Cloud Security · Lesson 1 of 5
Whose responsibility is what
Know which half is yours.
Moving to the cloud does not move the security problem, it changes its shape, and the most expensive mistakes come from misunderstanding who is responsible for what.
The shared responsibility model. The provider secures the infrastructure: the buildings, the hardware, the hypervisor, the physical network. You secure everything you put on it: your configuration, your access control, your data, your application, your patching where you run the machines.
Nearly every publicised cloud breach was the customer's half, and usually a configuration error rather than anything sophisticated.
The proportion shifts with the service. Running virtual machines, you own the operating system and its patches. Running a managed database, the provider patches it and you own access and configuration. Running a serverless function, almost everything is theirs except your code and your permissions.
Which means that as you move up that scale you have less to secure and less control, and understanding where a given service sits is what tells you what you are responsible for.
The mistake that produces incidents. Assuming the provider handles it. They secure their infrastructure, and a publicly readable storage bucket, an open database, an over permissioned role and a leaked key are all entirely yours.
And the cloud is not less secure than a server in your office, which is the other common misunderstanding. A well configured cloud environment is considerably more secure than most on premises arrangements, and a badly configured one is reachable by the entire internet within minutes.
For each cloud service you use, write down which half of the responsibility is yours. Most incidents come from assuming it was theirs.
ہر کلاؤڈ سروس کے لیے لکھیں کہ ذمہ داری کا کون سا حصہ آپ کا ہے۔ زیادہ تر واقعات یہی سمجھنے سے ہوتے ہیں کہ یہ ان کا کام تھا۔
Check what you learned
Create your free BvLogic ID to take the quiz and record your score.
Create your BvLogic ID