This document provides additional resources to supplement your learning in Module 3. These resources include architecture frameworks, cloud security tools, vendor management resources, and incident response materials.
Official Resources:
- TOGAF Website: https://www.opengroup.org/togaf
- TOGAF Standard: https://pubs.opengroup.org/architecture/togaf9-doc/arch/
Key Components:
- Architecture Development Method (ADM)
- Architecture Content Framework
- Enterprise Continuum
- Architecture Capability Framework
Official Resources:
- SABSA Website: https://sabsa.org/
- SABSA White Papers: https://sabsa.org/sabsa-executive-summary/
Key Concepts:
- Business-driven approach to security architecture
- Six-layer model (Contextual, Conceptual, Logical, Physical, Component, Operational)
- Risk-driven architecture
Official Resources:
- NIST SP 800-160: Systems Security Engineering
- NIST Cybersecurity Framework: https://www.nist.gov/cyberframework
Official Resources:
- NIST SP 800-207: Zero Trust Architecture
- CISA Zero Trust Maturity Model: https://www.cisa.gov/zero-trust-maturity-model
Key Principles:
- Verify explicitly
- Use least privilege access
- Assume breach
Core Components:
- Policy Engine
- Policy Administrator
- Policy Enforcement Point
Implementation Approaches:
- Enhanced Identity Governance
- Micro-segmentation
- Network Infrastructure and Software Defined Perimeter
- "Zero Trust Networks" by Evan Gilman and Doug Barth
- "The Cybersecurity Architect's Handbook" by Lester Nichols
- "Enterprise Security Architecture" by Nicholas A. Sherwood
| Model | Provider Manages | Customer Manages |
|---|---|---|
| IaaS | Physical infrastructure, virtualization | OS, middleware, runtime, data, applications |
| PaaS | Physical infrastructure, virtualization, OS, middleware, runtime | Data, applications |
| SaaS | Everything except data | Data (and some configurations) |
Official Resources:
- AWS Security Hub: https://aws.amazon.com/security-hub/
- AWS Well-Architected Framework: https://aws.amazon.com/architecture/well-architected/
- AWS Security Best Practices: https://aws.amazon.com/security/best-practices/
Key Services:
- IAM (Identity and Access Management)
- GuardDuty (Threat Detection)
- CloudTrail (Logging and Monitoring)
- KMS (Key Management Service)
- Security Groups and NACLs
Official Resources:
- Azure Security Center: https://azure.microsoft.com/en-us/services/security-center/
- Azure Security Documentation: https://docs.microsoft.com/en-us/azure/security/
Key Services:
- Azure Active Directory
- Azure Security Center
- Azure Sentinel (SIEM)
- Azure Key Vault
- Network Security Groups
Official Resources:
- Google Cloud Security: https://cloud.google.com/security
- Google Cloud Security Command Center: https://cloud.google.com/security-command-center
Key Services:
- Cloud Identity and Access Management
- Cloud Security Command Center
- Cloud Armor (DDoS Protection)
- Cloud KMS
- VPC Service Controls
- CSA Cloud Controls Matrix (CCM): https://cloudsecurityalliance.org/
- ISO 27017: Cloud Security Controls
- ISO 27018: Protection of PII in Public Clouds
- FedRAMP: Federal Risk and Authorization Management Program
- CloudSploit: Open-source cloud security scanning
- Prowler: AWS security assessment tool
- ScoutSuite: Multi-cloud security auditing tool
- Cloud Custodian: Cloud governance tool
- "Cloud Security and Privacy" by Tim Mather, Subra Kumaraswamy, and Shahed Latif
- "Architecting the Cloud" by Michael J. Kavis
Key Assessment Areas:
- Information Security Policies and Procedures
- Access Control and Identity Management
- Data Protection and Encryption
- Incident Response and Business Continuity
- Compliance and Regulatory Adherence
- Physical Security
- Personnel Security
- Network Security
- Application Security
- Vendor Management
- SIG (Standardized Information Gathering): https://sharedassessments.org/
- CAIQ (Consensus Assessments Initiative Questionnaire): https://cloudsecurityalliance.org/
- NIST SP 800-161: Supply Chain Risk Management
- OneTrust: Vendor risk management platform
- BitSight: Security ratings platform
- SecurityScorecard: Security ratings and continuous monitoring
- RiskRecon: Third-party cyber risk management
Essential Security Requirements:
- Data encryption (at rest and in transit)
- Access control and authentication
- Audit logging and monitoring
- Incident response procedures
- Business continuity and disaster recovery
- Compliance certifications (ISO 27001, SOC 2, etc.)
