TheCyberNews
Guide

The Shared Responsibility Model

Author: TheCyberNews Editorial
Updated: Recently
v1.0

The Biggest Cloud Myth

A common misconception is: “My data is in the cloud, so it’s the cloud provider’s job to keep it secure.”

This is false. Cloud security operates on a Shared Responsibility Model.

Security OF the Cloud vs. Security IN the Cloud

  • Security OF the Cloud (Provider’s Job): AWS, Microsoft, or Google is responsible for the physical security of the data centers, the hardware, and the network infrastructure that runs the cloud.
  • Security IN the Cloud (Your Job): You are responsible for who you give access to, how you configure your firewalls, encrypting your data, and ensuring your employees use strong passwords.

If a hacker breaks into the physical Amazon data center, that is Amazon’s fault. If you accidentally leave your cloud storage bucket public without a password and a hacker downloads your files, that is your fault.

Knowledge Check

Question 1 of 1

Under the Shared Responsibility Model, who is responsible for managing user passwords and access permissions?

Track your progress

Mark this guide as complete to update your learning roadmap.