Six-week example planStudy one domain at a time, then connect the responsibility boundaries.
Week 1: architecture and shared responsibility
Draw three versions of the same workload as SaaS, PaaS, and IaaS. For each version, identify who controls identity, data, operating system, network, application, logging, backups, and physical infrastructure. Then mark the dependencies that could fail together.
Week 2: data security
Classify a fictional dataset, define an owner, document where it flows, choose protection techniques, define key ownership, create retention rules, and explain how backups and replicas will be disposed of at the end of the lifecycle.
Week 3: platform and infrastructure
Build a cloud network and management-plane diagram. Add administrator identities, workload identities, segmentation, private endpoints, logging, container or orchestration controls, and one tested recovery path.
Week 4: application security
Threat-model an API-driven cloud application. Include dependencies, CI/CD, artifact storage, secrets, deployment identity, application authorization, storage permissions, telemetry, and third-party services. Select at least four testing methods and state what each one proves.
Week 5: operations
Run an incident exercise around stolen cloud credentials. Identify containment, evidence, provider coordination, rotation, recovery, and post-incident control changes. Then test whether a recovery plan includes identity, DNS, keys, data, and network dependencies.
Week 6: legal, risk, and mixed scenarios
Map one cross-border cloud service from data collection through subprocessors and contractual terms. Finish with mixed scenarios that force you to distinguish provider responsibilities, customer responsibilities, risk ownership, technical controls, and legal obligations.