30.1 The Shared Responsibility Model
AWS explains cloud security with the Shared Responsibility Model:
| AWS is responsible for ("security of the cloud") | You are responsible for ("security in the cloud") |
|---|---|
| Data centres, physical security, guards | IAM users, passwords, MFA, access keys |
| Hardware, network cables, hypervisor | Security groups and network design |
| The managed service software itself | OS patching on EC2 (sudo yum update) |
| Global infrastructure availability | Encryption choices, S3 bucket permissions |
| Your application code (OWASP, Chapter 29) |
The line moves with the service. On EC2 you patch the OS; on RDS AWS patches the database engine but you still control who can connect; on S3 AWS runs storage but you decide whether a bucket is public.
Ravindra Bagale's Tip
Students think "It's on AWS, so it's safe." Wrong! AWS doesn't make your bucket public – you do. If you read the news about cloud breaches, the cause is usually misconfiguration, not AWS being hacked. Take care of your own side yourself.
Ravindra Bagale's Tip – मराठी
Students ना वाटते "AWS वर आहे म्हणजे safe आहे". चूक! AWS तुमचा bucket public करत नाही – तुम्ही करता. Cloud breach च्या बातम्या वाचल्या तर बहुतेक वेळा कारण misconfiguration असते, AWS hack नाही. तुमची बाजू तुम्हीच सांभाळा.
Ravindra Bagale's Tip – हिंदी
Students को लगता है "AWS पर है मतलब safe है". गलत! AWS आपका bucket public नहीं करता – आप करते हो. Cloud breach की खबरें पढ़ो तो ज़्यादातर वजह misconfiguration होती है, AWS hack नहीं. अपनी तरफ़ की ज़िम्मेदारी खुद संभालो.
Practice task
For your reels app (EC2 + S3 + RDS from Chapter 16), make a two-column table: list five things AWS secures and five things you must secure yourself.