The shared responsibility model defines how security duties are divided between cloud service providers and their customers, varying based on the service model in use. Understanding this division is essential when handling sensitive data in cloud environments.
Cloud Security Shared Responsibility
If we're going to be purchasing cloud services, there's some extra considerations around that, especially if we're going to end up with some sensitive data and services in that cloud.
When we're moving services up to the cloud, we're relying on those cloud providers to do security right. We're also relying on ourselves to make sure that we're doing security. We're sharing the responsibility, and we call this a shared responsibility model.
Shared responsibility is just this idea that we are going to be responsible for some of security, and then the service provider is going to be providing a certain level of security with what they have. Maybe they have power — do they have redundant power with that? — they have cooling, they're providing the space, they're providing the processing power, they're providing the networking. They're providing these services and making sure that they're providing them at the level that we need. Then we come on top of that, and we're going to make sure that we have the encryption, or that we are installing the proper software, or that the data that we're storing is secure. There's an element that we're responsible for the security as well.
Some of it depends on which model you have. You've got an on premise model. This means that we're hosting everything internally. We have the whole stack right here that we are in charge of, and we're not relying on anybody else unless we have some sort of managed service provider that's servicing some of this. Essentially we're responsible for everything here.
Then you've got colocation. This is where I'm renting space, so they give us the data center, but the rest of it is really on us. They give us a rack, we go set everything up, and we're responsible for everything else from a security perspective.
Then you have infrastructure as a service. Infrastructure as a service provides quite a bit more. They have the data center, and a lot of times they're providing the network, storage, servers, virtualization. AWS does an amazing job at delivering their infrastructure as a service. Then on top of that, what you do is you choose which OS you want, and you manage the OS and the middleware and the runtime and the data and the application.
Then platform as a service — WordPress hosting would be an example of this. They're doing everything with WordPress, they're managing all of that, up until the point where you have your own data and application. With WordPress, for instance, I've got a hosting site with WordPress and they're managing everything, except that I set up the actual web pages and get the web pages going, and any plugins and stuff that I want to set up after that.
And then you have software as a service, so a SaaS company, which pretty much provides everything, all the support in there, except that you're just uploading the data and you're running everything in their application.
What this does is it draws clearer lines of exactly who is responsible for what. You can see in the red here, this is the cloud hosting provider, who they're responsible for, and the rest of it we're responsible for. Although at times you will see that you do sometimes share kind of half and half responsibility, so it's not always as clear-cut as this. Maybe there are times when, for instance, AWS does share some of the responsibility around the OS and the security of the OS, but then we share the other part of this responsibility here.
Ultimately, from my client's perspective, they want to know that I am managing security correctly, and as part of that they also have a lot of questions about how I'm choosing my vendor and the security levels of my vendor. So I have to do a lot of research to make sure that they're performing security well.
Let's take a look at an example here. Let's say we're working with some sort of cloud service provider, or want to work with some sort of cloud service provider. Maybe it's a SaaS company — SaaS is software as a service — so think of some sort of services up in the cloud. Office 365, Google Drive, Dropbox might be a few examples of this.
In those scenarios that I just gave, we're actually storing data up in the cloud, we're storing data with the SaaS company, and that data could be very sensitive. So we want to evaluate that SaaS company to make sure that they're going to handle our data in a secure manner.
Not only that, but there are times when we open ourselves up for even more risk. Let's say there's some local data that we have that this SaaS company needs to access for us to get the full features of the SaaS, and what we're going to do is maybe open up a hole in our firewall to allow that SaaS company to come in and grab that information. Obviously we'll want to take this evaluation to the next level to make sure that this is going to be a secure company, if you're opening up a portion of our network to this company. So I go through the process of checking news reports, looking at their SOC reports, making sure that they are performing the level of security.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →