A tailored course, built for your situation
Sources and specific examples on hand when peers push back
Confidently defend design choices with traceable reasoning and model implementations
Who this is for
Senior software engineer in regulated financial services contributing to system design and compliance-critical implementations
Who this is not for
Entry-level developers, product managers, or auditors without hands-on implementation responsibility
What you walk away with
- Map APRA CPS 234 requirements directly to AWS and GCP architecture patterns
- Quote specific clause language when justifying data classification approaches
- Reference working implementations that passed internal review
- Navigate peer challenges with confidence using documented decision logs
- Turn defensive conversations into collaborative refinements
The 12 modules (with all 144 chapters)
- What CPS 234 covers
- Three core obligations
- Difference from SOX 404
- Obligation versus recommendation
- Regulator expectations now
- How Schwab teams interpret it
- Security vs availability trade-off
- Clause 3.1 unpacked
- Clause 3.2 in practice
- Clause 3.3 implementation
- Mapping to cloud layers
- Common misreadings
- Four sensitivity levels
- Public data examples
- Internal use only
- Confidential financial data
- Protected information definition
- Encryption by class
- Labeling in GCP
- Labeling in AWS
- Metadata tagging
- Automated discovery
- DLP integration
- Classification audit trail
- Principle of least privilege
- Role-based access
- Project-level boundaries
- Service account hardening
- Access reviews frequency
- Just-in-time access
- Break glass accounts
- Audit logging setup
- Privileged user list
- Multi-factor enforcement
- Service control policies
- Access justification logs
- At-rest encryption scope
- In-transit requirements
- Key management responsibility
- AWS KMS configuration
- GCP Cloud KMS setup
- Customer managed keys
- Auto-rotation policies
- Key access logging
- Data residency impact
- Hybrid key architecture
- TLS version enforcement
- Certificate validation
- 72-hour reporting rule
- Internal detection timeline
- Incident severity tiers
- Escalation to APRA
- Legal team coordination
- Public relations sync
- Forensic data retention
- Tabletop exercise design
- Post-mortem structure
- Regulator-facing summary
- Notification documentation
- Lessons integration
- Vendor due diligence
- Subcontractor oversight
- Cloud provider scope
- Compliance verification
- Audit right to entry
- Right to exit clauses
- Security questionnaire
- Penetration test review
- SOC 2 report analysis
- Contractual obligations
- Ongoing monitoring
- Termination triggers
- VPC design principles
- Private service connect
- Firewall rule hierarchy
- Network segmentation
- Zero trust alignment
- Microsegmentation use
- DNS protection
- DDoS mitigation
- Web application firewall
- API gateway controls
- Rate limiting
- Bot detection
- Evidence types required
- System logs retention
- Configuration snapshots
- Access review records
- Change management logs
- Automated compliance checks
- Terraform state logging
- Drift detection
- Evidence retention period
- Sampling expectations
- Audit pack structure
- Cross-team visibility
- Change advisory board
- Urgent change path
- Peer review process
- Deployment window
- Rollback verification
- Pre-implementation check
- Post-implementation audit
- Version control
- Branch protection rules
- Signed commits
- Automated testing
- Deployment logging
- Developer training
- Security champions
- Code review checklists
- On-call integration
- Bug bounty programs
- Phishing simulation
- Security sprint goals
- Engineering KPIs
- Knowledge sharing
- Incident feedback
- Reward systems
- Leadership visibility
- Compliance as code
- Policy violation alerts
- Configuration drift
- Resource tagging checks
- Unapproved region use
- Public bucket exposure
- IAM policy changes
- Encryption status
- Patch compliance
- Firewall rule updates
- Automated remediation
- Daily compliance report
- Architecture decision records
- Rationale capture
- Trade-off analysis
- Regulatory alignment
- Stakeholder alignment
- Version history
- Approval tracking
- Peer challenge log
- External reference library
- Standard template use
- Storage location
- Searchable indexing
How this maps to your situation
- When designing a new cloud service
- Before a vendor security review
- During internal audit preparation
- After a policy change
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters total)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 2 hours per module, designed to be completed alongside active projects
How this compares to the alternatives
Unlike generic compliance trainings, this course provides concrete mappings from APRA CPS 234 to working cloud architectures, with real examples and defensible decision logs tailored to senior practitioners in financial services.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.