Skip to main content
Browser not supported!
We recommend using a modern browser such as Google Chrome, Microsoft Edge, Apple Safari, or Mozilla Firefox.

Submitter's Information

Name

Andrew Long

Title

Dean of Institutional Effectiveness

Region

Inland Empire/Desert

College

Chaffey College

CTE Dean

CTE Dean's Name

Dr. Yolanda Friday

CTE Dean's Email

Log in to view CTE Dean's Email.

Program Details

Program Title

Bachelor of Science in Cloud Computing and Security

Submission Type

New Program

TOPs Code

Computer Infrastructure and Support (070800)

Projected Start Date

01/11/27

Catalog Description

The Bachelor of Science in Cloud Computing & Security prepares students to design, deploy, secure, and manage modern cloud environments. The program blends cloud architecture, containerization, cybersecurity operations, threat analysis, and resilience engineering to build practical, industry‑ready skills. Students learn to protect cloud services, analyze threats, respond to incidents, and implement secure, scalable solutions across hybrid and multi‑cloud infrastructures. A hands‑on capstone showcases their ability to architect and defend resilient cloud systems for real‑world organizational needs.

Enrollment Completer Projections

The program anticipates 30 projected annual completers.

Program Proposal Attributes

Program Award Type(s) (Check all that apply)
  • Baccalaureate of Science (B.S.) Degree
Program Goal

The Program Goals for the Bachelor of Science in Cloud Computing and Security are:

  1. Prepare students for cloud‑focused engineering and technical careers by developing advanced skills in cloud architecture, containerization, automation, and secure infrastructure design.
  1. Develop workforce‑ready professionals who can deploy, monitor, and maintain multi-tenant, resilient, and well-architected cloud environments in enterprise settings.
  1. Cultivate analytical and investigative skills for identifying threats, responding to incidents, and supporting organizational continuity.
  1. Strengthen professional communication and collaboration abilities required for cross‑functional technical teams in modern cloud operations.

Course Units and Hours

Total Certificate Units (Minimum and Maximum)

n/a

Units for Degree Major or Area of Emphasis (Minimum and Maximum)

48 Upper Division, 41-48 Lower Division

Total Units for Degree (Minimum and Maximum)

120-126

Course Report

Program Requirements Narrative

Students completing the Associate of Science Degree in Cloud Solutions Architecture or the Associate of Science Degree in Cybersecurity will be eligible to apply to the Bachelor of Science in Cloud Computing and Security.

Chaffey Course

Chaffey Course Description

Chaffey Course SLOs

Units

ITIS-513 – Legal and Regulatory Frameworks for Cloud Security

This course examines the legal, regulatory, and governance frameworks that shape information technology, cybersecurity, and cloud computing, with emphasis on the laws and policies governing data collection, transmission, storage, and protection across jurisdictions. Students study privacy rights, cloud‑specific cybersecurity regulation, cross‑border data‑transfer requirements, breach‑notification laws, information‑security governance, incident response, and business‑continuity planning. The course also focuses on cloud‑focused compliance and operational governance, including shared‑responsibility legal implications, provider contract requirements, logging and auditing obligations, and real regulatory case analysis. Students evaluate how statutory requirements, industry standards, organizational policies, and emerging cloud technologies intersect to manage risk and ensure compliant cloud operations worldwide.

SLO1: Explain the legal, regulatory, and policy frameworks that govern cloud computing, cybersecurity, and data privacy across organizational and international contexts.
SLO2: Evaluate how cloud technologies, security threats, and organizational practices shape the development and implementation of cybersecurity and data‑protection requirements.
SLO3: Analyze how laws, regulations, industry standards, and governance models manage cybersecurity and cloud‑based data‑transfer risks.
SLO4: Examine the legal, operational, and strategic challenges involved in securing information, cloud services, critical infrastructure, and cross‑tenant environments.
SLO5: Assess strategies for preventing, responding to, and recovering from cybersecurity incidents and cloud‑related disruptions.
SLO6: Evaluate cybersecurity and compliance risks associated with emerging cloud technologies, third‑party service providers, and evolving threat landscapes.

