# Cloud Security Certificate Program

Canonical URL: <https://www.graduateschool.edu/certificates/cloud-security-certificate-program>

## Overview

This certificate joins the two halves of federal cloud security into one path. It begins with fundamentals — cloud service and deployment models, the role FedRAMP plays in federal cloud governance, the shared responsibility model worked against real scenarios, and the essential identity, access and data-protection practices — establishing the vocabulary and governance context first. It then turns to architecture and operations, treating the design of a secure cloud and the work of keeping it secure as two distinct jobs.

The second half teaches from real incidents rather than theory. The 2024 Snowflake tenant breach and the Storm-0558 signing-key compromise are worked through in detail, because between them they cover the two failure modes that matter most: credentials without strong authentication on a non-SSO path, and compromise of a trust anchor itself. The path also carries material most cloud training has not caught up to — CNAPP broken into its real parts of CSPM, CWPP and CIEM, post-quantum cryptography migration for cloud key management, service mesh proxy architecture, CISA's SCuBA baselines, and FedRAMP's move to the 20x authorization model. It ends with a workshop where participants take a fictional cloud architecture and build a prioritized hardening plan they then have to defend.

## What you'll learn

- Describe cloud service and deployment models and the core concepts behind federal cloud use; explain what FedRAMP does within federal cloud governance
- Apply the shared responsibility model to real scenarios and to real control ownership; identify trust boundaries and define a cloud security architecture around them
- Distinguish human identities from workload and service identities, and apply least privilege across both; identify excessive permissions, stale identities and privilege escalation paths using entitlement management
- Design segmented cloud networks and apply Zero Trust principles; protect data at rest, in transit and in processing, and manage the cryptographic key lifecycle
- Establish secure configuration baselines and detect drift from them; harden compute, containers and serverless workloads, and protect images and registries
- Secure applications and APIs, including service-to-service trust and secrets handling; build security logging and detection coverage across identity, network, workload and administrative activity
- Design for resilience and prepare for compromised identities, workloads and accounts
- Produce and defend a prioritized cloud-hardening plan

## Curriculum
1. **Cloud Security Fundamentals for Federal Employees**
2. **Cloud Security Architecture & Hardening: Build It Secure, Keep It Secure Course**

## Pricing

**Tuition:** $1299
