<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="26443" language="de" source="https://portal.flane.ch/swisscom/xml-course/amazon-sgs" lastchanged="2025-12-03T10:27:22+01:00" parent="https://portal.flane.ch/swisscom/xml-courses"><title>AWS Security Governance at Scale</title><productcode>SGS</productcode><vendorcode>AW</vendorcode><vendorname>Amazon Web Services</vendorname><fullproductcode>AW-SGS</fullproductcode><version>1.0</version><essentials>&lt;p&gt;Erforderlich:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AWS Security Fundamentals (digitaler Kurs)&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/course/amazon-sec-ess&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;AWS Security Essentials &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SEC-ESS)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Optional:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AWS Cloud Management Assessment&lt;/li&gt;&lt;li&gt;Introduction to AWS Control Tower&lt;/li&gt;&lt;li&gt;Automated Landing Zone course&lt;/li&gt;&lt;li&gt;Introduction to AWS Service Catalog&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Dieser Kurs richtet sich an L&amp;ouml;sungsarchitekten, Security-DevOps-Personal und Sicherheitsingenieure.&lt;/p&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Course Introduction&lt;/li&gt;&lt;li&gt;Module 1: Governance at Scale&lt;/li&gt;&lt;li&gt;Module 2: Governance Automation&lt;/li&gt;&lt;li&gt;Module 3: Preventive Controls&lt;/li&gt;&lt;li&gt;Module 4: Detective Controls&lt;/li&gt;&lt;li&gt;Module 5: Resources&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Course Introduction&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Instructor introduction&lt;/li&gt;&lt;li&gt;Learning objectives&lt;/li&gt;&lt;li&gt;Course structure and objectives&lt;/li&gt;&lt;li&gt;Course logistics and agenda&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 1: Governance at Scale&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Governance at scale focal points&lt;/li&gt;&lt;li&gt;Business and Technical Challenges&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 2: Governance Automation&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Multi-account strategies, guidance, and architecture&lt;/li&gt;&lt;li&gt;Environments for agility and governance at scale&lt;/li&gt;&lt;li&gt;Governance with AWS Control Tower&lt;/li&gt;&lt;li&gt;Use cases for governance at scale&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 3: Preventive Controls&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Enterprise environment challenges for developers&lt;/li&gt;&lt;li&gt;AWS Service Catalog&lt;/li&gt;&lt;li&gt;Resource creation&lt;/li&gt;&lt;li&gt;Workflows for provisioning accounts&lt;/li&gt;&lt;li&gt;Preventive cost and security governance&lt;/li&gt;&lt;li&gt;Self-service with existing IT service management (ITSM) tools&lt;/li&gt;&lt;li&gt;Lab 1: Deploy Resources for AWS Catalog&lt;/li&gt;&lt;li&gt;Create a new AWS Service Catalog portfolio and product.&lt;/li&gt;&lt;li&gt;Add an IAM role to a launch constraint to limit the actions the product can perform.&lt;/li&gt;&lt;li&gt;Grant access for an IAM role to view the catalog items.&lt;/li&gt;&lt;li&gt;Deploy an S3 bucket from an AWS Service Catalog product.&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 4: Detective Controls&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Operations aspect of governance at scale&lt;/li&gt;&lt;li&gt;Resource monitoring&lt;/li&gt;&lt;li&gt;Configuration rules for auditing&lt;/li&gt;&lt;li&gt;Operational insights&lt;/li&gt;&lt;li&gt;Remediation&lt;/li&gt;&lt;li&gt;Clean up accounts&lt;/li&gt;&lt;li&gt;Lab 2: Compliance and Security Automation with AWS Config&lt;/li&gt;&lt;li&gt;Apply Managed Rules through AWS Config to selected resources&lt;/li&gt;&lt;li&gt;Automate remediation based on AWS Config rules&lt;/li&gt;&lt;li&gt;Investigate the Amazon Config dashboard and verify resources and rule compliance&lt;/li&gt;&lt;li&gt;Lab 3: Taking Action with AWS Systems Manager&lt;/li&gt;&lt;li&gt;Setup Resource Groups for various resources based on common requirements&lt;/li&gt;&lt;li&gt;Perform automated actions against targeted Resource Groups&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Module 5: Resources&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explore additional resources for security governance at scale&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>Erforderlich:


- AWS Security Fundamentals (digitaler Kurs)
- AWS Security Essentials (SEC-ESS)
Optional:


- AWS Cloud Management Assessment
- Introduction to AWS Control Tower
- Automated Landing Zone course
- Introduction to AWS Service Catalog</essentials_plain><audience_plain>Dieser Kurs richtet sich an Lösungsarchitekten, Security-DevOps-Personal und Sicherheitsingenieure.</audience_plain><contents_plain>- Course Introduction
- Module 1: Governance at Scale
- Module 2: Governance Automation
- Module 3: Preventive Controls
- Module 4: Detective Controls
- Module 5: Resources</contents_plain><outline_plain>Course Introduction


- Instructor introduction
- Learning objectives
- Course structure and objectives
- Course logistics and agenda
Module 1: Governance at Scale


- Governance at scale focal points
- Business and Technical Challenges
Module 2: Governance Automation


- Multi-account strategies, guidance, and architecture
- Environments for agility and governance at scale
- Governance with AWS Control Tower
- Use cases for governance at scale
Module 3: Preventive Controls


- Enterprise environment challenges for developers
- AWS Service Catalog
- Resource creation
- Workflows for provisioning accounts
- Preventive cost and security governance
- Self-service with existing IT service management (ITSM) tools
- Lab 1: Deploy Resources for AWS Catalog
- Create a new AWS Service Catalog portfolio and product.
- Add an IAM role to a launch constraint to limit the actions the product can perform.
- Grant access for an IAM role to view the catalog items.
- Deploy an S3 bucket from an AWS Service Catalog product.
Module 4: Detective Controls


- Operations aspect of governance at scale
- Resource monitoring
- Configuration rules for auditing
- Operational insights
- Remediation
- Clean up accounts
- Lab 2: Compliance and Security Automation with AWS Config
- Apply Managed Rules through AWS Config to selected resources
- Automate remediation based on AWS Config rules
- Investigate the Amazon Config dashboard and verify resources and rule compliance
- Lab 3: Taking Action with AWS Systems Manager
- Setup Resource Groups for various resources based on common requirements
- Perform automated actions against targeted Resource Groups
Module 5: Resources


- Explore additional resources for security governance at scale</outline_plain><duration unit="d" days="1">1 Tag</duration><pricelist><price country="AT" currency="EUR">795.00</price><price country="SE" currency="EUR">750.00</price><price country="SI" currency="EUR">795.00</price><price country="PL" currency="PLN">2000.00</price><price country="AE" currency="USD">750.00</price><price country="GR" currency="EUR">795.00</price><price country="MK" currency="EUR">795.00</price><price country="HU" currency="EUR">795.00</price><price country="NL" currency="EUR">795.00</price><price country="BE" currency="EUR">795.00</price><price country="CH" currency="CHF">870.00</price></pricelist><miles/></course>