← All 186 courses
SEC-104 Security

Zero Trust & Secure Network Design

Move from perimeter thinking to verified-every-time: zero-trust principles translated into concrete segmentation, identity-aware access, encrypted transport everywhere, and policy enforcement points — applied by redesigning a flat legacy network into a defensible architecture.

B3Practitioner
5modules
34skill atoms
7role journeys
Curriculum

What this course covers.

5 modules, 34 named skill atoms. Expand any module to see them.

1Zero-Trust Principles7 skill atoms
never trust, always verifyblast-radius thinkingNIST 800-207 tenetspolicy decision vs enforcement pointscontinuous verificationassume-breach postureimplicit-trust removal
2Segmentation Strategy7 skill atoms
macro/micro segmentationeast-west controlflow discovery before enforcementdefault-deny rollout sequencingVLAN vs identity-based segmentationsegment ownership modelbrownfield exception handling
3Identity-Aware Access7 skill atoms
per-request authdevice posture conceptsidentity-aware proxy patternsVPN to ZTNA migrationconditional-access signalsservice-to-service mTLS identitystep-up authentication
4Encrypted Everywhere7 skill atoms
TLS/mTLS coverageinspection trade-offsservice-mesh mTLS rollouttermination point placementcertificate distribution at scaleencrypted DNS considerationsvisibility loss vs confidentiality
5Redesign Capstone6 skill atoms
flat network → zero-trust target architecturecurrent-state flow mappingenforcement point placementphased migration sequencingfailure-mode walkthroughpeer design defense
Where it fits

SEC-104 in the role journeys.

This course appears in 7 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Cloud Network Engineer

Practitioner stage
CL-213SEC-104CL-301

Security Engineer

Practitioner stage
SEC-106SEC-104SEC-201

Cloud Security Engineer

Practitioner stage
SEC-204SEC-104SEC-205

IAM Engineer

Practitioner stage
SEC-101SEC-104SEC-207

GRC / Compliance Analyst

Practitioner stage
SEC-504SEC-104SEC-210

Cryptography / PQC Engineer

Practitioner stage
SEC-106SEC-104SEC-306

OT / ICS Security Engineer

Practitioner stage
SEC-105SEC-104SEC-406

Roles this course serves

The capability ladder

This course is authored to band B3.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-104 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free