SCADEMY logo, back to home

Application Security in the Cloud

CL-CLS

Onsite / Virtual classroom

3 days

Ends with an exam

Audience: DevelopersManagersProfessionals

Preparedness: Cloud computing, software development

Exercises: Hands-on

Application Security in the Cloud
Application Security in the Cloud

Migrating to the cloud introduces immense benefits for companies and individuals in terms of efficiency and costs. With respect to security, the effects are quite diverse, but it is a common perception that using cloud services impacts security in a positive manner. Opinions, however, diverge many times even on defining who is responsible for ensuring the security of cloud resources.

Covering IaaS, PaaS and SaaS, first the security of the infrastructure is discussed: hardening and configuration issues as well as various solutions for authentication and authorization alongside identity management that should be at the core of all security architecture. This is followed by some basics regarding legal and contractual issues, namely how trust is established and governed in the cloud.

The journey through cloud security continues with understanding cloud-specific threats and the attackers’ goals and motivations as well as typical attack steps taken against cloud solutions. Special focus is also given to auditing the cloud and providing security evaluation of cloud solutions on all levels, including penetration testing and vulnerability analysis.

The focus of the course is on application security issues, dealing both with data security and the security of the applications themselves. From the standpoint of application security, cloud computing security is not substantially different than general software security, and therefore basically all OWASP-enlisted vulnerabilities are relevant in this domain as well. It is the set of threats and risks that makes the difference, and thus the training is concluded with the enumeration of various cloud-specific attack vectors connected to the weaknesses discussed beforehand.


Outline

IT security and secure coding

Cloud security basics

Threats and risks in the clouds

Cloud security solutions

Practical cryptography

Web application security

Denial of service

Input validation

Data security in the cloud

Security audit in the cloud

Dynamic security testing

Securing the cloud environment

Knowledge sources


Participants attending this course will

Understand basic concepts of security, IT security and secure coding

Understand major threats and risks in the cloud domain

Learn about elementary cloud security solutions

Understand security concepts of Web services

Learn about XML security

Have a practical understanding of cryptography

Learn Web vulnerabilities beyond OWASP Top Ten and know how to avoid them

Learn about denial of service attacks and protections

Learn typical input validation mistakes

Understand data security challenges in the cloud

Learn about NoSQL security

Learn about MongoDB security

Understand the challenges of auditing and evaluating cloud systems for security

Learn how to secure the cloud environment and infrastructure

Learn how to set up and operate the deployment environment securely

Get sources and further readings on secure coding practices




Our students say

0 of 0

Instructor-led courses
Instructor-led courses

Handle complex subjects, provide practical skills training, and hands-on experience, enable discussion and collaboration, and maintain the motivation and accountability of learners.

 Large-scale trainings
Large-scale trainings

Courses with couple of thousands of participants to be conducted in a short time frame, in any time zone, on-site or online.

Academic knowledge, practical application
Academic knowledge, practical application

Utilzing our R&D&I we combine academic knowledge with practical application, we develop and tailor courses to latest trends and clients' needs.

Proprietary platform with virtual machines
Proprietary platform with virtual machines

We use our proprietary platform with virtual machines for a safe practice, coding, and experimentation environment.

Hi SCADEMY Team,

My name isand my email is
I'd like to get more information aboutcourse for
The number of people would participate in the course
Man and woman
Find us here:

Budafoki street 187-189.
Budapest, 1117, Hungary

+36 1 205 3098

These courses could interest you, too:

Go to full course catalog

Trusted by top companies and brands:

EvosoftAirbusKnorr-BremseGE HealthCareEricssonSiemensNokiaBMW GroupLenovoConaxNAGRAAtosBeldenCode42VolvoElektrobitAXAKongsbergEvosoftAirbusKnorr-BremseGE HealthCareEricssonSiemensNokiaBMW GroupLenovoConaxNAGRAAtosBeldenCode42VolvoElektrobitAXAKongsberg