3

ITIS 517 – Cloud Data Analytics

This course explores the principles and practices of data analytics as applied to cloud computing. Students collect, prepare, analyze, and visualize data from cloud platforms and other cloud-based data sources to identify patterns, detect anomalies, and support evidence-based decision making. Topics include data preparation, statistical analysis, data transformation, data visualization, dashboard design, cloud data architectures, and communicating analytical findings. Students also examine the ethical, legal, and societal considerations associated with collecting, analyzing, and interpreting data in cloud environments. This course aligns with Amazon Web Services (AWS) Academy Data Engineering Course.

SLO-1: Analyze cloud datasets using statistical and analytical techniques to identify patterns, trends, and anomalies that support data-driven decision making.
SLO-2: Apply data preparation, transformation, and analytical techniques to solve cloud data analytics problems and support organizational decision making.
SLO-3: Design and create effective visualizations, dashboards, and data stories that communicate analytical findings to technical and non-technical audiences.
SLO-4: Evaluate analytical methods, tools, and technologies used to collect, prepare, analyze, and interpret cloud data.
SLO-5: Assess the ethical, legal, and societal implications of collecting, analyzing, and communicating data in cloud environments.

3

ITIS 580 – Emerging Technology & Cybersecurity

This course is an exploratory study of new, emerging, and developing technologies in cyber defense operations. Emphasis is placed on both operational theory and designing and deploying technological solutions to combat evolving cyber threats. Topics include Zero Trust and Secure Access Service Edge (SASE) architectures, Artificial Intelligence (AI) Introductions using Machine Learning (ML), Networking, 5G networks, and Internet of Things (IoT).

SLO 1: Identify strengths, weaknesses, opportunities, threats and ethical impacts of IoT and  emerging technology.
SLO 2: Explain edge computing and discuss how various aspects and choices in hardware design can affect cost, reliability, and value.
SLO 3: Examine the security architect's role in building a scalable, secure, and enterprise IoT and 6G architecture.
SLO 4: Weigh the importance of AI and future integrations of AI into cybersecurity operations.
SLO 5: Explain the process of machine learning and how it can help cybersecurity systems automatically detect and respond to cyberattacks.
SLO 6: Explain the application of neural networks and major features and components that are offered by cloud providers.
SLO 7: Consider and discuss the concepts and principles of zero trust architecture and its application to enterprise networks that are composed of pre-established devices and components.

3

ITIS- 526 - Cryptography

This course covers the principles of cryptography, with applications to cyber defense. Topics include secret-key, public-key encryption, message integrity, digital signatures, user authentication, key management, cryptographic hashing, public-key infrastructure, and zero-knowledge protocols. Emerging topics may be introduced.

SLO 1. Describe key network security requirements of confidentiality, integrity and availability.                                                 
SLO 2. Understand security services, mechanisms, security threats and attacks.                                                                             SLO 3. Analyze and evaluate symmetric and asymmetric cryptography algorithms.                                                                       SLO 4. Investigate the operation of HASH & MAC functions and digital signatures.                                                                     SLO 5. Discuss new and future developments in cryptography.

3

ITIS-570 - Cloud Architecting &  Containerization

This course aligns with the Amazon Web Services (AWS) Academy curriculum designed to help further develop technical expertise in containerization and cloud computing. Building from the Cloud Computing Foundations level, the course focuses on the knowledge needed to deliver optimized services using best practices and value. Students gain the skills necessary to use and deploy cloud infrastructure, services, compute resources, and containerized workloads using modern containerization technologies. The course prepares students to sit for the AWS Solutions Architect – Associate Certification Exam

