Shared Responsibility Model Flashcards
What controls within the shared responsibility model are AWS responsible for?
Inherited controls: physical and environmental
What controls do customer and AWS share within the shared responsibility model assuming a non managed service?
Patch management:
AWS within infrastructure
Customer OS’ and Apps
Config management:
Customer OS’, DBs and Apps
AWS within infrastructure
Awareness and training:
AWS of it’s employees
Costumer their employees
What security is AWS responsible for as part of a IaaS?
The service foundation:
compute, storage, database, networking
Global infrastructure:
regions, AZs and edge locations
What security is the customer responsible for as part of an IaaS?
Customer data
Platform, Apps, IAM
OS, Network config and Firewall config
Encryption - even with KMS still manage keys
What controls are the responsibility of the customer only?
Service and Communications Protection or Zone Security
Managed services reduce both patch and config management responsibilities for the customer what are the managed services within AWS?
EFS, FSx, RDS, Aurora, ElastiCache, DynamoDB, DocumentDB, QLDB, Managed Blockchain, Glue, Batch, Lambda, Elastic Beanstalk, Code services, Route 53, Outpost, SQS, Kinesis, MQ
What responsibilities become AWS’ responsibility as part of a PaaS?
Platform and OS
What responsibilities become AWS’ responsibility as part of a SaaS?
Platform, OS and Apps