Explanation
According to the AWS Shared Responsibility Model:
- Customer data is ALWAYS the customer's responsibility to manage and secure
- Software licenses - AWS manages infrastructure licenses, but customers are responsible for their application software licenses
- Networking - AWS manages the underlying network infrastructure, but customers configure security groups, VPCs, etc.
- Encryption keys - While customers can manage their own keys, AWS also provides key management services
Key Points:
- AWS Responsibility: Security OF the cloud (infrastructure, hardware, software, facilities)
- Customer Responsibility: Security IN the cloud (customer data, platform/applications, identity/access management)
Customer data is the only item in this list that is unequivocally and always the customer's responsibility under the shared responsibility model.