Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC532 Network and Cloud Security Engineering
This unit equips students to engineer, automate and validate security controls across hybrid, multicloud and containerised environments. Students will design zero-trust network architectures, implement micro-segmentation, integrate “security as code” (IaC) pipelines, and apply cloud-native security frameworks (e.g. AWS Well-Architected, Azure CAF, CIS Benchmarks). Hands-on labs use software-defined networking (SDN) and container networking interfaces (CNI) to harden cloud workloads, while threat-modelling exercises ensure graduates can balance performance, cost and compliance requirements at enterprise scale.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
ITC511 Networking and Systems Security
UNIT LEARNING OUTCOMES
- Critically analyse hybrid and multicloud network architectures to identify security gaps, performance constraints and regulatory obligations
- Design and implement zero-trust and micro-segmentation controls using SDN/CNI and infrastructure-as-code pipelines
- Critically evaluate cloud-native security services and third-party virtual appliances for threat prevention and compliance
- Optimise network-security configurations through continuous validation, automation testing and cost-benefit analysis
- Articulate and justify engineering decisions to technical and non-technical stakeholders
CONTENT
- Hybrid and multicloud reference architectures; shared-responsibility models
- Zero-trust principles; identity-centric segmentation
- Software-defined networking (NSX-T, Azure vNet, AWS VPC); policy automation
- Micro-segmentation with CNI (Calico, Cilium) in Kubernetes clusters
- Infrastructure-as-Code for network security (Terraform, CloudFormation)
- Cloud-native security services & virtual NGFWs
- Threat-modelling hybrid workloads; STRIDE & MITRE Cloud ATT&CK
- Continuous validation: Chaos engineering and automated penetration testing
- Performance-security trade-offs; cost optimisation & sizing
- Compliance frameworks (CIS Benchmarks, PCI-DSS, ASD Essential Eight in cloud)
- Incident response in cloud networks; packet-mirroring and log correlation
- Emerging trends: SASE, service mesh security, post-quantum VPNs
ASSESSMENT METHODS
- Hybrid Threat-Model Report – 20%
- Group IaC Micro-Segmentation Project – 30%
- Zero-Trust Architecture White Paper and Invigilated Presentation – 50%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












