Shared Responsibility Model

The core of the AWS Shared Responsibility Model: AWS secures the cloud, you secure what's in the cloud.

Many people assume that when they use AWS, AWS handles all the security. In reality, responsibility is split between AWS and the customer. This is called the Shared Responsibility Model.

It is one of the most frequently tested topics on the CLF-C02 exam.

---

 

Think of It Like an Apartment

Imagine you live in an apartment building.

The landlord (AWS) is responsible for the building structure, elevators, shared electrical systems, and the exterior walls. But arranging the furniture inside your unit, locking your front door, and protecting your personal belongings is the tenant's (customer's) job.

Even in the best apartment building, if you leave your front door unlocked, a thief can get in. AWS works the same way.

---

 

The Core Distinction in One Line

AWS responsibility: "Security OF the Cloud"

Customer responsibility: "Security IN the Cloud"

Remember this one line and you can answer the majority of these exam questions.

---

 

What AWS Is Responsible For

AWS protects the cloud infrastructure itself.

Physical data center security (building, power supply, cooling systems) Server hardware and network infrastructure Virtualization layer (hypervisor) Underlying software updates for managed services

AWS data center locations are not even publicly disclosed. Physical security is entirely AWS's domain.

---

 

What the Customer Is Responsible For

Customers must protect what they run on top of the cloud.

Data encryption configuration Operating system security patches (for virtual servers like EC2) Firewall rules (Security Groups, Network ACLs) IAM user accounts and permission management Application code security

!The AWS shared responsibility model

Responsibility Changes Depending on the Service

This is the most important point. The service you choose changes how much you are responsible for.

| Service | Customer Responsibility | AWS Responsibility | |---------|------------------------|-------------------| | Amazon EC2 | OS patching, firewall, apps, data | Physical servers, virtualization layer | | Amazon RDS | Data, user access management | OS patching, DB engine patching, backup infrastructure | | AWS Lambda | Code, data, IAM settings | OS, runtime, all infrastructure | | Amazon S3 | Data, bucket policies, encryption settings | Storage infrastructure, availability |

The core rule: the more AWS manages for you (Lambda, RDS), the less you have to worry about.

---

 

Always the Customer's Responsibility

No matter which service you use, these are always yours to manage:

Classifying and managing your own data IAM user accounts and permission settings Client-side encryption Protecting network traffic

---

 

Always AWS's Responsibility

Physical data centers (buildings, hardware) Global network infrastructure Virtualization layer (hypervisor) management Physical separation between Availability Zones

---

 

Exam Key Points

"Physical data center security" -- always AWS responsibility

"OS patching on EC2" -- customer responsibility (AWS does not manage this for you)

"OS patching on RDS" -- AWS responsibility (it is a managed service)

"Data encryption" -- always customer responsibility

"IAM user and permission management" -- always customer responsibility

"DB engine patching (RDS)" -- AWS responsibility

More managed the service, less the customer is responsible for

"Security OF the cloud = AWS" / "Security IN the cloud = Customer" — this one sentence is the key

Back to blog list