- AWS Certified Security:Specialty Exam Guide
- Stuart Scott
- 282字
- 2021-06-11 18:13:15
Shared responsibility model for abstract services
The final model we will look at is the abstract shared responsibility model, shown here:

Right away, from a visual perspective, we can see that the shift in responsibility leans even greater toward AWS.
This model retains the level of security AWS has to manage from both the previous two models (infrastructure and container), with the addition of server-side encryption and network traffic protection. Example AWS services that fall within this model are the Amazon Simple Queue Service (SQS), Amazon DynamoDB, and Amazon S3.
These are defined as abstract services as almost all the control and management of the service has been abstracted away from the end customer; we simply access these services through endpoints. Customers do not have access to the underlying operating system (infrastructure) or to the actual platform that is running these services (container); instead, the customer is presented with the service frontend or endpoint to configure as required.
As a result, the customer has been totally abstracted away from having to maintain security updates for the operating system or any platform patches and security management. This also means that AWS now has the responsibility to implement and control any server-side encryption options, such as Amazon S3 Server-Side Encryption (S3-SSE), where the customer has no control over the access keys used for this encryption method; it's all managed by AWS.
Also, AWS will manage the secure transfer of data between the service components—for example, when S3 automatically copies customer data to multiple endpoints across different Availability Zones. As a customer, we have no control over how this data is transferred, and so the traffic has to be secured by AWS.
- 特種木馬防御與檢測技術(shù)研究
- Enterprise Cloud Security and Governance
- 代碼審計(jì):企業(yè)級Web代碼安全架構(gòu)
- 同態(tài)密碼學(xué)原理及算法
- 防火墻技術(shù)與應(yīng)用(第2版)
- 從0到1:CTFer成長之路
- 云原生安全與DevOps保障
- Kerberos域網(wǎng)絡(luò)安全從入門到精通
- 解密數(shù)據(jù)恢復(fù)
- 信息安全導(dǎo)論(第2版)
- 先進(jìn)云安全研究與實(shí)踐
- 網(wǎng)絡(luò)關(guān)鍵設(shè)備安全檢測實(shí)施指南
- 信息安全工程與實(shí)踐
- Bug Bounty Hunting Essentials
- 網(wǎng)絡(luò)安全實(shí)戰(zhàn)詳解(企業(yè)專供版)