The cloud’s shared security responsibility model
As the cloud is becoming the norm and many organizations are moving their workload to a public cloud such as AWS, GCP, and Azure, the customer needs to understand the cloud security model.
Security in the cloud is a joint effort between the customer and the cloud provider.
Customers are responsible for what they implement using cloud services and the applications connected to the cloud. In the cloud, customer responsibility for application security depends upon the cloud provider they are using and the complexity of their system.
The following diagram illustrates a cloud security model from one of the largest public cloud providers (AWS), and it’s pretty much applicable to any public cloud provider, such as Azure, GCP, Oracle, IBM, and Alibaba:
Figure 7.11: AWS Cloud shared security responsibility model
The customer handles the security in the cloud, which includes the following:
- Server...