1Security strategy and best practices
- 1.1Zero Trust and RaMP
Understand Zero Trust (verify explicitly, least privilege, assume breach) across its six defense pillars (identity/endpoints/apps/data/infrastructure/network) and the prioritized adoption path of the Rapid Modernization Plan (RaMP), from an architect’s perspective.
- 1.2Aligning to best practices with MCRA and MCSB
Understand how to align capabilities and controls to best practices using the Microsoft Cybersecurity Reference Architectures (MCRA) and the Microsoft cloud security benchmark (MCSB), designing against insider, external, and supply-chain attacks.
- 1.3CAF, WAF, Azure landing zones, and DevSecOps
Understand security/governance strategy based on the Cloud Adoption Framework (CAF) and the Azure Well-Architected Framework (WAF), implementing governance via Azure landing zones, and designing a DevSecOps process aligned to CAF.
- 1.4Resiliency, BCDR, and ransomware defense
Understand a security strategy aligned to business resiliency goals, identifying and prioritizing threats to business-critical assets, secure backup & restore (BCDR) for hybrid/multicloud, ransomware mitigation (prioritizing BCDR and privileged access), and evaluating security updates.

