Group Purchasing
Group Purchasing
AI SKILLSUPDATED

SEC549: Cloud Security Architecture

SEC549Cloud Security, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Eric JohnsonDavid HazarGregory Leonard
Eric Johnson, David Hazar & Gregory Leonard
SEC549: Cloud Security Architecture
Course authored by:
Eric JohnsonDavid HazarGregory Leonard
Eric Johnson, David Hazar & Gregory Leonard
  • GIAC Cloud Security Architecture and Design (GCAD)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 15 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn to design enterprise-ready, scalable cloud solutions for your organization. Engage in threat modeling, secure architecture review, and hands-on labs covering identity, network, data, and AI service architecture.

Course Overview

SEC549 prepares students to design secure, scalable cloud infrastructure. Through a representative case study, students threat model, analyze, and address real-world challenges in identity, access management, organization policy, network security, data security, AI services, and log aggregation. Across five days, students complete 15 hands-on labs, 25 security architecture reviews, and 10 CloudWars challenge rounds, giving them repeated practice applying centralized security controls to support fast, secure cloud adoption. 

Design It Right from the Start

SEC549 teaches students how to design enterprise-scale cloud infrastructure solutions for their organization. As a practical and highly technical cloud architect course, it focuses on building secure-by-design environments that align with real-world needs. By learning the cloud providers' well-architected frameworks, security architects can design centralized security controls for their cloud estate while maximizing the speed of cloud adoption for the organization. Students will learn how threat models change in the cloud with new, vastly distributed perimeters and unfamiliar trust boundaries. With those challenges in mind, the focus shifts to designing strategies for centralizing and reinforcing workforce identity, conditional access, policy guardrails, workload identity, network security controls, data perimeters, AI service architecture, and cloud logging. This Cloud Security Architecture course emphasizes practical design techniques for multi-cloud environments and serves as excellent preparation for professionals seeking a GIAC Cloud Security Architecture (GCAD) certification.

SEC549 takes students through the cloud migration journey of a fictional enterprise and the challenges encountered along the way. As aspiring cloud security architects, students perform threat models against the company’s existing cloud infrastructure. Using those threats and countermeasures, students perform in-depth security architecture reviews to identify the pros and cons of the company’s new cloud design patterns.

Concluding each section, students are challenged to create their own architecture design plans supporting the enterprise’s acquisition of a young startup company. Each CloudWars scenario gives students insight into the startup’s existing cloud resources, interviews with key employees, and requirements for the migration. Students work in teams to build the migration plans, architecture diagrams, and documentation supporting the acquisition. Each team presents their cloud architecture plans in the final capstone exercise to determine which team wins the SEC549 challenge coin.

Author Statement

"Distributing our workloads and data to the public cloud increases our perimeter, which is often protected only by identity-based security controls. With the network perimeter being lifted, the margin for error is slim. Even with this grim reality, we can still be optimistic. Migrating to the cloud enables our most innovative technologies and presents an opportunity for the security sector to evolve and mature.

“If armed with the correct foundational design principles, we can build more security in the cloud, with greater availability and confidentiality than ever possible on premises. Transitioning to the new cloud-native, zero-trust world may be bumpy, but we are here to help guide you on your journey."

- Eric Johnson, David Hazar, Gregory Leonard

What You’ll Learn

  • Design secure, enterprise-ready cloud architectures that support business goals
  • Build a scalable identity foundation, centralizing workforce identity with conditional access policies and break glass access
  • Learn how the cloud enables zero-trust for workforce, customer, and workload identities with both identity-based and network-based security controls
  • Create micro-network segmentation using hub-and-spoke models and centralized inspection firewalls
  • Protect data stored in the cloud with strong network and identity perimeters
  • Learn to create architectures for cloud-hosted AI and agentic services, alongside centralized Key Management Service (KMS) and disaster recovery designs
  • Enable cloud incident response and telemetry using centralized intra-cloud and cross-cloud push and pull logging designs

Business Takeaways

  • Reduce cloud risks with strategic, phased adoption plans
  • Prevent identity sprawl and technical debt through centralization
  • Support growth with high-level guardrails and secure architecture
  • Avoid costly anti-patterns with thoughtful cloud design
  • Move toward zero-trust using proven access control patterns
  • Create effective conditional access and manage policy exceptions
  • Adopt AI and agentic services securely by extending identity and data perimeters to AI workloads

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC549: Cloud Security Architecture.

