According to the AWS Shared Responsibility Model:
- A. Password Policies - Managed by AWS customers
- B. User permissions - Managed by AWS customers
- C. Physical security - Managed by AWS (infrastructure security)
- D. Disk disposal - Managed by AWS (hardware lifecycle management)
- E. Hardware patching - Managed by AWS (infrastructure maintenance)
AWS customers are responsible for security IN the cloud, including:
- Customer data
- Platform, applications, identity and access management
- Operating system, network and firewall configuration
- Client-side data encryption and data integrity authentication
- Server-side encryption (file system and/or data)
- Network traffic protection (encryption, integrity, identity)
AWS is responsible for security OF the cloud, including:
- Compute, storage, database, and networking
- Hardware/AWS global infrastructure
- Software (host operating system and virtualization)
- Physical security of data centers