend Global Technology Information (GIT) to any technical inclined person who is seeking to become a top-notch Information Technology Technician (ITT). GIT is a unique technology school that I had the pleasure of attending. It is true that it is dedicated to providing high quality and cost effective training [...] Read more
Eddie Henderson
I got an Associate degree In Electronics Engineering Technology in 1996. The results I got from getting that degree were good; however, I had been laid off several times within a time frame of 14 years. The last time I got laid off, I thought about my continued interest in computer technology and the lack [...] Read more
Mister Jackson