Cross-Domain & Regulated Cloud
The cleared-world cloud skill set — DoD Impact Levels & data classification, Cross-Domain Solutions (guards, data diodes), FedRAMP / DoD SRG / RMF & ATO, and government cloud (AWS GovCloud, Secret/Top-Secret regions). Concept decks + a practice exam + browser-graded AWS policy-guardrail drills.
Flashcard decks
6 decks · 84 cards · in study order1Cross-Domain & Regulated Cloud — Big PictureThe synthesis deck: how impact levels, classification, CDS, compliance, and government cloud fit together — the mappings, the decision guides, and the throughlines that connect the cleared-world cloud skill set.102Impact Levels & Data ClassificationHow the U.S. government labels sensitivity and picks a hosting bar: DoD Cloud SRG Impact Levels (IL2/4/5/6), FedRAMP Low/Moderate/High, FIPS 199 categorization, CUI, the classification levels (U/C/S/TS/SCI), and the NIPR/SIPR/JWICS networks.163Regulated & Government CloudWhere regulated workloads actually run: AWS GovCloud and the AWS Secret/Top-Secret regions, Azure Government (incl. Secret/Top Secret), Google Assured Workloads, FIPS 140-2/3 validated crypto, ITAR/EAR export control, and data-sovereignty / U.S.-person requirements.144Compliance & RMF (FedRAMP, DoD SRG, ATO)How systems get permission to operate: the NIST Risk Management Framework (RMF) steps, ATO / POA&M / cATO, FedRAMP's authorization path (3PAO, JAB vs Agency), the DoD Cloud SRG, and the control families — NIST 800-53, 800-171, and CMMC 2.0.155Networks, Enclaves & Zero TrustThe separation models behind it all: air gaps and enclaves, the classic MAC models (Bell-LaPadula for confidentiality, Biba for integrity), least privilege and need-to-know, and the DoD Zero Trust shift from perimeter defense to 'never trust, always verify'.146Cross-Domain Solutions (CDS)The controlled bridges between security domains: what a CDS is, Access vs Transfer CDS, guards, data diodes / unidirectional gateways, the high-to-low vs low-to-high directions, NSA 'Raise the Bar' + NCDSMO, filtering/dirty-word inspection, and spillage.15
Practice exams
1 setCloud guardrail drills
6 drillsCurated resources
verified July 2026This is a docs-heavy domain of official government standards — polished video courses are genuinely thin, so none were padded in. Read the primary sources; they are the real curriculum.
Frameworks & standards (NIST / FIPS)
NIST SP 800-37 Rev. 2 — Risk Management Framework (RMF)free · officialThe authoritative 7-step RMF process behind ATO, POA&M, and continuous/cATO authorization for federal and DoD systems.NIST SP 800-53 Rev. 5 — Security and Privacy Controlsfree · officialThe master control catalog that FedRAMP and the DoD SRG baselines are built from, across 20 control families.NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systemsfree · officialThe CUI protection requirements that form the technical basis of CMMC Level 2 assessments for defense contractors.FIPS 199 — Standards for Security Categorizationfree · officialDefines the Low/Moderate/High categorization of C-I-A that drives every downstream control baseline (the high-water mark).FIPS 140-3 — Security Requirements for Cryptographic Modulesfree · officialThe validation standard for cryptographic modules required in GovCloud and other regulated federal environments.
Compliance programs & data handling
FedRAMP — Official Program Site & MarketplaceofficialThe government-wide program authorizing cloud services, with a marketplace of authorized offerings and current program rules.AWS DoD SRG Compliance (Impact Levels IL2/4/5/6)official docsThe clearest verified mapping of DoD Cloud SRG Impact Levels to real regions, including GovCloud and the Secret region.NARA CUI Program & RegistryofficialThe executive-branch authority on Controlled Unclassified Information marking, categories, and the government-wide CUI Registry.