- Overview
- Course Details
The course is designed to provide participants with a deep understanding of Zero Trust concepts and practical skills in implementing Zero Trust strategies in an AWS environment using both containers and VMs. Participants will not only learn about the theoretical underpinnings of Zero Trust but will also gain hands-on experience in configuring and managing Zero Trust environments, ensuring they can apply what they have learned in real-world scenarios.
This five day instructor led course will
consist of three days focusing on Zero Trust Architecture.
The course offers a
balanced mix of lectures and hands-on labs, primarily focusing on the
fundamentals of Zero Trust principles, architecture as defined by NIST SP
800-207, and the CISA Zero Trust Maturity Model, as well as incorporating
insights from the NSTAC Report to the President and CSA documentation on Zero
Trust.
Day four and half of day five will focus on exam prep for the Certificate of Competence in Zero Trust (CCZT) exam. The afternoon of
day five will have everyone in the class take the virtual exam.
The course is designed to provide
participants with a deep understanding of Zero Trust concepts and practical
skills in implementing Zero Trust strategies in an AWS environment using both
containers and VMs. Participants will not only learn about the theoretical
underpinnings of Zero Trust but will also gain hands-on experience in
configuring and managing Zero Trust environments, ensuring they can apply what
they have learned in real-world scenarios.
Course Outline
- Day 1: Introduction to Zero
Trust Principles and Architecture
Session 1: Introduction to
Zero Trust
Overview of Zero Trust concepts
Historical context and evolution of the
Zero Trust model
Key principles of Zero Trust (CISA, NIST,
NSTAC)
Session 2: Foundations of Zero
Trust Architecture (NIST SP 800-207)
Definitions and core concepts
Detailed discussion on NIST’s Zero Trust
Architecture
Reviewing the Zero Trust Architecture
Pillars and Tenets
Session 3: Hands-On Lab 1
Setting up a basic AWS environment
Configuring VMs and Containers to run Zero
Trust simulations
Basic exercises on identity verification
and secure access
Session 4: Zero Trust Maturity
Model (CISA)
Introduction to the maturity model
Stages of maturity: Traditional, Advanced,
Optimal
Assessing organizational readiness and
maturity levels.
- Day 2: Deep Dive into Zero
Trust Components and CSA Guidance
Session 1: Trust Algorithms
and Policies
Understanding trust algorithms in Zero
Trust
Policy enforcement in a Zero Trust
Architecture
Use of artificial intelligence and machine
learning in trust assessments
Session 2: Identity and Access
Management in Zero Trust
Role of identity management
Authentication mechanisms (multi-factor
authentication, biometric, etc.)
Hands-on with AWS IAM for Zero Trust
scenarios
Session 3: Hands-On Lab 2
Implementing conditional access and
microsegmentation on AWS
Practical exercises using AWS security
tools and features
Session 4: CSA Documentation
on Zero Trust
Reviewing key CSA publications and
guidelines on Zero Trust
Implementing CSA’s recommendations in
enterprise environments.
- Day 3: Implementing and
Managing Zero Trust Environments
Session 1: Network Security in
Zero Trust Environments
Network segmentation strategies
Implementing least privilege access
Inspection and logging mechanisms for
traffic
Session 2: Monitoring,
Analytics, and Continuous Improvement
Continuous monitoring and diagnostics
Anomaly detection using AWS CloudTrail and
other tools
Feedback loops for policy and
configuration updates
Session 3: Hands-On Lab 3
Advanced scenarios: Responding to security
incidents in a Zero Trust framework
Using AWS tools for real-time alerts and
responses
Session 4: Case Studies and
Future Trends
Discussion on real-world applications of
Zero Trust
Future trends and innovations in Zero
Trust technologies
Q&A and course wrap-up.
Exam: participants must take the exam on the last day of class (afternoon of day 5).