Ravindra BagaleCourses & study guides

30. Cloud and AWS Security

30.1 The Shared Responsibility Model

AWS explains cloud security with the Shared Responsibility Model:

AWS is responsible for ("security of the cloud") You are responsible for ("security in the cloud")
Data centres, physical security, guards IAM users, passwords, MFA, access keys
Hardware, network cables, hypervisor Security groups and network design
The managed service software itself OS patching on EC2 (sudo yum update)
Global infrastructure availability Encryption choices, S3 bucket permissions
Your application code (OWASP, Chapter 29)

The line moves with the service. On EC2 you patch the OS; on RDS AWS patches the database engine but you still control who can connect; on S3 AWS runs storage but you decide whether a bucket is public.

Ravindra Bagale's Tip

Students think "It's on AWS, so it's safe." Wrong! AWS doesn't make your bucket public – you do. If you read the news about cloud breaches, the cause is usually misconfiguration, not AWS being hacked. Take care of your own side yourself.

Practice task

For your reels app (EC2 + S3 + RDS from Chapter 16), make a two-column table: list five things AWS secures and five things you must secure yourself.