SLO-1: Evaluate cloud solution designs against the AWS Well-Architected Framework's five pillars, identifying architectural weaknesses and recommending improvements that balance security, reliability, performance, and cost across IaaS, PaaS, and SaaS deployment models.
 SLO-2: Design scalable, highly available AWS infrastructures by selecting and integrating compute, storage, database, and networking services, including VPCs, Auto Scaling, load balancing, and Multi-AZ deployments, to meet defined organizational requirements.
 SLO-3: Implement identity, access, and data protection controls using AWS IAM, KMS, Secrets Manager, and encryption services, applying least-privilege principles and the Shared Responsibility Model to secure cloud environments against unauthorized access and data exposure.
 SLO-4: Monitor, automate, and optimize cloud operations using AWS management and infrastructure-as-code tools, demonstrating how automation improves operational consistency, reduces risk, and enables scalable governance in enterprise cloud environments.
 SLO-5: Synthesize course competencies by designing and presenting a comprehensive, cost-optimized AWS architecture solution for a realistic organizational scenario, justifying every design decision through written documentation and oral defense aligned to professional industry standards.
 SLO‑6: Deploy and manage containerized applications using Docker and Kubernetes, implementing scalable orchestration, service networking, and automated workload management across cloud and hybrid environments.

3

ITIS 540 – Applied Intrusion Detection & Analysis

This course is a hands-on study of methodologies used to analyze network traffic in order to identify intrusions. Emphasis is placed on the theoretical and practical analysis of network activity to deem if it is noteworthy or a false indication of a breach. Topics include common application protocols, analyzing network behavior to detect breaches, strengths and limitations of intrusion detection systems (IDS) and other monitoring tools in multi-tenant environments as well as visualizing data traffic to identify patterns and anomalies.

SLO 1: Apply cloud infrastructure monitoring tasks and processes while designing scalable, efficient intrusion detection architectures and strategies.
SLO 2: Explain cyber intrusion and describe methods attackers use to compromise cloud connected devices.
SLO 3: Writing, testing, and tuning custom IDS/IPS signatures for engines like Snort or Suricata, with a heavy emphasis on balancing true positive detection against alert fatigue.
SLO 4: Analyze the technique for successfully coupling geospatial intrusion systems (GIS) with traditional security mechanisms.
SLO 5: Apply cloud‑based WAF and IDS/IPS capabilities to detect, block, and analyze malicious traffic, enforce application‑layer security policies, and maintain real‑time threat visibility in hybrid and multi‑cloud environments.
SLO 6: Apply behavioral analysis techniques to spot anomalies in security data and consider when, where, and what action needs to be taken to improve accuracy.
SLO 7: Understand statistical anomalies, machine learning baselines, and threat hunting methodologies

3

ITIS-520 – Deconstructing Malware

This course is a hands-on study of methodologies used to reverse-engineer malicious software (malware). Emphasis is placed on the analytical ability to examine inner workings of malware in the context of forensic investigations, incident response, and systems administration. Topics include data files and browser scripts analysis, fundamental behavioral analysis of memory forensics and malware code, and concepts for reverse engineering common malware. This course provides an in-depth exploration of malicious software analysis, reverse engineering, and threat intelligence extraction. Students will learn how to safely isolate, execute, and deconstruct various forms of malware to understand their architecture, propagation mechanisms, and intent. The curriculum emphasizes a hands-on approach to both static and dynamic analysis using industry-standard debugging and disassembly tools within controlled, air-gapped sandbox environments. By unpacking compiled binaries and analyzing network telemetry, students will develop the critical skills required to extract rapid Indicators of Compromise (IoCs), map behaviors to the MITRE ATT&CK framework, and engineer actionable defensive countermeasures for enterprise systems.

SLO 1: Categorize common types of malware and summarize fundamental approaches to malware analysis.
SLO 2: Test a malware sample in a controlled environment and evaluate its activities, interaction, and effect on the system.
SLO 3: Explain concepts and demonstrate skills required to perform reverse engineering techniques on malware.
SLO 4: Identify and describe tools and techniques used in the disassembly process.
SLO 5: Compare and contrast different malware behaviors, characteristics, and capabilities.
SLO 6: Compare different code injection techniques used by malicious programs to inject and practice executing malicious code within the context of a legitimate process.
SLO 7: Examine and demonstrate the process of memory forensics for malware investigation and illustrate how it may be used in malware analysis.

3

ITIS - 550 - Bug Bounties

This course introduces students to authorized bug bounty and vulnerability research workflows with an emphasis on web and API security testing. Students practice safe testing in controlled lab environments, interpret scope and rules of engagement, validate security weaknesses, reduce false positives, assess risk and impact, and prepare professional vulnerability reports with remediation guidance. The course emphasizes responsible disclosure, evidence collection, ethical testing, secure remediation awareness, and communication with technical stakeholders.

