The AWS Shared Responsibility Model

Back
The AWS Shared Responsibility Model
The AWS Shared Responsibility Model

By CloudDog, Created on 03/03/2023

The AWS shared responsibility model is an approach that defines the responsibilities of AWS and its customers in protecting resources and data in the cloud. This model is designed to ensure that security in the cloud is a responsibility shared between AWS and its customers.

According to this model, AWS is responsible for the security of the underlying infrastructure that supports the cloud services, including the physical security of the data centers, network security, and hardware security. AWS also offers security tools and services to help customers protect their data and resources in the cloud, such as AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), and AWS CloudTrail.

On the other hand, AWS customers are responsible for ensuring the security of their own workloads, data, and applications in the cloud. This includes correctly configuring access permissions, protecting sensitive data, applying security patches, and implementing appropriate security controls.

The AWS shared responsibility model establishes a balance of responsibility between AWS and its customers to ensure that resources and data in the cloud are protected in an adequate and secure way.

Check out some examples:

  1. Infrastructure security: AWS is responsible for the physical security of the data centers, network security, and hardware security. This includes protection against unauthorized access, threat monitoring, and the implementation of security controls to ensure the integrity of data and resources in the cloud.
  2. Operating system security: When customers use AWS instance services (such as EC2 or Lightsail), they are responsible for ensuring that the operating system and applications are up to date with the latest security patches. AWS provides virtual machine images with default security configurations, but it is the customer’s responsibility to configure and maintain their own images.
  3. Identity and access management: AWS provides identity and access management services, such as IAM, to allow customers to control access to their resources in the cloud. It is the customer’s responsibility to define the correct access policies and grant access only to authorized users or services.
  4. Data protection: AWS customers are responsible for protecting their own data in the cloud. AWS provides encryption services, such as KMS, to help customers protect their data, but it is the customer’s responsibility to manage the encryption keys and define the correct security policies to protect their data.
  5. Regulatory compliance: AWS is responsible for ensuring that its infrastructure meets various security regulations, such as HIPAA or PCI-DSS. However, it is the customer’s responsibility to ensure that their own applications and workloads are compliant with these regulations.

In summary, the AWS shared responsibility model is applied in various ways in practice, requiring AWS and its customers to work together to ensure the security and protection of data in the cloud.

Tags

#aws #segurança #na #nuvem #responsabilidade #do #cliente #responsabilidade #da #aws

About the author

CloudDog

CloudDog is a consultancy specialized in cloud computing and an AWS partner that helps companies migrate, modernize, manage, and optimize their cloud environments. With more than 400 projects delivered, we combine technical expertise, governance, and innovation to accelerate our clients’ digital transformation through solutions in infrastructure, security, observability, artificial intelligence, and managed services.

Comments

WhatsApp