Choose your language
Design Security Solutions for Infrastructure Course
More than 2 million students worldwide

Design Security Solutions for Infrastructure Course

Master the skills to design robust, end-to-end security solutions for modern infrastructure environments. From network segmentation and identity governance to cloud security and incident response, this course equips security professionals with the architectural frameworks and practical tools needed to protect critical systems at scale.

Dedika for businesses

What you will learn:

  • Apply proven security frameworks and risk management principles to real infrastructure environments.

  • Design secure network architectures using segmentation, perimeter controls, and traffic inspection strategies.

  • Architect identity and access management systems that enforce least privilege across all infrastructure layers.

  • Implement encryption, data classification, and key management controls to protect sensitive infrastructure data.

  • Integrate cloud-native security controls and posture management into hybrid and multi-cloud environments.

  • Develop security governance frameworks, monitoring pipelines, and incident response plans for sustained protection.

How you study in practice Design Security Solutions for Infrastructure Course

How you practise Design Security Solutions for Infrastructure Course

For companies looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Infrastructure Security

  • Lesson 1 • Risk Management Fundamentals

    Covers risk identification, assessment, and prioritisation as the basis for security investment. Links risk posture to design choices throughout the course.

  • Lesson 2 • Threat Landscape and Attack Surfaces

    Maps common threat actors, attack vectors, and infrastructure-specific vulnerabilities. Connects threat awareness to proactive security design.

  • Lesson 3 • Infrastructure Security Core Concepts

    Defines infrastructure components, security goals, and the CIA triad. Provides the conceptual baseline for all subsequent security design decisions.

  • Lesson 4 • Security Frameworks and Standards

    Introduces widely adopted security frameworks and control catalogues used to structure infrastructure protection. Enables framework-driven design decisions.

  • Lesson 5 • Security Design Principles

    Presents least privilege, separation of duties, fail-safe defaults, and zero trust as guiding design principles. Grounds all later architectural decisions in proven principles.

Chapter 2See details

Network Security Architecture Design

  • Lesson 1 • Traffic Inspection and Filtering

    Covers intrusion detection and prevention systems, deep packet inspection, and web application firewalls. Enables detection and blocking of malicious traffic flows.

  • Lesson 2 • Network Segmentation Strategies

    Covers VLANs, subnetting, and micro-segmentation to isolate workloads and limit blast radius. Directly applies defence-in-depth principles from Chapter 1.

  • Lesson 3 • Secure Remote Access Design

    Addresses VPN architectures, split tunnelling risks, and zero trust network access models. Ensures remote connectivity does not expand the attack surface.

  • Lesson 4 • Network Security Monitoring Design

    Designs logging, flow analysis, and alerting pipelines for network visibility. Connects network architecture to detection and response capabilities.

  • Lesson 5 • Perimeter and Boundary Controls

    Examines firewall architectures, DMZ design, and ingress/egress filtering. Establishes controlled entry and exit points for infrastructure traffic.

Chapter 3See details

Identity and Access Management Design

  • Lesson 1 • Identity Architecture Fundamentals

    Defines identity stores, directory services, and federation models as the backbone of access control. Builds on least privilege principles introduced in Chapter 1.

  • Lesson 2 • Identity Governance and Auditing

    Covers access reviews, entitlement management, and audit trail design for compliance. Ensures ongoing accountability for all identity-related actions.

  • Lesson 3 • Authentication Mechanism Design

    Covers multi-factor authentication, passwordless methods, and certificate-based authentication. Ensures authentication strength matches infrastructure sensitivity.

  • Lesson 4 • Authorisation and Access Control Models

    Examines RBAC, ABAC, and policy-based access control for infrastructure resources. Translates business roles into enforceable access policies.

  • Lesson 5 • Privileged Access Management

    Addresses privileged account governance, just-in-time access, and session recording for high-risk accounts. Reduces insider threat and credential abuse risk.

Chapter 4See details

Data Security and Encryption Design

  • Lesson 1 • Encryption at Rest Design

    Addresses full-disk, file-level, and database encryption strategies for stored data protection. Ensures sensitive data remains protected if storage media is compromised.

  • Lesson 2 • Encryption in Transit Design

    Covers TLS configuration, certificate management, and secure protocol selection for data in motion. Prevents interception and tampering of infrastructure communications.

  • Lesson 3 • Data Classification and Governance

    Establishes data classification tiers, ownership models, and handling policies as prerequisites for protection design. Aligns data controls with risk levels from Chapter 1.

  • Lesson 4 • Key Management Architecture

    Designs key generation, storage, rotation, and escrow processes to sustain cryptographic controls. Ensures encryption remains effective and recoverable over time.

  • Lesson 5 • Cryptographic Principles and Selection

    Covers symmetric, asymmetric, and hashing algorithms with selection criteria for infrastructure use cases. Provides the cryptographic foundation for all encryption design decisions.