- Data residency and sovereignty
- Right to audit
- Breach notification procedures
- Data deletion and retention policies
- Data Protection Addendum (DPA)
- Service Level Agreement (SLA)
- Liability and Indemnification
- Audit Rights
- Termination and Data Return
Incident Response Lifecycle:
- Preparation
- Detection and Analysis
- Containment, Eradication, and Recovery
- Post-Incident Activity
Official Resource: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Six Steps:
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned
Official Resource: https://www.sans.org/
- TheHive: Incident response platform
- MISP (Malware Information Sharing Platform): Threat intelligence platform
- GRR (Google Rapid Response): Incident response framework
- Velociraptor: Endpoint visibility and collection tool
| Severity | Description | Response Time |
|---|---|---|
| Critical | Significant business impact, widespread data breach | Immediate (< 1 hour) |
| High | Moderate business impact, limited data breach | < 4 hours |
| Medium | Minor business impact, no data breach | < 24 hours |
| Low | Minimal business impact, informational | < 72 hours |
Official Resource: https://www.iso.org/standard/75106.html
Key Components:
- Business Impact Analysis (BIA)
- Risk Assessment
- Business Continuity Strategy
- Business Continuity Plans
- Testing and Exercising
- Maintenance and Review
Key Metrics:
- RTO (Recovery Time Objective): Maximum acceptable time to restore a system
- RPO (Recovery Point Objective): Maximum acceptable amount of data loss
- MTTR (Mean Time to Repair): Average time to repair a system
- MTBF (Mean Time Between Failures): Average time between system failures
- Ransomware Attack: Critical systems encrypted, ransom demanded
- Data Breach: Customer data exfiltrated by external attacker
- Insider Threat: Employee intentionally sabotages systems
- DDoS Attack: Website and services unavailable due to distributed attack
- Supply Chain Compromise: Third-party vendor compromised, affecting your systems
- Natural Disaster: Data center destroyed by fire/flood/earthquake
- "The Cybersecurity Playbook" by Allison Cerra
- "Incident Response & Computer Forensics" by Jason T. Luttgens, Matthew Pepe, and Kevin Mandia
- "Business Continuity Planning" by Kenneth N. Myers
Multiple layers of security controls to protect assets.
Layers:
- Physical Security
- Network Security
- Host Security
- Application Security
- Data Security
Users and systems should have only the minimum access necessary to perform their functions.
Critical functions should be divided among multiple people to prevent fraud and error.
Systems should fail in a secure state rather than an insecure state.
- CCSP (Certified Cloud Security Professional): https://www.isc2.org/Certifications/CCSP
- AWS Certified Security - Specialty: https://aws.amazon.com/certification/
- Azure Security Engineer Associate: https://docs.microsoft.com/en-us/learn/certifications/
- GCIH (GIAC Certified Incident Handler): https://www.giac.org/
- Cloud Security Alliance (CSA): https://cloudsecurityalliance.org/
- FIRST (Forum of Incident Response and Security Teams): https://www.first.org/
- BCP (Business Continuity Plan): A plan for maintaining business operations during and after a disruption
- DRP (Disaster Recovery Plan): A plan for recovering IT systems after a disaster
- IRP (Incident Response Plan): A plan for responding to security incidents
- MTBF (Mean Time Between Failures): Average time between system failures
- MTTR (Mean Time to Repair): Average time to repair a system
- RPO (Recovery Point Objective): Maximum acceptable amount of data loss
- RTO (Recovery Time Objective): Maximum acceptable time to restore a system
- TPRA (Third-Party Risk Assessment): Assessment of risks associated with third-party vendors
- ZTA (Zero Trust Architecture): Security model based on "never trust, always verify"
Last Updated: December 2025
Version: 1.0