Key information
Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: TBC
Delivered by: TBC
Awarding Institution: TBC
Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350
Microcredential Information
The module aims to provide learners with the knowledge and skills to make informed, risk-aware decisions about enterprise architecture, infrastructure design, and cloud computing. It focuses on understanding how digital infrastructure choices impact business strategy, resilience, compliance, and trust. Learners will critically examine security strategies, assess the risks and opportunities of digital transformation, and develop governance-aligned recommendations that support sustainable and secure organisational growth
Key Details
Time commitment
- Total workload: 125 hours (30 Contact + 95 Independent Learning)
- Contact hours: Lectures: 6 x 2 hours = 12 hours
- Labs: 6 x 2 hours = 12 hours
- Tutorial: 6 x 1 hour = 6 hours
- Private study including examination preparation, specified in hours[1]
- Independent Learning: 95 hours
Assessment
- Continuous Assessment 1 (40%) —Case Study Presentation: for this assessment learners will have to analyse and present a case study of enterprise/cloud adoption, evaluating security strategies, governance implications, and business alignment. The CA is based on course content covered up to the date of assessment. Critical appraisal and evaluation required. Learning Outcome addressed LO1 and LO3.
- Assessment 2, proctored (60%) – Policy Brief / Strategy Recommendation Report/Project: for this assessment learners will have to write and present (with identity verification) a policy brief or executive strategy recommendation to a relevant stakeholder based on a given scenario (e.g., hybrid cloud adoption, data sovereignty compliance, etc/). The report must identify risks/opportunities, propose governance-aligned security strategies, and recommend decision pathways that enhance resilience and trust. The CA is based on the varied themes covered during the course requiring critical evaluation and demonstration of conceptual learning based on scenarios, research and critical appraisal. Learning Outcome addressed LO1, LO2 and LO3.
- Reassessment strategy: The reassessment strategy for this module will consist of an assessment that will evaluate all learning outcomes.
Subjects covered
Week 1: Introduction to EA, Infrastructure & Cloud
Defining EA, infrastructure, and cloud in a digital enterprise; differences from traditional IT; intro to CIA triad within architectural thinking; positioning security as a design concern not an afterthought; relationship to business goals,
Week 2: Enterprise Architecture Frameworks
TOGAF, SABSA, Zachman overview; layering business/app/infra/security domains; mapping SABSA layers to CIA triad; architectural roles in cybersecurity governance.
Week 3: Modelling and Architecture Tooling
ArchiMate, UML for infrastructure and security zoning; visualising defence in depth as architectural layers; mapping firewalls, DMZs, and zoning into infrastructure diagrams.
Week 4: Infrastructure Design Principles
Redundancy, segmentation, zoning, microsegmentation, Zero Trust embedded in infrastructure; secure-by-design principles; aligning infrastructure to security controls. Architectural validation via pen testing and red/blue team simulations.
Week 5: Cloud Architecture & Design
Infrastructure-as-Code (IaC), containers, microservices, orchestration, shared responsibility model, securing cloud-native patterns (serverless, PaaS, SaaS); threat modelling in cloud environments. Using threat intelligence to inform cloud threat models and architecture decisions.
Week 6: Security by Design in EA
Embedding security principles in EA layers; CIA triad revisited in enterprise security strategy; aligning SABSA objectives to business risk; continuity and disaster recovery as architectural functions. Integrating vulnerability management and CVE tracking into architectural governance processes.
Week 7: Identity, Access & Governance in Cloud
IAM architecture; Authentication vs Authorisation, MFA, federation, least privilege, RBAC/ABAC models; governance as risk control; audit trails and trust zones.
Week 8: Cloud Infrastructure: Secure Design Patterns
Virtualisation, Kubernetes, service meshes, API gateways; DevSecOps, container hardening, secrets management; network and endpoint security by design (not bolt-on). Integrating static/dynamic security testing tools into CI/CD pipelines (e.g., SonarQube, ZAP). Container security lifecycle including image scanning (e.g., Trivy) and runtime protection (e.g., Falco).
Week 9: Cloud Deployment Models & Security Impact
IaaS, PaaS, SaaS models through an architectural lens; public/private/hybrid/multi-cloud; how deployment model affects attack surface, data flow, and control layers.
Week 10: Data Security and Sovereignty
Data lifecycle design (at rest/in transit); encryption models; privacy by design, data residency, compliance (e.g., GDPR, ISO27001), cloud security policies.
Week 11: Governance, Risk & Budget in EA
Strategic risk frameworks (e.g., NIST CSF); cost of poor security design; cloud cost management (FinOps); business continuity; risk appetite mapped to infrastructure priorities.
Week 12: Course Wrap-Up & Presentations
Peer presentations of “secure digital transformation” case studies; reflect on architecture–business alignment; link back to learning outcomes and real-world application.
Apply nowLearning objectives
On successful completion of this module the learner will be able to:
LO1: Critically evaluate enterprise security architectures and cybersecurity frameworks to support defence-in-depth strategies that protect the confidentiality, integrity, and availability of enterprise systems and data.
LO2: Assess the unique challenges and requirements of cloud security compared to traditional IT security, with emphasis on virtualised architectures, service models, and data protection strategies.
LO3: Recommend secure-by-design approaches to secure enterprise architectures by integrating cybersecurity controls, governance principles, and regulatory considerations to support risk-informed business decisions
Apply nowMaking Europe cyber-aware
Our digital world is under constant attack. Master the advanced skills to defend critical data and infrastructure. Become a sought-after expert in one of today’s most vital and in-demand career fields.
Download prospectusFAQs
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.