# Cloud Security Certificate Program (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/certificates/cloud-security-certificate-program-self-paced>

## Overview

This certificate pairs the two halves of federal cloud security. It opens with the fundamentals — cloud service and deployment models, what FedRAMP does within federal cloud governance, the shared responsibility model applied to real scenarios, and the essential identity, access and data-protection practices. It then moves into architecture and operations, separating the work of designing a secure cloud from the work of keeping it secure.

The second half is anchored to real incidents, working through the 2024 Snowflake tenant breach and the Storm-0558 signing-key compromise, which between them cover the two failure modes that matter most: credentials without strong authentication on a non-SSO path, and compromise of a trust anchor itself. It also carries the CNAPP vocabulary broken into its actual parts of CSPM, CWPP and CIEM, post-quantum cryptography migration for cloud key management, service mesh proxy architecture, CISA's SCuBA baselines, and FedRAMP's shift to the 20x authorization model. The path closes with a workshop in which learners take a fictional cloud architecture and produce a prioritized, defended hardening plan.

## What you'll learn

- Describe cloud service and deployment models and the core concepts behind federal cloud use; Explain what FedRAMP does within federal cloud governance
- Apply the shared responsibility model to real scenarios and to real control ownership; Identify trust boundaries and define a cloud security architecture around them
- Distinguish human identities from workload and service identities, and apply least privilege across both; Identify excessive permissions, stale identities and privilege escalation paths using entitlement management
- Design segmented cloud networks and apply Zero Trust principles; Protect data at rest, in transit and in processing, and manage the cryptographic key lifecycle
- Establish secure configuration baselines and detect drift from them; Harden compute, containers and serverless workloads, and protect images and registries
- Secure applications and APIs, including service-to-service trust and secrets handling; Build security logging and detection coverage across identity, network, workload and administrative activity
- Design for resilience and prepare for compromised identities, workloads and accounts
- Produce and defend a prioritized cloud-hardening plan

## Curriculum
1. **Cloud Security Fundamentals for Federal Employees (Self-Paced)**
2. **Cloud Security Architecture & Hardening: Build It Secure, Keep It Secure Course (Self-Paced)**

## Pricing

**Tuition:** $1299
