官术网_书友最值得收藏!

Customer security responsibilities

AWS shares security responsibilities with customers for all its offerings. Essentially, the customer is responsible for security of everything that they decide to put in cloud such as data, applications, resources, and so on. So network protection and instance protection for IaaS services and database protection for container services are areas that fall under customer security responsibilities. Let us look at customer security responsibilities for these three categories:

For AWS infrastructure services, the customer is responsible for the following:

  • Customer data
  • Customer application
  • Operating system
  • Network and firewall configuration
  • Customer identity and access management
  • Instance management
  • Data protection (transit, rest, and backup)
  • Ensuring high availability and auto scaling resources

For AWS container services, the customer is responsible for the following:

  • Customer data
  • Network VPC and firewall configuration
  • Customer identity and access management (DB users and table permissions)
  • Ensuring high availability
  • Data protection (transit, rest, and backup)
  • Auto scaling resources

For AWS abstract services, the customer is responsible for the following:

  • Customer data
  • Securing data at rest using your own encryption
  • Customer identity and access management

So essentially when we move from AWS infrastructure services towards AWS abstract services, customer security responsibility is limited to configuration, and operational security is handled by AWS. Moreover, AWS infrastructure services gives you many more options to integrate with on-premises security tools than AWS abstract services.

 All AWS products that are offered as IaaS such as Amazon EC2, Amazon S3, and Amazon VPC are completely under customer control. These services require the customer to configure security parameters for accessing these resources and performing management tasks. For example, for EC2 instances, the customer is responsible for management of the guest operating system including updates and security patches, installation and maintenance of any application software or utilities on the instances, and security group (firewall at the instance level, provided by AWS) configuration for each instance. These are essentially the same security tasks that the customer performs no matter where their servers are located. The following figure depicts customer responsibilities for the AWS shared security responsibilities model:

Figure 9 AWS shared security model - customer responsibilities 

AWS provides a plethora of security services and tools to secure practically any workloads, but the customer has to actually implement the necessary defenses using those security services and tools. 

At the top of the stack lies customer data. AWS recommends that you utilize appropriate safeguards such as encryption to protect data in transit and at rest. Safeguards also include fine-grained access controls to objects, creating and controlling the encryption keys used to encrypt your data, selecting appropriate encryption or tokenization methods, integrity validation, and appropriate retention of data. Customer chooses where to place their data in cloud, meaning they choose geographical location to store their data in cloud. In AWS, this geographical location is known as region, so customer has to choose an AWS region to store their data. Customers are also responsible for securing access to this data. Data is neither replicated to another AWS Region nor moved to other AWS Region unless customer decides to do it. Essentially, customers always own their data and they have full control over encrypting it, storing it at a desired geographical location, moving it to another geographical location or deleting it.

For AWS container services such as Amazon RDS, the customer doesn't need to worry about managing the infrastructure, patch update or installation of any application software. The customer is responsible for securing access to these services using Amazon IAM. The customer is also responsible for enabling Multi-Factor Authentication (MFA) for securing their AWS account access. 

As a customer, you get to decide on security controls that you want to put in place based on the sensitivity of your data and applications. You have complete ownership of your data. You get to choose from a host of tools and services available across networking, encryption, identity and access management, and compliance.

The following table shows a high-level classification of security responsibilities for AWS and the customer:

Table 2 - AWS Security responsibilities classification
主站蜘蛛池模板: 临武县| 靖宇县| 桑日县| 元朗区| 建平县| 平邑县| 什邡市| 石柱| 扎鲁特旗| 海城市| 丰县| 齐齐哈尔市| 叶城县| 根河市| 建德市| 太仆寺旗| 安康市| 阳东县| 咸阳市| 宜宾市| 封开县| 南丹县| 长汀县| 土默特左旗| 耿马| 延川县| 孟津县| 伽师县| 乐清市| 丰顺县| 林周县| 延长县| 林西县| 宁远县| 安塞县| 房山区| 苍山县| 定安县| 双桥区| 阜康市| 靖远县|