Chapter 5See details

Endpoint and Server Hardening

  • Lesson 1 • Vulnerability Management Programme Design

    Designs scanning schedules, remediation workflows, and exception handling for ongoing vulnerability management. Sustains hardening posture over the infrastructure lifecycle.

  • Lesson 2 • Endpoint Protection Controls

    Examines antimalware, host-based firewalls, and application allowlisting as layered endpoint defences. Complements network controls designed in Chapter 2.

  • Lesson 3 • Application and Service Hardening

    Covers secure configuration of web servers, databases, and middleware to remove default vulnerabilities. Extends OS hardening to the application layer.

  • Lesson 4 • Operating System Hardening

    Addresses service minimisation, patch management, and secure boot configuration for server and workstation OS. Eliminates unnecessary exposure at the OS layer.

  • Lesson 5 • Hardening Baseline Development

    Covers benchmark selection, configuration standards, and baseline documentation for consistent hardening. Operationalises the attack surface reduction principles from Chapter 1.

Chapter 6See details

Cloud and Hybrid Infrastructure Security

  • Lesson 1 • Cloud Network Security Design

    Covers virtual network segmentation, security groups, and private connectivity options for cloud environments. Adapts network security architecture from Chapter 2 to cloud platforms.

  • Lesson 2 • Cloud Security Posture Management

    Designs continuous configuration assessment, policy enforcement, and drift detection for cloud environments. Ensures cloud infrastructure maintains its intended security posture over time.

  • Lesson 3 • Cloud Identity and Access Design

    Addresses cloud IAM policies, service account governance, and federated identity for cloud workloads. Applies IAM design from Chapter 3 to cloud-native environments.

  • Lesson 4 • Cloud Security Fundamentals

    Covers shared responsibility models, cloud service types, and deployment models as the basis for cloud security design. Extends on-premises principles from earlier chapters to cloud contexts.

  • Lesson 5 • Cloud Data Protection Strategies

    Examines cloud storage encryption, data residency controls, and secure data transfer for cloud workloads. Applies encryption design from Chapter 4 to cloud storage services.

Chapter 7See details

Security Monitoring and Incident Response Design

  • Lesson 1 • Incident Response Plan Design

    Covers incident classification, response team roles, and escalation procedures for structured incident handling. Provides the organisational framework for executing technical response actions.

  • Lesson 2 • Containment and Eradication Procedures

    Designs isolation strategies, malware removal workflows, and system restoration procedures for active incidents. Operationalises the response plan with technical containment actions.

  • Lesson 3 • Security Information and Event Management

    Covers SIEM architecture, log source onboarding, and correlation rule design for centralised detection. Aggregates visibility from network, endpoint, and identity layers designed earlier.

  • Lesson 4 • Threat Detection Engineering

    Addresses detection use case development, MITRE ATT&CK mapping, and behavioural analytics for infrastructure threats. Translates threat knowledge from Chapter 1 into actionable detections.

  • Lesson 5 • Post-Incident Review and Improvement

    Covers lessons-learned processes, root cause analysis, and control improvement cycles after incidents. Closes the feedback loop between detection, response, and security design.

Chapter 8See details

Security Architecture Review and Governance

  • Lesson 1 • Compliance and Audit Programme Design

    Covers control mapping to regulatory requirements, audit evidence collection, and continuous compliance monitoring. Ensures infrastructure designs satisfy external and internal obligations.

  • Lesson 2 • Security Policy and Standards Design

    Addresses policy hierarchy, standards development, and exception management to formalise security requirements. Translates technical controls into enforceable organisational policy.

  • Lesson 3 • Security Architecture Review Process

    Covers threat modelling, design review gates, and architecture decision records for evaluating security designs. Applies all prior technical knowledge within a structured review process.

  • Lesson 4 • Security Metrics and Reporting

    Designs KPIs, KRIs, and executive dashboards to communicate security posture to stakeholders. Enables data-driven governance and resource allocation decisions.

  • Lesson 5 • Continuous Security Improvement

    Covers maturity model assessments, roadmap development, and programme benchmarking for ongoing security evolution. Synthesises all course content into a sustainable improvement cycle.

Certification

Your valid completion certificate

This course is for you:

  • Systems Administrator: ready to move from operations into security architecture roles.

  • Network Engineer: wanting to formalise security design skills beyond firewall management.

  • IT Security Analyst: aiming to grow from reactive armed response into proactive infrastructure design.

  • Cloud Engineer: seeking structured security frameworks for hybrid and multi-cloud environments.

  • DevOps Engineer: looking to embed security thinking into infrastructure provisioning workflows.

  • Career Changer: transitioning from general IT into a dedicated infrastructure security specialty.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in Nigeria?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course