Section 1Cloud Account Management and Identity Foundations

Section 1 introduces core concepts like cloud threat modeling and secure design, then dives into cloud identity. Students build identity foundations, use AI assistants to analyze cloud infrastructure, enable federation from Entra ID to AWS and GCP, design resource hierarchies, set up policy guardrails, and manage cloud access.

Topics covered

  • Security Architecture in the Cloud
  • Cloud Identity Foundations
  • Federated Access / Single Sign On (SSO)
  • Creating Hierarchical Cloud Structures and Guardrails
  • Privileged Identity Management

Labs

  • Threat Modeling Cloud Services
  • Azure to AWS Single Sign-On
  • Azure Organization Policies
  • CloudWars: Cloud Account Management and Identity Foundations

Overview

Section 1 starts by defining concepts used throughout the course, such as threat modeling the cloud, what makes a secure design, and how security changes in the cloud. Students then learn about the cloud identity foundation required to start designing identity federation and provisioning from Microsoft Entra ID to both AWS and Google Cloud using Entra ID enterprise applications. With identity federation in place, students design a foundational cloud resource hierarchy for the organization to host resources with policy guardrails for organization units and accounts. The final module covers privileged identity management and break glass access for team members accessing the cloud’s management control plane.

Full Lab Details

  • Threat Modeling Cloud Services (AWS / Azure / Google)
  • Azure to AWS Single Sign-On (AWS / Azure)
  • Azure Organization Policies (Azure)
  • CloudWars: Account Management and Identity (Azure)

Full Topic Details

  • Security Architecture in the Cloud
    • Transitioning to the public cloud
    • Cloud-native security models
    • Cloud provider well-architected frameworks
  • Cloud Identity Foundations
    • Understanding how permissions are granted and patterns of IAM in the cloud
    • Cloud diagramming and threat modeling tools
    • Leveraging AI assistants for cloud infrastructure analysis
  • Federated Access / Single Sign-On
    • Managing users at scale with Microsoft Entra ID, AWS Single Sign-On, and Google Cloud Identity
    • Provisioning users with the System for Cross-domain Identity Management (SCIM) specification
  • Creating Hierarchical Cloud Structures
    • Designing organizational hierarchy with AWS Organizations, Azure Management Groups, and Google Cloud
    • Creating policy guardrails in the hierarchy to help silo job roles and prevent IAM mistakes
  • Privileged Identity Management
    • Designing access to the management control plane for standard, privileged, break glass, and administrators
    • Granting secure external access to vendors and contractors

Section 2Implementing an Identity Perimeter in the Cloud

Section 2 explores zero-trust in the cloud, focusing on conditional access policies, customer identity and access management (CIAM), and authenticating users and machines across clouds.

Topics covered

  • Implementing Zero-Trust Architecture
  • Conditional Access Policies
  • Customer Identity and Access Management (CIAM)
  • Architecting Cross-Cloud Authentication

Labs

  • Threat Modeling Zero-Trust Architecture
  • Microsoft Entra ID Conditional Access
  • CIAM – AWS Cognito User Pools
  • CIAM – AWS Cognito Identity Pools
  • CloudWars: Implementing an Identity Perimeter in the Cloud

Overview

Section 2 starts with an in-depth look at the zero-trust movement, its history, and how zero-trust in the cloud can be leveraged to modernize legacy access patterns. We not only discuss permission-granting architectures but also how to build identity guardrails into your cloud estates, ensuring conditional access policies define how and when resources can be accessed. Students will learn how to authenticate customers and machine identities across multiple public cloud environments. With this knowledge, students will see how to restrict access between an organization's resources and trusted third parties.

Full Lab Details

  • Threat Modeling Zero Trust Architecture (cloud agnostic)
  • Microsoft Entra ID Conditional Access (Azure)
  • CIAM – AWS Cognito User Pools (AWS)
  • CIAM – AWS Cognito Identity Pools (AWS)
  • CloudWars: Implementing an Identity Perimeter in the Cloud (Azure, Google)

Full Topic Details

  • Implementing Zero-Trust Architecture
    • History of Zero-Trust
    • Using cloud services to implement zero-trust architecture
  • Conditional Access Policies
    • Designing effective Conditional Access policies
    • Understanding Conditional Access using Google BeyondCorp, AWS Verified Access, AWS Service Control Policy (SCP), and Entra ID Conditional Access
  • Customer Identity and Access Management (CIAM)
    • Identity federation with Microsoft Entra External ID and AWS Cognito
  • Architecting Cross-Cloud Authentication
    • Cloud provider machine identities (AWS IAM Roles, Azure managed identities and Google Cloud service accounts)
    • Designing workload identity federation across cloud providers
    • Using certificates and AWS IAM Roles Anywhere to authenticate workloads to cloud machine identities
    • Using workload identity federation and OIDC to authentication workloads to cloud machine identities

Section 3Network Access Perimeters for the Cloud

Section 3 covers cloud network components and design, starting with key resources for public, private, and hybrid clouds. Students learn centralized management, micro-segmentation, traffic inspection, and how to access shared services.

