Skip to content

Certified Cloud Security Professional (CCSP)

Professional training. Expert instructors. Better value. No compromises.

CY-010 Live Instructor-Led Training
ISC2 5 Days 8 Hours
$2,199

Expert Training. Better Value.

Why pay $3,670 elsewhere?

Pricing shown is for individual enrollment.

Training a Team?

Ask us about group pricing, custom scheduling, and focused delivery.

Contact Us

ISC2 Certified Cloud Security Professional (CCSP) develops the advanced knowledge required to design, implement, manage, and secure cloud environments. It is intended for cybersecurity and cloud professionals responsible for protecting data, applications, platforms, and infrastructure, along with organizations building security capabilities across public, private, hybrid, and multicloud environments.

The curriculum covers cloud concepts, architecture and design, cloud data security, platform and infrastructure security, application security, security operations, and legal, risk, and compliance requirements. Participants examine shared responsibility, cloud service and deployment models, identity and access management, encryption and key management, workload protection, secure development, monitoring, incident response, business continuity, vendor risk, privacy, and regulatory obligations. These areas are addressed as connected parts of a cloud security program rather than isolated technical controls.

Cloud architects, security architects, engineers, consultants, administrators, and other professionals with substantial cloud and cybersecurity responsibilities are the primary audience. ISC2 requires five years of cumulative IT experience, including three years in cybersecurity and one year within a CCSP domain, although qualifying education, the CCSK certificate, or an active CISSP may satisfy part or all of that requirement. Organizations can use CCSP training to strengthen cloud governance, improve coordination between security and infrastructure teams, and develop staff capable of evaluating cloud risk across the full service lifecycle.

Course Objectives

What you will learn

Domain 1: Cloud Concepts, Architecture and Design

  • Understand cloud computing concepts.
  • Describe cloud reference architecture.
  • Understand security concepts relevant to cloud computing.
  • Understand design principles of secure cloud computing.
  • Evaluate Cloud Service Providers (CSP).
  • Comprehend Artificial Intelligence (AI)/Machine Learning (ML).

Domain 2: Cloud Data Security

  • Describe cloud data concepts.
  • Design and implement cloud data storage architectures.
  • Design and apply data security technologies and strategies.
  • Implement data discovery.
  • Plan and implement data classification.
  • Design and implement Information Rights Management (IRM).
  • Plan and implement data retention, deletion and archiving policies.
  • Design and implement auditability, traceability and accountability of data events.
  • Comprehend data protection of Artificial Intelligence (AI) and Machine Learning (ML) data.

Domain 3: Cloud Platform and Infrastructure Security

  • Comprehend cloud infrastructure components.
  • Design a secure data center.
  • Analyze risks associated with cloud infrastructure and platforms.
  • Plan and implementation of security controls.
  • Plan Business Continuity (BC) and Disaster Recovery (DR).

Domain 4: Cloud Application Security

  • Advocate training and awareness for application security.
  • Describe the Secure Software Development Life Cycle (SDLC) process.
  • Apply the Secure Software Development Life Cycle (SDLC).
  • Apply cloud software assurance and validation.
  • Use verified secure software.
  • Comprehend and apply the specifics of cloud application architecture.
  • Design appropriate Identity and Access Management (IAM) solutions.

Domain 5: Cloud Security Operations

  • Build and implement physical and logical infrastructure for cloud environment.
  • Operate and maintain physical and logical infrastructure for cloud environment.
  • Implement operational controls and standards (e.g., NIST, ISO, HIPAA, COBIT, CIS Controls, COSO, ITIL, ISO/IEC 20000-1).
  • Support digital forensics.
  • Manage communication with relevant parties.
  • Manage security operations.

Domain 6: Legal, Risk and Compliance

  • Articulate legal requirements and unique risks within the cloud environment.
  • Understand privacy requirements.
  • Understand audit processes, methodologies, and required adaptations for a cloud environment.
  • Understand implications of cloud to enterprise risk management.
  • Understand outsourcing and cloud contract design.