← All 186 courses
SEC-506 Security

Sovereign Cloud & Data Residency Architecture

Design for jurisdictions, not just regions: residency-driven data splits, sovereign PII handling with proven-not-asserted location guarantees, semantic-cache and AI-service governance under residency rules, and live regulator-style sampling — modeled on our GovServe-class capstone scenarios.

B5Advanced
5modules
35skill atoms
4role journeys
Curriculum

What this course covers.

5 modules, 35 named skill atoms. Expand any module to see them.

1Sovereignty Requirements7 skill atoms
residency vs sovereigntylegal driversdata, operational & technical sovereignty layersforeign lawful-access exposuresovereign region and trusted-partner cloud modelssector mandates for government workloadseliciting requirements from legal counsel
2Split Architectures7 skill atoms
PII partitioningcross-border data flowsin-region data plane with global control planetokenisation keeping identifiers localdisaster recovery inside the jurisdictionlatency & consistency cost of the splitdegraded-mode behaviour on region loss
3Prove, Don't Assert7 skill atoms
residency evidencesampling interfacesper-record location attestationimmutable audit trail of data movementregulator-facing sampling query interfacetesting control effectiveness rather than asserting policycontinuous residency monitoring
4AI Under Residency7 skill atoms
prompt-logging policycache governance memoin-region model endpoint selection & fallback rulesprompt and completion retention limitssemantic cache tenancy boundariesembeddings treated as personal datacontractual controls on vendor training use
5Regulator Simulation7 skill atoms
live sampling drillfindings remediationproducing lineage for a named record on requestresponding within a fixed time boxhandling an unprovable claim honestlyremediation plan with owners and datesclosure evidence and re-test
Where it fits

SEC-506 in the role journeys.

This course appears in 4 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Cloud / Solutions Architect

Capstone stage
CL-321SEC-506journey complete

Cloud Security Engineer

Capstone stage
SEC-302SEC-506journey complete

GRC / Compliance Analyst

Capstone stage
SEC-307SEC-506SEC-509

Enterprise Architect

Capstone stage
AI-503SEC-506CL-503

Roles this course serves

The capability ladder

This course is authored to band B5.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-506 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free