SLO-1: Explain the legal, ethical, and professional responsibilities involved in authorized bug bounty testing, vulnerability disclosure, and rules of engagement.
 SLO-2: Analyze an authorized target scope and develop a safe testing plan that identifies permitted assets, prohibited activity, and documentation requirements.
 SLO-3: Use common application security tools to identify and validate web and API vulnerabilities in controlled lab environments.
 SLO-4: Evaluate vulnerability severity using evidence, exploitability, business impact, and remediation difficulty.
 SLO-5: Write professional vulnerability reports that include evidence, impact, severity, and remediation guidance.

3

ITIS 543 – Disaster Response & Recovery

This project-based course equips students with the planning, analytical, technical, and leadership skills needed to keep an organization operational in the face of cyber threats, natural disasters, and other disruptive events. Students work through the full business continuity and disaster recovery (BC/DR) lifecycle: conducting business impact analyses (BIA), quantifying financial exposure through loss expectancy calculations, developing and testing disaster recovery plans (DRP), and standing up emergency operations procedures. Cloud-based continuity strategies, service level agreements (SLAs), and the regulatory dimensions of BC/DR planning are examined through case studies, tabletop exercises, and written project deliverables. Students graduate with practical experience developing recovery documentation aligned to NIST SP 800-34 and SP 800-184, and are prepared to lead resilience programs in organizations across the public and private sectors.

SLO-1: Conduct a business impact analysis (BIA) for a realistic organizational scenario, identifying mission-critical processes, quantifying financial and operational exposure using SLE, ARO, and ALE calculations, and translating findings into prioritized recovery time and recovery point objectives.
SLO-2: Develop a comprehensive disaster recovery plan (DRP) that integrates risk management frameworks, Emergency Operations Center (EOC) procedures, recovery site strategies, and crisis communication protocols to protect organizational continuity against cyber and physical disruptions.
SLO-3: Evaluate cloud computing service and deployment models as continuity infrastructure, analyzing tradeoffs in availability, data sovereignty, cost, and vendor dependency, and applying cloud-native DR services to design resilient, multi-region recovery architectures.
SLO-4: Analyze contracts and service level agreements (SLAs) with cloud and managed service providers, identifying RTO/RPO commitments, escalation rights, liability provisions, and governance obligations critical to maintaining organizational resilience during disruptions.
SLO-5: Design, document, and present a BCP testing strategy, incorporating tabletop, walkthrough, and simulation test types, and produce a lessons-learned report that drives measurable improvements to the organization's disaster preparedness posture.

3

ITIS 533 – Cyber Threat Intelligence (CTI)

This course provides an applied study of cyber threat intelligence programs and the use of intelligence to support organizational decision making. Students define intelligence requirements, collect and assess threat data, apply analytic frameworks, evaluate threat intelligence platforms, develop threat models, use intrusion analysis to identify adversary behavior, and produce intelligence reports for technical and business stakeholders. Emphasis is placed on proactive and reactive defense, CTI metrics, information sharing, AI-assisted analysis, and ethical considerations in the use and distribution of threat intelligence.

SLO-1: Explain the purpose of cyber threat intelligence and its role in supporting business and security decision-making.
SLO-2: Define intelligence requirements and evaluate threat data sources, frameworks, and collection methods.
SLO-3: Apply analytic tradecraft, threat modeling, and intrusion analysis techniques to assess adversary behavior.
SLO-4: Evaluate CTI platforms, sharing methods, metrics, and reporting practices used in a threat intelligence program.
SLO-5: Assess the ethical and societal impacts of collecting, analyzing, and distributing cyber threat intelligence.

3

ITIS 533 – Advanced Security Implementation & Management

Students in this course build the advanced technical and organizational competencies required to design, oversee, and continuously improve a cloud-based enterprise security program. Drawing on the eight CISSP domains, learners examine how risk management principles drive decisions about asset protection, secure system design, cryptographic controls, and network architecture. Hands-on laboratory activities challenge students to configure identity and access management (IAM) systems, conduct security assessments, and evaluate software development pipelines for security vulnerabilities. Students leave prepared to pursue the CISSP credential and fulfill mid- to senior-level security roles aligned with DoD 8140/8570.01-M workforce requirements. Ethical leadership and the societal responsibilities of security professionals are woven throughout the course.

