The course is designed to provide participants with a deep understanding of Zero Trust concepts and practical skills in implementing Zero Trust strategies in an AWS environment using both containers and VMs. Participants will not only learn about the theoretical underpinnings of Zero Trust but will also gain hands-on experience in configuring and managing Zero Trust environments, ensuring they can apply what they have learned in real-world scenarios.



Zero Trust Training 

This five day instructor led course will
consist of three days focusing on Zero Trust Architecture. 

The course offers a
balanced mix of lectures and hands-on labs, primarily focusing on the
fundamentals of Zero Trust principles, architecture as defined by NIST SP
800-207, and the CISA Zero Trust Maturity Model, as well as incorporating
insights from the NSTAC Report to the President and CSA documentation on Zero
Trust. 

Day four and half of day five will focus on exam prep for the Certificate of Competence in Zero Trust (CCZT) exam. The afternoon of
day five will have everyone in the class take the virtual exam.


The course is designed to provide
participants with a deep understanding of Zero Trust concepts and practical
skills in implementing Zero Trust strategies in an AWS environment using both
containers and VMs. Participants will not only learn about the theoretical
underpinnings of Zero Trust but will also gain hands-on experience in
configuring and managing Zero Trust environments, ensuring they can apply what
they have learned in real-world scenarios.


Course Outline


  • Day 1: Introduction to Zero
    Trust Principles and Architecture

Session 1: Introduction to
Zero Trust

Overview of Zero Trust concepts

Historical context and evolution of the
Zero Trust model

Key principles of Zero Trust (CISA, NIST,
NSTAC)


Session 2: Foundations of Zero
Trust Architecture (NIST SP 800-207)

Definitions and core concepts

Detailed discussion on NIST’s Zero Trust
Architecture

Reviewing the Zero Trust Architecture
Pillars and Tenets


Session 3: Hands-On Lab 1

Setting up a basic AWS environment

Configuring VMs and Containers to run Zero
Trust simulations

Basic exercises on identity verification
and secure access


Session 4: Zero Trust Maturity
Model (CISA)

Introduction to the maturity model

Stages of maturity: Traditional, Advanced,
Optimal

Assessing organizational readiness and
maturity levels.


  • Day 2: Deep Dive into Zero
    Trust Components and CSA Guidance

Session 1: Trust Algorithms
and Policies

Understanding trust algorithms in Zero
Trust

Policy enforcement in a Zero Trust
Architecture

Use of artificial intelligence and machine
learning in trust assessments


Session 2: Identity and Access
Management in Zero Trust

Role of identity management

Authentication mechanisms (multi-factor
authentication, biometric, etc.)

Hands-on with AWS IAM for Zero Trust
scenarios


Session 3: Hands-On Lab 2

Implementing conditional access and
microsegmentation on AWS

Practical exercises using AWS security
tools and features


Session 4: CSA Documentation
on Zero Trust

Reviewing key CSA publications and
guidelines on Zero Trust

Implementing CSA’s recommendations in
enterprise environments.


  • Day 3: Implementing and
    Managing Zero Trust Environments

Session 1: Network Security in
Zero Trust Environments

Network segmentation strategies

Implementing least privilege access

Inspection and logging mechanisms for
traffic


Session 2: Monitoring,
Analytics, and Continuous Improvement

Continuous monitoring and diagnostics

Anomaly detection using AWS CloudTrail and
other tools

Feedback loops for policy and
configuration updates


Session 3: Hands-On Lab 3

Advanced scenarios: Responding to security
incidents in a Zero Trust framework

Using AWS tools for real-time alerts and
responses


Session 4: Case Studies and
Future Trends

Discussion on real-world applications of
Zero Trust

Future trends and innovations in Zero
Trust technologies

Q&A and course wrap-up.


Exam: participants must take the exam on the last day of class (afternoon of day 5).