Topics covered

  • On-Premises versus Cloud Networks
  • Managing Cloud-Hosted Networks at Scale
  • Cloud Network Micro-Segmentation
  • Network Firewalls and Traffic Inspection
  • Centralized Shared Network Services

Labs

  • VPC Peering Architecture
  • Hub and Spoke Architecture
  • Centralized Traffic Inspection
  • CloudWars: Network Access Perimeters for the Cloud

Overview

Section 3 shifts focus to designing network perimeters in the cloud. Starting with the key resources required to build public, private, and hybrid cloud networks, students learn to centrally manage the configuration of these resources across their organization. Next, we explore cloud micro-segmentation, hub and spoke networks, and routing traffic between micro-networks. From there, the architecture expands to include traffic inspection for ingress, egress, and east-west traffic using third-party security appliances. Finally, students learn how to share network services by adding additional spoke networks and sharing DNS configurations across the organization.

Full Lab Details

  • VPC Peering (Google)
  • Hub and Spoke Architecture (Azure)
  • Centralized Traffic Inspection (Azure)
  • CloudWars: Network Access Perimeters for the Cloud (AWS)

Full Topic Details

  • On-Premises versus Cloud Networks
    • Cloud architecture challenges
    • CISA Zero Trust Model: Network & Environment
  • Managing Cloud-Hosted Networks at Scale
    • Cloud network building blocks (virtual networks, subnets, internet gateways, firewall rules, network interfaces, and private service endpoints)
    • Hosting network resources centrally in a cloud organization
    • Sharing VPC networks across projects / accounts
    • Managing firewall rules using AWS Firewall Manager, Azure Firewall Manager, and Google Cloud Hierarchical Firewall Policies
  • Cloud Network Micro-Segmentation
    • Connecting micro networks using VPC peering and hub and spoke services
    • Creating hybrid networks with site-to-site VPN tunnels and dedicated connections
  • Network Firewalls and Traffic Inspection
    • Centralizing ingress and egress traffic network controls using AWS Transit Gateway and Azure Virtual WAN
    • Inspecting east-west traffic with third-party security appliances, Kubernetes network policy, and AWS VPC Lattice
    • Load balancing traffic and symmetric routing to third-party security appliances
  • Centralized Shared Network Services
    • Hosting private link / private access services in a centralized spoke
    • Designing least privilege private link policies for data perimeters
    • Sharing private DNS hosted zones with spoke networks

Section 4Data Access Perimeters in the Cloud

Section 4 covers cloud-native data protection: storage controls, data lake security, and sensitive information discovery using tags, attribute-based access control (ABAC), and masking. Students apply these controls to secure cloud-hosted AI services, designing perimeters around the models, grounding data, and agentic applications that reach sensitive data.

Topics covered

  • Data Security and Privacy Playbook
  • Data Lake and Cloud Storage Security
  • AI Service Architecture
  • Business Continuity and Disaster Recovery Design

Labs

  • Data Discovery and Classification
  • BigQuery Data Lake Security
  • AI Service Architecture
  • CloudWars: Data Access Perimeters in the Cloud

Overview

Section 4 focuses on cloud-native data protection patterns. Starting with common organization-wide storage service controls, students will establish foundational data perimeter policies. From there, we learn to segment data lake access through access points, row-level, and column-level security policy. Next, students explore how attribute-based access control, tagging, and data masking can enable cloud-native data loss prevention controls. Finally, the section wraps up with AI services, key management, and backup architecture patterns.