SLO-1: Construct a risk-based enterprise security program by applying the CIA triad, security governance principles, and asset management practices to design policies, controls, and procedures that protect an organization's cloud environment.
 SLO-2: Design and evaluate secure system architectures, incorporating defense-in-depth, cryptographic solutions, and network security controls, to systematically identify vulnerabilities and reduce organizational exposure across on-premise, cloud, and hybrid environments.
 SLO-3: Implement and audit identity and access management (IAM) systems, applying authentication frameworks, authorization models, and the identity provisioning lifecycle to enforce accountability and protect resources against unauthorized access.
 SLO-4: Plan and execute security assessment and testing engagements, interpret findings against established risk tolerance, and develop prioritized remediation strategies that strengthen security operations across people, processes, and technology.
 SLO-5: Analyze software development security practices and organizational security operations, including logging, monitoring, incident handling, and SDLC security controls, and evaluate how each contributes to a sustainable, enterprise-wide security posture.

4

ITIS 576 – Critical Infrastructure & Supply Chain Protection

This course examines the protection and resilience of critical infrastructure and supply chain operations. Students analyze responsibility across political and organizational boundaries, apply risk analysis methods, examine complex system failures, evaluate sector-specific infrastructure dependencies, categorize cyber threats to critical systems, and develop strategies to improve resilience. The course emphasizes supply chain risk, critical infrastructure sectors, modeling and simulation, policy coordination, resource optimization, and the ethical and societal impacts of protecting essential services.

SLO-1: Analyze responsibility across political, organizational, and public-private boundaries in critical infrastructure and supply chain protection.
SLO-2: Apply risk analysis methods to evaluate critical infrastructure security, resilience, and supply chain dependencies.
SLO-3: Examine complex system failures, infrastructure interdependencies, and environmental factors that affect CIKR systems.
SLO-4: Categorize cyber threats to critical infrastructure and evaluate strategies for improving resilience.
SLO-5: Assess the ethical and societal impacts of critical infrastructure and supply chain protection decisions.

3

ITIS  530 – Systems & Network Auditing

This course develops the knowledge needed to plan, conduct, and report on Information Technology (IT) audit engagements using a risk-based approach. Students learn to evaluate an organization's information systems governance, acquisition and development practices, operational resilience, and information asset protection controls, the five core domains examined by the Certified Information Systems Auditor (CISA) exam. Through case analyses, simulated audit scenarios, and hands-on tool exercises, learners practice gathering evidence, assessing IT general controls, and communicating findings to management and governance bodies. The course integrates ISACA standards, COBIT, and NIST frameworks to ground students in widely recognized audit methodologies. Graduates are positioned to pursue the CISA credential and enter audit, compliance, or IT risk roles aligned with DoD 8140/8570.01-M workforce pathways.

SLO-1: Plan and execute an IT audit engagement using ISACA standards, COBIT, and risk-based methodologies, applying sampling techniques and evidence collection procedures to produce objective, defensible findings for management and governance stakeholders.
SLO-2: Assess IT governance structures and resource management practices, including vendor relationships, human capital allocation, and technology portfolios, to determine how effectively an organization directs and controls IT in support of enterprise objectives.
SLO-3: Evaluate the security and control effectiveness of information systems across their acquisition, development, implementation, and operational lifecycle, identifying gaps that expose the organization to compliance, financial, or operational risk.
SLO-4: Audit business resilience and information asset protection controls, spanning physical security, logical access, network defenses, and backup and recovery procedures, against applicable regulatory frameworks.
SLO-5: Produce and present a complete audit report that communicates findings, risk ratings, and actionable recommendations to both technical and non-technical audiences, demonstrating the professional judgment and ethical independence required of IS auditors.

