You are viewing a free preview of this lesson.
Subscribe to unlock all 10 lessons in this course and every other course on LearningBro.
Security and compliance on AWS are a shared responsibility between AWS and the customer. This model clearly defines what AWS is responsible for (security of the cloud) and what you are responsible for (security in the cloud). Misunderstanding this boundary is one of the most common causes of security incidents.
┌─────────────────────────────────────────────────────────┐
│ CUSTOMER │
│ Security "IN" the Cloud │
│ │
│ Customer data │
│ Platform, applications, identity & access management │
│ Operating system, network & firewall configuration │
│ Client-side data encryption │
│ Server-side encryption (file system and/or data) │
│ Networking traffic protection (encryption, integrity) │
├─────────────────────────────────────────────────────────┤
│ AWS │
│ Security "OF" the Cloud │
│ │
│ Hardware / AWS Global Infrastructure │
│ Regions, Availability Zones, Edge Locations │
│ Compute, storage, database, networking (hardware) │
│ Software: virtualisation layer, host OS, patching │
│ Physical security of data centres │
└─────────────────────────────────────────────────────────┘
AWS is responsible for the infrastructure that runs all AWS services. This includes:
AWS maintains a vast portfolio of compliance certifications:
| Certification | Scope |
|---|---|
| SOC 1, 2, 3 | Controls over financial reporting and security |
| ISO 27001 | Information security management |
| ISO 27017 | Cloud-specific security controls |
| ISO 27018 | Protection of personal data in the cloud |
| PCI DSS Level 1 | Payment card processing |
| HIPAA | Healthcare data (via BAA) |
| FedRAMP | US government workloads |
| GDPR | EU data protection |
| C5 | German government cloud security |
You can access AWS compliance reports through AWS Artifact.
You are responsible for securing everything you put into or build on top of AWS. The exact scope depends on the service model.
When you use EC2, you take on the most responsibility:
AWS takes on more responsibility:
Minimal customer responsibility:
Subscribe to continue reading
Get full access to this lesson and all 10 lessons in this course.