The idea of having an interconnected global network was first conceptualised by J.C.R Licklider in the 1960s.
In 1983, CompuServe offered consumer disk space for remote file uploads and downloads, becoming the first ever “cloud” storage in the world, before the term cloud was coined in 1996.
Fast forward 10 years, Amazon Web Services(AWS) launched an Elastic Compute Cloud which was the first modern commercial public cloud infrastructure.
Today, the cloud is a global safe, storing confidential files, sensitive data, intellectual property and customer records.
While the cloud offers immense scalability, cost efficiency and agility, its status as a safe increases the threat posed by malicious entities and attackers.
Securing the cloud landscape is a top priority for modern organisations and although technology plays a crucial role in protecting the cloud infrastructure, the human element is non negotiable for cloud security.
In order to build a resilient workforce against cloud data breaches, organisations must design a comprehensive cloud security training programme.
In order to build an effective training programme, organisations must have strategic approaches right from understanding the cloud security mindset to the core pillars of a security curriculum, effective delivery of training, certifications and keeping pace with innovation.
The Shared Responsibility Model and Zero Trust Architecture
The shared responsibility model defines the provider and the customer’s responsibility towards cloud security. It is very important to understand this model in order to be effectively trained in the field as this model is the foundation of all cloud security training.
Providers such as AWS and Azure have a rather definite structure that divides the responsibility.
The cloud provider is responsible for protecting the infrastructure such as the hardware, software and networking.
The customer is responsible for everything that they place in the cloud, such as applications, data and operating systems.
Cloud security training must clearly define the boundaries between the responsibilities of the provider and the customer in order to prevent critical data exposure.
A Zero Trust mindset is one which is guided by the principle, Never trust, always verify.
Training programmes must educate trainees in designing security systems with the assumption that an attacker is already present in the network.
Designing such a system requires continuous authentication, micro segmentation of resources and access control.
Developing a cloud security mindset is the most crucial step in an efficient training programme aimed at building a resilient workforce.
Pillars of a Cloud Security Curriculum
Identity and Access Management
This domain deals with permissions and access given to users.
Training programmes should emphasise on three main aspects:
Firstly, the Principle of Least Privilege, which ensures that users have minimal access, which is necessary for them to perform their roles.
Secondly, Multi-Factor Authentication, which should be enforced across all accounts.
Thirdly, Role Based Access Control, which can reduce credential exposure.
Data Security and Privacy
Cloud security training must educate trainees to understand data protection in all its stages, that is at rest and in transit, along with an understanding of storage misconfiguration.
Encryption at rest ensures that data stored in databases, block storage and object storage is secured using keys which can be managed by customers or providers.
Encryption in transit is all about implementing protocols such as HTTPS, which protect the data while moving across networks.
Trainees can also be taught how to prevent public access exposure on object storage containers.
Infrastructure and Network Security
This domain involves virtualised network controls.
It consists of Virtual Private Clouds, which are created by isolating environments into distinct networks.
Firewalls are configured to restrict inbound and outbound traffic and a secure connectivity is ensured to establish safe connections between data centres and the cloud using VPNs.
Logging, Monitoring and Incident Response
This is a domain for damage control. Specialised training in responding to cloud anomalies when a breach occurs is critical.
This domain involves actions such as centralised logging, which involves aggregation of logs from cloud trails and network flows.
It also consists of automated threat detection which uses cloud native tools to identify suspicious calls.
Cloud incident response playbooks can be used to simulate steps to revoke breached credentials.
An effective cloud security training programme should cover four core domains to ensure protection.
Use of AI to defend cloud infrastructure and securing AI workloads running in the cloud should be a part of cloud security training, especially with the advent of AI.
Effective Training Delivery
Practical application of theoretical knowledge of the cloud ensures a well-rounded cloud security training.
This can be done in two ways, tailored training and simulation.
Tailored training according to roles, such as DevSecOps, which trains developers and coders to focus on secure coding practices and infrastructure as code security. Operations based roles can be trained in patch management and network monitoring while executive roles can focus on compliance and risk management.
Simulation environments where trainees can practice configuring firewalls and hunting threats without risking live environments are highly effective. Capture the flag exercises are also useful to build troubleshooting skills.
Certification
Certifications recognised by the industry are key in validating a trainee’s expertise and should be encouraged.
Some cloud security certifications are:
- Certified Cloud Security Professional(CCSP)
- AWS Certified Security
- Microsoft Certified Azure Security Engineer Associate
- Google Cloud Professional Cloud Security Engineer
Key Challenges in Cloud Training
Implementation of an effective cloud security training programme can face certain challenges.
Rapid innovation makes training an ongoing process as providers release new services every year. This can lead to burnout.
Training programmes should include regular updates and acknowledge the pace of individual learning without implementing stringent deadlines and requirements which may have an adverse impact on learners.
Multi-Cloud Complexity must be addressed as many enterprises use a mix of AWS, Azure and Google Cloud. Training should include the architectural differences between platforms to prevent configuration errors across various platforms.
Effectiveness of security training must be measured using factors like reduced security alerts or faster incident resolution times.
Trainees should be encouraged to hold active certification and pursue further certification for increased efficiency.
Cloud Security Training is not a one time process. It is an ongoing effort, which must keep up with modern technology, changing threat environments and new services.
The human element is extremely crucial as the cloud is, after all, a human development and its defence, while enhanced by technology, requires a human mind and intention to protect valuable data from threat.
By: Samikhsha Deshpande