Full Lab Details

  • Data Discovery and Classification (cloud agnostic)
  • BigQuery Data Lake Security (Google)
  • AI Service Architecture (Google)
  • CloudWars: Data Access Perimeters in the Cloud (Azure, Google)

Full Topic Details

  • Data Security and Privacy Playbook
    • Defining, dissecting, and defending data
    • Data classification patterns
    • Resource naming and tagging
    • Cloud sensitive data discovery and protection services
  • Cloud Storage Service Security
    • Managing access to cloud storage services
    • Defining data retention and lifecycle policies
    • Enabling data access logs for monitoring and analysis
    • Hosting static web content behind cloud content delivery networks
  • Data Lake Security
    • Designing centralized data warehouses with data mart access points
    • Access control and governance with S3 access points
    • Access control and governance with BigQuery row-level and column-level security policies
    • Data pipelines for tagging for attribute-based access control, masking, and data loss prevention
    • Establishing network perimeters in the cloud for data access
  • Key Management Architecture
    • Creating centralized key management stores for the organization
    • Patterns for isolating key administrators from data being protected
    • Sharing keys across cloud accounts
    • Regulatory requirements that may require customer-managed or cloud hardware security module (HSM) managed keys
  • AI Services Architecture
    • Understanding AI vendor service trust boundaries and inference paths
    • Review cloud managed AI services and capabilities
    • Designing an internal agentic application architecture and inference path
    • Managing AI agent identities and secrets
    • Establishing AI agent micro-segmentation and data perimeters
    • Granting AI agent identities access to storage and data lake sources
  • Disaster Recovery
    • Advantages and disadvantages of disaster recovery (DR) in the cloud
    • Cloud DR design for Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)
    • Storage service ransomware prevention, replication, and immutable policy
    • Cross-cloud disaster recovery strategies

Section 5Enable the Cloud-Focused SOC

Section 5 teaches students how to enable SOC operations in the cloud, covering cloud data sources, log aggregation, and exporting to a central SIEM. Students design logging architectures that support threat detection, response, and recovery from cloud incidents.

Topics covered

  • Security Operations in a Cloud-Centric World
  • Intra-cloud Logging and Aggregation
  • Centralized Log Export Patterns

Labs

  • Intra-Cloud Logging Architecture
  • Cross-Cloud Logging Architecture
  • CloudWars: Enabling the Cloud-Focused SOC

Overview

This section covers how to enable your SOC to operate, investigating incidents, logging events, and hunting for threats in the new cloud-based world. Covered in this section is a deep dive on cloud data sources, aggregating logs and cloud-native events within the CSP while positioning them for export to the central SIEM. This section teaches students how to build effective architecture that empowers defenders to respond, contain, and ultimately recover from cloud-based incidents.

Full Lab Details

  • Intra-Cloud Logging Architecture (AWS, Azure, Google)
  • Cross-Cloud Logging Architecture (AWS, Azure, Google)
  • CloudWars: Enabling the Cloud-Focused SOC (Azure)

Full Topic Details

  • Security Operations in a Cloud-Centric World
    • On-premises versus cloud security operations
    • Cloud service provider incident coordination
    • Managing security contacts in AWS, Azure, and Google cloud
  • Intra-cloud Logging and Aggregation
    • Understanding the logging journey for events in the cloud
    • Cloud event log types and data elements
    • Designing an intra-cloud security data lake for in-depth analysis
  • Centralized Log Export Patterns
    • Comparing SIEM solutions and platforms
    • Ingesting cloud events using push and pull architecture patterns
    • Exporting AWS log events using Kinesis, S3, and SQS
    • Exporting Azure log events using Event Hub
    • Exporting Google Cloud log events using Pub/Sub
    • Data processing and transformation using Cribl
    • Ingesting cross-cloud log event data using Microsoft Sentinel
  • CloudWars
  • Course Wrap-Up

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.

SANS will be providing access to the following cloud environments: AWS, Azure, and Google Cloud. Unfortunately, due to some cloud security controls we cannot control, sometimes the login you receive requires two-step verification with an authenticator app or a valid phone number where you can receive text messages (virtual numbers will not work). Please ensure you have and are willing to install an authenticator app (e.g., Microsoft Authenticator) and provide your phone number to the cloud provider should this situation occur.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Our class uses a browser-hosted electronic workbook for delivering the lab instructions. A second monitor and/or a tablet device can be useful for keeping instructions materials visible while you are working in the cloud web consoles and draw.io diagrams.

If you have additional questions about the laptop specifications, please contact customer service.

SEC549 training is recommended for a diverse range of individuals, including:

  • Solutions Architects
  • Security Auditors
  • Cloud Architects
  • Security Engineers
  • Security Architect
  • Cloud Engineers
  • DevOps Engineers
  • System Administrators
  • Operations
  • Anyone responsible for:
    • Enabling business through secure cloud architecture
    • Evaluating and adopting new cloud offerings
    • Planning for cloud migrations
    • Implementing or managing cloud identity and access management
    • Managing a cloud-based virtual network

The GIAC Cloud Security Architecture and Design (GCAD) certification validates a practitioner’s understanding of cloud provider frameworks and design approaches for secure architecture in the cloud. GCAD certification holders have demonstrated knowledge of the strategies and design techniques for topics such as workforce identity, conditional access, network security controls, and centralized logging.

