Curriculum · Phase 4
Encrypting, governing, and proving control over data at rest, in transit, and in cloud storage
Data protection is where compliance stops being about people and devices and starts being about the data itself. This phase covers cryptography and encryption at rest (cloud KMS, CMK vs BYOK), encryption in transit (TLS 1.3, mTLS, certificate lifecycle), securing cloud object storage (S3, GCS, Azure Blob) against the misconfigurations behind most public-cloud breaches, backups and ransomware resilience (3-2-1, RTO/RPO, immutable backups), and secrets management and DLP (keeping credentials out of code and regulated data from leaking out). The throughline: translate a "protect the data" requirement into a specific cloud control and the exportable evidence that proves it operates.
~5 hours
·
5 modules
·
190 points
Module 4.2
Cryptography + Encryption at Rest
The cryptography a GRC Engineer actually needs: symmetric vs asymmetric vs hashing and what each is for, envelope encryption, and how cloud KMS (AWS, GCP, Azure) turns "data must be encrypted at rest" into a key policy, a rotation schedule, and an access log you can hand to an auditor.
58 min
0 / 3
Module 4.3
Encryption in Transit + TLS
How data is protected while it moves: the TLS handshake, TLS 1.2 vs 1.3, mutual TLS for service-to-service trust, and the certificate lifecycle whose weakest link — an expired or weakly-configured cert — is one of the most common audit findings and outages alike.
30 min
0 / 2
Module 4.4
Cloud Storage Security
Securing cloud object storage — S3, Google Cloud Storage, and Azure Blob — against the misconfigurations behind most public-cloud data exposures: public access, weak ACLs vs IAM, missing default encryption, no versioning, and no access logging. Includes a hands-on find-and-fix exercise and a reusable cross-cloud security checklist.
58 min
0 / 3
Module 4.5
Backups + Ransomware Resilience
Backups are the control that turns a ransomware incident from a business- ending event into a bad week. The 3-2-1 rule, RTO/RPO, immutable and air-gapped backups, restore testing, and a tabletop that shows where backup programs actually fail — then designing a ransomware-resilient backup for a large dataset.
48 min
0 / 3
Module 4.6
Secrets Management + DLP
The two controls that keep sensitive data from leaking out the side doors: secrets management (Vault and the cloud-native secret stores, plus rotation and dynamic credentials) so credentials never live in code, and Data Loss Prevention (Macie, Purview, and classification) so regulated data is found and stopped before it leaves. Ends with migrating a codebase off hardcoded secrets.
60 min
0 / 3