3

ITIS 573 – Operational Security Architecture

This course prepares students to function as security architects who translate organizational strategy and regulatory requirements into technically sound, scalable security designs. Students learn to model security architectures using accepted frameworks, including SABSA, TOGAF security extensions, and NIST SP 800-160, and apply them to identity and access management, infrastructure, application, and security operations contexts. Governance, risk, and compliance requirements are examined as inputs that shape architectural decisions rather than afterthoughts. Students practice developing architecture documentation, conducting application security reviews, and aligning cloud and on-premise solutions to business continuity and incident response needs. The course prepares graduates for the CISSP-ISSAP concentration and senior architect roles across industries in the Inland Empire and beyond, in alignment with DoD 8140/8570.01-M requirements.

SLO-1: Translate organizational strategy, regulatory requirements, and risk appetite into an executable security architecture, demonstrating how governance, compliance, and business objectives shape technical design decisions across IAM, infrastructure, and application security domains.
 SLO-2: Design and apply enterprise-scale access control and identity architectures, applying least privilege, separation of duties, and identity federation, that balance security requirements with operational usability across on-premise, cloud, and hybrid environments.
 SLO-3: Architect and deploy security operations capabilities, integrating SIEM platforms, network security controls, and incident response workflows, for distributed computing environments including cloud, hybrid, and edge deployments.
 SLO-4: Conduct structured application security reviews using recognized frameworks such as OWASP and STRIDE, identify exploitable vulnerabilities across the SDLC, and develop prioritized remediation strategies aligned to the organization's risk tolerance and architectural constraints.
 SLO-5: Produce comprehensive security architecture documentation, including threat models, architecture diagrams, and design rationale, and present findings to technical and executive audiences, demonstrating the communication and analytical skills required of a senior security architect.

4

ITIS 590 – Architecture Resiliency Capstone

This capstone course uses a pseudo‑production environment where students design and deploy containerized services in a hybrid cloud environment, configure secure infrastructure, and demonstrate their ability to detect, respond to, and recover from disaster‑related or security incident. The project requires students to integrate skills from across the program into a comprehensive real‑world scenario that tests their technical, operational, and incident‑management competencies.

SLO‑1: Design, deploy, and secure an enterprise hybrid‑cloud infrastructure using industry‑standard networking, cloud computing, and cybersecurity technologies.
SLO‑2: Integrate cloud and security concepts from multiple domains to support organizational operations in a pseudo‑production environment.
SLO‑3: Detect, analyze, and investigate incidents using appropriate monitoring, logging, and security analysis tools.
SLO‑4: Respond to, contain, and recover from disaster‑related incidents by restoring affected systems and services, maintaining high availability, and ensuring business continuity.
SLO‑5: Collaborate with peer teams to conduct attestation and validation activities that verify system recovery, effectiveness, and compliance with project requirements.
SLO‑6: Communicate technical findings and recommendations through professional technical writing, documentation, presentations, and post‑incident reports.

4


Program Requirements
CourseTitleUnitsYear/Semester
(Y1 or S1)
ITIS 513Legal and Regulatory Frameworks for Cloud Security3Y3
ITIS 517Cloud Data Analytics3Y3
ITIS 580Emerging Technology and Cybersecurity3Y3
ITIS 526Cryptography3Y3
ITIS 570Cloud Architecting and Containerization3Y3
ITIS 540Applied Intrusion Detection and Analysis3Y3
ITIS 520Deconstructing Malware3Y3
ITIS 550Bug Bounties3Y3
ITIS 543Disaster Response and Recovery3Y4
ITIS 533Cyber Threat Intelligence (CTI)3Y4
ITIS 533Advanced Security Implementation and Management4Y4
ITIS 576Critical Infrastructure and Supply Chain Protection3Y4
ITIS 530Systems and Network Auditing3Y4
ITIS 573Operational Security Architecture4Y4
ITIS 590Architecture Resiliency Capstone4Y4

Inland/Empire Desert Regional Questions

Submission Details

Published at

07/16/26 - 06:04 PM

Status

Submitted

Return to Drafts

Please list the reason(s) for returning "Bachelor of Science in Cloud Computing and Security". to Andrew Long's drafts. This message will be sent to andrew.long@chaffey.edu

Comments, Documents, Voting

Comments

All Comments

No comments to display.