Skip to Section
Submitter's Information
Andrew Long
Dean of Institutional Effectiveness
Inland Empire/Desert
Chaffey College
CTE Dean
Dr. Yolanda Friday
Log in to view CTE Dean's Email.
Program Details
Bachelor of Science in Cloud Computing and Security
New Program
Computer Infrastructure and Support (070800)
01/11/27
The Bachelor of Science in Cloud Computing & Security prepares students to design, deploy, secure, and manage modern cloud environments. The program blends cloud architecture, containerization, cybersecurity operations, threat analysis, and resilience engineering to build practical, industry‑ready skills. Students learn to protect cloud services, analyze threats, respond to incidents, and implement secure, scalable solutions across hybrid and multi‑cloud infrastructures. A hands‑on capstone showcases their ability to architect and defend resilient cloud systems for real‑world organizational needs.
The program anticipates 30 projected annual completers.
Program Proposal Attributes
- Baccalaureate of Science (B.S.) Degree
The Program Goals for the Bachelor of Science in Cloud Computing and Security are:
- Prepare students for cloud‑focused engineering and technical careers by developing advanced skills in cloud architecture, containerization, automation, and secure infrastructure design.
- Develop workforce‑ready professionals who can deploy, monitor, and maintain multi-tenant, resilient, and well-architected cloud environments in enterprise settings.
- Cultivate analytical and investigative skills for identifying threats, responding to incidents, and supporting organizational continuity.
- Strengthen professional communication and collaboration abilities required for cross‑functional technical teams in modern cloud operations.
Course Units and Hours
n/a
48 Upper Division, 41-48 Lower Division
120-126
Course Report
Students completing the Associate of Science Degree in Cloud Solutions Architecture or the Associate of Science Degree in Cybersecurity will be eligible to apply to the Bachelor of Science in Cloud Computing and Security.
Chaffey Course | Chaffey Course Description | Chaffey Course SLOs | Units |
ITIS-513 – Legal and Regulatory Frameworks for Cloud Security | This course examines the legal, regulatory, and governance frameworks that shape information technology, cybersecurity, and cloud computing, with emphasis on the laws and policies governing data collection, transmission, storage, and protection across jurisdictions. Students study privacy rights, cloud‑specific cybersecurity regulation, cross‑border data‑transfer requirements, breach‑notification laws, information‑security governance, incident response, and business‑continuity planning. The course also focuses on cloud‑focused compliance and operational governance, including shared‑responsibility legal implications, provider contract requirements, logging and auditing obligations, and real regulatory case analysis. Students evaluate how statutory requirements, industry standards, organizational policies, and emerging cloud technologies intersect to manage risk and ensure compliant cloud operations worldwide. | SLO1: Explain the legal, regulatory, and policy frameworks that govern cloud computing, cybersecurity, and data privacy across organizational and international contexts. | 3 |
ITIS 517 – Cloud Data Analytics | This course explores the principles and practices of data analytics as applied to cloud computing. Students collect, prepare, analyze, and visualize data from cloud platforms and other cloud-based data sources to identify patterns, detect anomalies, and support evidence-based decision making. Topics include data preparation, statistical analysis, data transformation, data visualization, dashboard design, cloud data architectures, and communicating analytical findings. Students also examine the ethical, legal, and societal considerations associated with collecting, analyzing, and interpreting data in cloud environments. This course aligns with Amazon Web Services (AWS) Academy Data Engineering Course. | SLO-1: Analyze cloud datasets using statistical and analytical techniques to identify patterns, trends, and anomalies that support data-driven decision making. | 3 |
ITIS 580 – Emerging Technology & Cybersecurity | This course is an exploratory study of new, emerging, and developing technologies in cyber defense operations. Emphasis is placed on both operational theory and designing and deploying technological solutions to combat evolving cyber threats. Topics include Zero Trust and Secure Access Service Edge (SASE) architectures, Artificial Intelligence (AI) Introductions using Machine Learning (ML), Networking, 5G networks, and Internet of Things (IoT). | SLO 1: Identify strengths, weaknesses, opportunities, threats and ethical impacts of IoT and emerging technology. | 3 |
ITIS- 526 - Cryptography | This course covers the principles of cryptography, with applications to cyber defense. Topics include secret-key, public-key encryption, message integrity, digital signatures, user authentication, key management, cryptographic hashing, public-key infrastructure, and zero-knowledge protocols. Emerging topics may be introduced. | SLO 1. Describe key network security requirements of confidentiality, integrity and availability. | 3 |
ITIS-570 - Cloud Architecting & Containerization | This course aligns with the Amazon Web Services (AWS) Academy curriculum designed to help further develop technical expertise in containerization and cloud computing. Building from the Cloud Computing Foundations level, the course focuses on the knowledge needed to deliver optimized services using best practices and value. Students gain the skills necessary to use and deploy cloud infrastructure, services, compute resources, and containerized workloads using modern containerization technologies. The course prepares students to sit for the AWS Solutions Architect – Associate Certification Exam | SLO-1: Evaluate cloud solution designs against the AWS Well-Architected Framework's five pillars, identifying architectural weaknesses and recommending improvements that balance security, reliability, performance, and cost across IaaS, PaaS, and SaaS deployment models. | 3 |