  • Identity and access management
  • Design and implement Zero-Trust concepts
  • Network architecture and design
  • Data protection
  • Configuring centralized monitoring

More Certification Details

  • Printed and electronic courseware
  • Draw.io architectural diagrams representing secure patterns you can use as reference architecture
  • Access to the SEC549 Cloud lab environment and sandbox cloud accounts

The following experience is a prerequisite for SEC549:

  • Familiarity with AWS, Azure, and Google Management Consoles and common services in these cloud providers
  • Experience or willingness to learn how to use cloud architecture diagram tools such as draw.io
  • Ability or willingness to learn to run basic Linux commands for SSH connections, testing network connectivity, and looking up domain names
  • Familiarity with or willingness to learn identity federation technologies such as SAML, Open ID Connect (OIDC), and JSON Web Tokens (JWT)

Preparing For SEC549

Students taking SEC549 will have the opportunity to learn many different architecture patterns across the AWS, Azure, and Google clouds. Basic familiarity with cloud concepts like IAM, role-based access control, identity federation, VPC networks, and storage services management is helpful.

Additionally, students will delve into cloud-native tools for securing deployments at the network layer. Having a basic understanding of network concepts such as firewalls, network access control lists and IP addressing is also very helpful.

The SEC549 course is part of the Cloud Security focus area and Cloud Security Architect Journey. The development path aims to equip security professionals with a comprehensive understanding of how to build secure cloud environments, from designing cohesive architecture and securing multicloud environments to aligning cloud design with larger business strategies.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Cloud security architecture is the practice of designing secure systems in cloud environments that align with business goals. It involves understanding both the organization's needs and the capabilities of cloud services to create secure access patterns, network controls, and processes.

Architects must design solutions that work across Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS). Hybrid environments—where cloud and on-premises systems connect—add another layer of complexity.

The goal is to spot design flaws and inefficiencies early, before systems go live, and address them with cloud-native security controls.

SEC549 dives deep into these challenges, equipping students with the skills to build secure, scalable cloud architectures across service models.

The SEC549: Cloud Security Architecture course provides in-depth knowledge and relevant experience in designing secure cloud infrastructures. As cloud adoption continues to rise, organizations need skilled professionals who can build secure, scalable, and compliant cloud architectures. By taking this course, you willl gain expertise in cloud-native security controls, identity management, and threat mitigation strategies—skills that are increasingly in demand in the cybersecurity field.

Key Career Benefits:

  • Gain practical experience with cloud security design, from IaaS to SaaS models
  • Learn to implement zero-trust principles and effective access management
  • Develop the ability to identify and mitigate cloud security risks early
  • Master cloud migration and hybrid architecture design
  • Increase your employability with expertise in securing multi-cloud environments
  • This course positions you as a cloud security expert, empowering you to lead the way in securing critical cloud infrastructures.

Relevant Job Roles

Cybersecurity Architect

European Cybersecurity Skills Framework

Plans and designs security-by-design solutions (infrastructures, systems, assets, software, hardware and services) and cybersecurity controls.

Explore learning path

Cybersecurity Architecture (OPM 652)

NICE: Design and Development

Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes.

Explore learning path

Cloud Security Manager

Cloud Security

Developing cloud security roadmaps, plans and procurement models to mature cloud security.

Explore learning path

Infrastructure Design (IFDN)

Skills Framework for the Information Age

Planning and design of secure, scalable, and resilient infrastructure across on-premise, cloud, and hybrid environments. Design outputs meet both current and future business needs.

Explore learning path

Cloud Security Architect Training, Salary, and Career Path

Cloud Security

Designs and secures the defensive architecture of secure cloud environments.

Explore learning path

Enterprise Architecture (OPM 651)

NICE: Design and Development

Responsible for developing and maintaining business, systems, and information processes to support enterprise mission needs. Develops technology rules and requirements that describe baseline and target architectures.

Explore learning path

Cybersecurity Architecture

SCyWF: Cybersecurity Architecture, Research And Development

This role conducts cybersecurity design, architecture, research and development activities. Find the SANS courses that map to the Cybersecurity Architecture SCyWF Work Role.

Explore learning path

Solution Architecture (ARCH)

Skills Framework for the Information Age

Definition of technology solutions that meet functional and non-functional requirements while aligning with strategic goals. Designs integrate security, scalability, and cost-effectiveness.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 13

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources