Data Security Posture Management (DSPM) Training
About Course
Most organisations cannot answer a simple question: where is our sensitive data, who can reach it, and which of those paths should not exist? DSPM is the practice of answering that continuously rather than once a year.
This programme covers the discipline end to end — discovering data across cloud and on-premise estates, classifying it accurately enough to act on, mapping the identities and permissions that reach it, scoring what actually matters, and driving remediation that holds. It is built for security engineers, cloud architects and data platform teams who own the estate rather than audit it.
What you will learn
- Distinguish DSPM from CSPM, CASB and DLP, and know where each belongs
- Discover structured, unstructured and shadow data across multi-cloud estates
- Build a classification scheme that survives contact with real data
- Map data-to-identity relationships and find effective access paths
- Detect the misconfigurations that most often cause exposure
- Score risk by combining sensitivity, exposure and reachability
- Design remediation that closes findings without breaking pipelines
- Report posture in terms an executive and an engineer both accept
Course Outline
Module-1 WHAT DSPM IS FOR
- The question DSPM answers, and the ones it does not
- Where DSPM sits alongside CSPM, DLP, CASB and IAM
- Data-centric versus infrastructure-centric security
- Exercise: list the data questions your current tooling cannot answer
Module-2 DISCOVERY ACROSS THE ESTATE
- Object storage, managed databases, warehouses, lakes and snapshots
- Unstructured data in file shares, collaboration tools and ticket systems
- Shadow data: copies, exports, dev fixtures, forgotten backups
- Agentless versus agent-based discovery and the trade-offs
- Exercise: enumerate the data stores in one cloud account
Module-3 CLASSIFICATION THAT HOLDS UP
- Pattern matching, context, and their failure modes
- Validating classifier output; measuring precision and recall
- Handling confidential-but-not-personal data
- Regional definitions: personal data, PHI, PCI, special category
- Exercise: build and test a classification ruleset
Module-4 ACCESS AND IDENTITY MAPPING
- Effective permissions versus assigned permissions
- Roles, policies, groups, service accounts and inherited access
- Cross-account and cross-tenant reachability
- Standing access, just-in-time access and stale entitlements
- Exercise: compute who can actually read one sensitive bucket
Module-5 EXPOSURE AND MISCONFIGURATION
- Public exposure paths people do not expect
- Encryption at rest and in transit: what it does and does not prevent
- Logging gaps that hide access
- Third-party and vendor reachability into your data
- Exercise: audit one store against an exposure checklist
Module-6 RISK SCORING AND PRIORITISATION
- Combining sensitivity, volume, exposure and reachability
- Avoiding scores nobody trusts
- Blast-radius thinking
- Separating what is urgent from what is merely wrong
- Exercise: rank twenty findings and justify the top five
Module-7 REMEDIATION AND PREVENTION
- Fixing access without breaking the pipeline that needs it
- Tightening defaults so the same finding stops recurring
- Guardrails in infrastructure as code
- Data minimisation and retention as posture controls
- Exercise: write a remediation plan for a real over-permissioned path
Module-8 OPERATING DSPM
- Continuous assessment versus point-in-time scanning
- Ownership: who receives a finding and who closes it
- Integrating findings into existing ticketing and SLAs
- Reporting posture trend, not just posture
- Exercise: design the operating model and its metrics
Student Ratings & Reviews
No Review Yet