ITIS 540 – Applied Intrusion Detection & Analysis | This course is a hands-on study of methodologies used to analyze network traffic in order to identify intrusions. Emphasis is placed on the theoretical and practical analysis of network activity to deem if it is noteworthy or a false indication of a breach. Topics include common application protocols, analyzing network behavior to detect breaches, strengths and limitations of intrusion detection systems (IDS) and other monitoring tools in multi-tenant environments as well as visualizing data traffic to identify patterns and anomalies. | SLO 1: Apply cloud infrastructure monitoring tasks and processes while designing scalable, efficient intrusion detection architectures and strategies. | 3 |
ITIS-520 – Deconstructing Malware | This course is a hands-on study of methodologies used to reverse-engineer malicious software (malware). Emphasis is placed on the analytical ability to examine inner workings of malware in the context of forensic investigations, incident response, and systems administration. Topics include data files and browser scripts analysis, fundamental behavioral analysis of memory forensics and malware code, and concepts for reverse engineering common malware. This course provides an in-depth exploration of malicious software analysis, reverse engineering, and threat intelligence extraction. Students will learn how to safely isolate, execute, and deconstruct various forms of malware to understand their architecture, propagation mechanisms, and intent. The curriculum emphasizes a hands-on approach to both static and dynamic analysis using industry-standard debugging and disassembly tools within controlled, air-gapped sandbox environments. By unpacking compiled binaries and analyzing network telemetry, students will develop the critical skills required to extract rapid Indicators of Compromise (IoCs), map behaviors to the MITRE ATT&CK framework, and engineer actionable defensive countermeasures for enterprise systems. | SLO 1: Categorize common types of malware and summarize fundamental approaches to malware analysis. | 3 |
ITIS - 550 - Bug Bounties | This course introduces students to authorized bug bounty and vulnerability research workflows with an emphasis on web and API security testing. Students practice safe testing in controlled lab environments, interpret scope and rules of engagement, validate security weaknesses, reduce false positives, assess risk and impact, and prepare professional vulnerability reports with remediation guidance. The course emphasizes responsible disclosure, evidence collection, ethical testing, secure remediation awareness, and communication with technical stakeholders. | SLO-1: Explain the legal, ethical, and professional responsibilities involved in authorized bug bounty testing, vulnerability disclosure, and rules of engagement. | 3 |
ITIS 543 – Disaster Response & Recovery | This project-based course equips students with the planning, analytical, technical, and leadership skills needed to keep an organization operational in the face of cyber threats, natural disasters, and other disruptive events. Students work through the full business continuity and disaster recovery (BC/DR) lifecycle: conducting business impact analyses (BIA), quantifying financial exposure through loss expectancy calculations, developing and testing disaster recovery plans (DRP), and standing up emergency operations procedures. Cloud-based continuity strategies, service level agreements (SLAs), and the regulatory dimensions of BC/DR planning are examined through case studies, tabletop exercises, and written project deliverables. Students graduate with practical experience developing recovery documentation aligned to NIST SP 800-34 and SP 800-184, and are prepared to lead resilience programs in organizations across the public and private sectors. | SLO-1: Conduct a business impact analysis (BIA) for a realistic organizational scenario, identifying mission-critical processes, quantifying financial and operational exposure using SLE, ARO, and ALE calculations, and translating findings into prioritized recovery time and recovery point objectives. | 3 |
ITIS 533 – Cyber Threat Intelligence (CTI) | This course provides an applied study of cyber threat intelligence programs and the use of intelligence to support organizational decision making. Students define intelligence requirements, collect and assess threat data, apply analytic frameworks, evaluate threat intelligence platforms, develop threat models, use intrusion analysis to identify adversary behavior, and produce intelligence reports for technical and business stakeholders. Emphasis is placed on proactive and reactive defense, CTI metrics, information sharing, AI-assisted analysis, and ethical considerations in the use and distribution of threat intelligence. | SLO-1: Explain the purpose of cyber threat intelligence and its role in supporting business and security decision-making. | 3 |
ITIS 533 – Advanced Security Implementation & Management | Students in this course build the advanced technical and organizational competencies required to design, oversee, and continuously improve a cloud-based enterprise security program. Drawing on the eight CISSP domains, learners examine how risk management principles drive decisions about asset protection, secure system design, cryptographic controls, and network architecture. Hands-on laboratory activities challenge students to configure identity and access management (IAM) systems, conduct security assessments, and evaluate software development pipelines for security vulnerabilities. Students leave prepared to pursue the CISSP credential and fulfill mid- to senior-level security roles aligned with DoD 8140/8570.01-M workforce requirements. Ethical leadership and the societal responsibilities of security professionals are woven throughout the course. | SLO-1: Construct a risk-based enterprise security program by applying the CIA triad, security governance principles, and asset management practices to design policies, controls, and procedures that protect an organization's cloud environment. | 4 |
