Curriculum · Phase 5
Segmenting, gating, and proving control over the network your data moves across
Phase 4 protected the data; this phase protects the network it travels on. It covers cloud networking fundamentals (VPCs, subnets, security groups vs NACLs, and segmentation), Zero Trust Network Access (why the flat VPN is dying and how identity- and device-aware access replaces it — Cloudflare Access, Tailscale, Twingate), and the perimeter services that sit in front of applications (WAF, DDoS protection, and service-mesh mTLS/authorization). The throughline is the same as every phase: translate a "control network access" requirement into a specific cloud configuration and the exportable evidence that proves it operates.
~3 hours
·
3 modules
·
100 points
Module 5.2
Cloud Networking Fundamentals
The network primitives a GRC Engineer must read fluently: VPCs and subnets, the difference between security groups (stateful, instance-level) and NACLs (stateless, subnet-level), and why segmentation is the control behind "limit the blast radius." Includes a hands-on lab designing least-privilege security group rules for a 3-tier application.
40 min
0 / 2
Module 5.3
Zero Trust Networking (ZTNA vs VPN)
Why the flat corporate VPN is being retired and what replaces it: Zero Trust Network Access, where every request is authenticated, authorized per application, and evaluated against device posture — no implicit trust from being "on the network." Compares Cloudflare Access, Tailscale, and Twingate, then has you configure a ZTNA policy set for a 50-person company.
50 min
0 / 3
Module 5.4
WAF, DDoS + Service Meshes
The services that sit in front of and between applications: web application firewalls (OWASP managed rules and the false-positive tuning problem), DDoS protection at the edge, and service meshes that enforce mTLS and service-to-service authorization inside the cluster. Includes a lab on tuning WAF rules to stop blocking legitimate traffic without weakening protection.
33 min
0 / 2