官术网_书友最值得收藏!

Shared responsibility model for abstract services

The final model we will look at is the abstract shared responsibility model, shown here:

Right away, from a visual perspective, we can see that the shift in responsibility leans even greater toward AWS.

This model retains the level of security AWS has to manage from both the previous two models (infrastructure and container), with the addition of server-side encryption and network traffic protection. Example AWS services that fall within this model are the Amazon Simple Queue Service (SQS), Amazon DynamoDB, and Amazon S3.

These are defined as abstract services as almost all the control and management of the service has been abstracted away from the end customer; we simply access these services through endpoints. Customers do not have access to the underlying operating system (infrastructure) or to the actual platform that is running these services (container); instead, the customer is presented with the service frontend or endpoint to configure as required.

As a result, the customer has been totally abstracted away from having to maintain security updates for the operating system or any platform patches and security management. This also means that AWS now has the responsibility to implement and control any server-side encryption options, such as Amazon S3 Server-Side Encryption (S3-SSE), where the customer has no control over the access keys used for this encryption method; it's all managed by AWS.

Also, AWS will manage the secure transfer of data between the service components—for example, when S3 automatically copies customer data to multiple endpoints across different Availability Zones. As a customer, we have no control over how this data is transferred, and so the traffic has to be secured by AWS.

主站蜘蛛池模板: 金平| 合水县| 会宁县| 定襄县| 福州市| 南平市| 顺昌县| 灵台县| 佛冈县| 安溪县| 盘山县| 萨嘎县| 沂水县| 西乌| 揭阳市| 宁阳县| 兴城市| 罗田县| 咸阳市| 通化县| 桂平市| 宽城| 阜平县| 岳西县| 梁平县| 潼南县| 辰溪县| 玉田县| 称多县| 吐鲁番市| 哈巴河县| 怀来县| 临汾市| 库车县| 台中市| 楚雄市| 天峨县| 开封县| 怀仁县| 阿瓦提县| 监利县|