ITIS 576 – Critical Infrastructure & Supply Chain Protection | This course examines the protection and resilience of critical infrastructure and supply chain operations. Students analyze responsibility across political and organizational boundaries, apply risk analysis methods, examine complex system failures, evaluate sector-specific infrastructure dependencies, categorize cyber threats to critical systems, and develop strategies to improve resilience. The course emphasizes supply chain risk, critical infrastructure sectors, modeling and simulation, policy coordination, resource optimization, and the ethical and societal impacts of protecting essential services. | SLO-1: Analyze responsibility across political, organizational, and public-private boundaries in critical infrastructure and supply chain protection. | 3 |
ITIS 530 – Systems & Network Auditing | This course develops the knowledge needed to plan, conduct, and report on Information Technology (IT) audit engagements using a risk-based approach. Students learn to evaluate an organization's information systems governance, acquisition and development practices, operational resilience, and information asset protection controls, the five core domains examined by the Certified Information Systems Auditor (CISA) exam. Through case analyses, simulated audit scenarios, and hands-on tool exercises, learners practice gathering evidence, assessing IT general controls, and communicating findings to management and governance bodies. The course integrates ISACA standards, COBIT, and NIST frameworks to ground students in widely recognized audit methodologies. Graduates are positioned to pursue the CISA credential and enter audit, compliance, or IT risk roles aligned with DoD 8140/8570.01-M workforce pathways. | SLO-1: Plan and execute an IT audit engagement using ISACA standards, COBIT, and risk-based methodologies, applying sampling techniques and evidence collection procedures to produce objective, defensible findings for management and governance stakeholders. | 3 |
ITIS 573 – Operational Security Architecture | This course prepares students to function as security architects who translate organizational strategy and regulatory requirements into technically sound, scalable security designs. Students learn to model security architectures using accepted frameworks, including SABSA, TOGAF security extensions, and NIST SP 800-160, and apply them to identity and access management, infrastructure, application, and security operations contexts. Governance, risk, and compliance requirements are examined as inputs that shape architectural decisions rather than afterthoughts. Students practice developing architecture documentation, conducting application security reviews, and aligning cloud and on-premise solutions to business continuity and incident response needs. The course prepares graduates for the CISSP-ISSAP concentration and senior architect roles across industries in the Inland Empire and beyond, in alignment with DoD 8140/8570.01-M requirements. | SLO-1: Translate organizational strategy, regulatory requirements, and risk appetite into an executable security architecture, demonstrating how governance, compliance, and business objectives shape technical design decisions across IAM, infrastructure, and application security domains. | 4 |
ITIS 590 – Architecture Resiliency Capstone | This capstone course uses a pseudo‑production environment where students design and deploy containerized services in a hybrid cloud environment, configure secure infrastructure, and demonstrate their ability to detect, respond to, and recover from disaster‑related or security incident. The project requires students to integrate skills from across the program into a comprehensive real‑world scenario that tests their technical, operational, and incident‑management competencies. | SLO‑1: Design, deploy, and secure an enterprise hybrid‑cloud infrastructure using industry‑standard networking, cloud computing, and cybersecurity technologies. | 4 |
| Course | Title | Units | Year/Semester (Y1 or S1) |
|---|---|---|---|
| ITIS 513 | Legal and Regulatory Frameworks for Cloud Security | 3 | Y3 |
| ITIS 517 | Cloud Data Analytics | 3 | Y3 |
| ITIS 580 | Emerging Technology and Cybersecurity | 3 | Y3 |
| ITIS 526 | Cryptography | 3 | Y3 |
| ITIS 570 | Cloud Architecting and Containerization | 3 | Y3 |
| ITIS 540 | Applied Intrusion Detection and Analysis | 3 | Y3 |
| ITIS 520 | Deconstructing Malware | 3 | Y3 |
| ITIS 550 | Bug Bounties | 3 | Y3 |
| ITIS 543 | Disaster Response and Recovery | 3 | Y4 |
| ITIS 533 | Cyber Threat Intelligence (CTI) | 3 | Y4 |
| ITIS 533 | Advanced Security Implementation and Management | 4 | Y4 |
| ITIS 576 | Critical Infrastructure and Supply Chain Protection | 3 | Y4 |
| ITIS 530 | Systems and Network Auditing | 3 | Y4 |
| ITIS 573 | Operational Security Architecture | 4 | Y4 |
| ITIS 590 | Architecture Resiliency Capstone | 4 | Y4 |
Supporting Documents
Inland/Empire Desert Regional Questions
Submission Details
07/16/26 - 06:04 PM
Submitted
Return to Drafts
Please list the reason(s) for returning "Bachelor of Science in Cloud Computing and Security". to Andrew Long's drafts. This message will be sent to andrew.long@chaffey.edu
Comments, Documents, Voting
Comments
All Comments
No comments to display.