{"id":3082,"date":"2019-08-31T11:45:36","date_gmt":"2019-08-31T11:45:36","guid":{"rendered":"https:\/\/www.testpreptraining.com\/tutorial\/?page_id=3082"},"modified":"2020-05-01T11:35:24","modified_gmt":"2020-05-01T11:35:24","slug":"shared-responsibility-2","status":"publish","type":"page","link":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/","title":{"rendered":"Understanding Shared Responsibility"},"content":{"rendered":"\n<p>AWS cloud computing infrastructure offers multitude of services which are varied in nature and usage. Thus, there is an inherent need to isolate shared responsibility between customer and AWS<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>physical security of the computing infrastructure is taken care by AWS, which includes resources of &nbsp;\n<ul>\n<li>compute<\/li>\n<\/ul>\n<ul>\n<li>database<\/li>\n<\/ul>\n<ul>\n<li>storage<\/li>\n<\/ul>\n<ul>\n<li>networking<\/li>\n<\/ul>\n<\/li><li>Customer is accountable only for\n<ul>\n<li>Software on top of the infrastructure layer<\/li>\n<li>data and access &nbsp;on top of the infrastructure layer<\/li>\n<\/ul>\n<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"310\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-161.png\" alt=\"\" class=\"wp-image-3767\"\/><\/figure>\n\n\n\n<p><strong>AWS Security Responsibilities<\/strong><\/p>\n\n\n\n<p>AWS is accountable for following<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Computing Hardware and Global Infrastructure, which includes\n<ul>\n<li>AWS regional, available, and edge zones cloud infrastructure\n<ul>\n<li>All has physical security protections, and constant IT maintenance<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li><li>Software related to AWS computing hardware management covering\n<ul>\n<li>Computation<\/li>\n<\/ul>\n<ul>\n<li>Storage<\/li>\n<\/ul>\n<ul>\n<li>Database<\/li>\n<\/ul>\n<ul>\n<li>Networking<\/li>\n<\/ul>\n<ul>\n<li>&nbsp;software platform for all of AWS services<\/li>\n<\/ul>\n<ul>\n<li>security services from AWS to be used by customers, and includes\n<ul>\n<li>encryption keys<\/li>\n<\/ul>\n<ul>\n<li>network monitoring tools<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li><li>database protection, and more.<\/li><\/ul>\n\n\n\n<p><strong>Customer Security Responsibilities<\/strong><\/p>\n\n\n\n<p>As per AWS service selected by customer, customer is accountable for different levels of security, as<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>For IaaS AWS service like &#8211; EC2\/VPC\/ S3, all of the security configuration and management tasks for security is to be done by customer and includes\n<ul>\n<li>Customer Business Data before it enters AWS and after it exits AWS.<\/li>\n<\/ul>\n<ul>\n<li>Security of the platform running on the IaaS like shoppers identities protection for an online clothing store<\/li>\n<\/ul>\n<ul>\n<li>Data Encryption when data is at rest or transit<\/li>\n<\/ul>\n<ul>\n<li>Encryption of the File System<\/li>\n<\/ul>\n<ul>\n<li>Safety of the Network Traffic<\/li>\n<\/ul>\n<\/li><li>Safety for routing and zoning data<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"314\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-162.png\" alt=\"\" class=\"wp-image-3768\"\/><\/figure>\n\n\n\n<p><strong>Security Shared Responsibility<\/strong><\/p>\n\n\n\n<p>AWS fulfills the need for cloud computing infrastructure and the customer is responsible for the implementation part of AWS\u2019s cloud computing infrastructure like configuration, patching, etc. It consists of<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Controls in the cloud\u2019s IT setup \u2013 Operating and managing IT operation and controls are to be taken care by both customer and AWS. Customer is responsible for deployment of IT controls as per laid down AWS\u2019s guidelines and regulations. AWS provides various security related maintenance facilities like network level encryption, firewall maintenance, etc. to ease the burden on customer<\/li><li>Configuration Management \u2013 AWS takes the shared responsibility of the cloud computing infrastructure\u2019s configuration management and customer is responsible for configuration of operating systems, databases and software applications on the instances.<\/li><li>Patch Management \u2013 AWS is responsible for cloud computing infrastructure\u2019s patching and error fixing whereas customer does patching of operating systems, databases and software applications on the instances.<\/li><li>Customer Software Specific Controls \u2013 Customer is responsible for controls which are specific to their software application and has no linkage to AWS\u2019s cloud computing infrastructure<\/li><li>Employee Training and Awareness \u2013 Training and awareness of customer\u2019s employees who are using the AWS\u2019s cloud computing infrastructure, is customer\u2019s responsibility<\/li><\/ul>\n\n\n\n<p>Customers should<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>access control policies should be employed by using the AWS\u2019s IAM<\/li><li>access to ports to be controlled by configuring AWS Security Groups<\/li><li>CloudTrail should be enabled for logging<\/li><\/ul>\n\n\n\n<p>Responsibility of Customers also include<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Implementation of policies for DLP (or data loss prevention) as might be needed by customer\u2019s internal and external policy compliance<\/li><li>Prevention, detection and remedy any hazard due to loss or stealing of account credentials resulting in malicious misuse of AWS<\/li><\/ul>\n\n\n\n<p>AWS takes the responsibility of securing its cloud computing infrastructure which includes<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Computing<\/li><li>Storage<\/li><li>Networking<\/li><li>database services<\/li><li>security configuration of AWS services like\n<ul>\n<li>DynamoDB<\/li>\n<\/ul>\n<ul>\n<li>RDS<\/li>\n<\/ul>\n<ul>\n<li>Redshift<\/li>\n<\/ul>\n<ul>\n<li>Elastic MapReduce<\/li>\n<\/ul>\n<ul>\n<li>Workspaces, etc.<\/li>\n<\/ul>\n<\/li><\/ul>\n\n\n\n<p>AWS Shared Responsibility Model Summary<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>&nbsp;<\/td><td>Customer<\/td><td>AWS<\/td><\/tr><tr><td>Prevent\/detect any compromise of AWS account<\/td><td>x<\/td><td>&nbsp;<\/td><\/tr><tr><td>Prevent\/detect any insecure behavior of AWS user<\/td><td>x<\/td><td>&nbsp;<\/td><\/tr><tr><td>Securely configuring AWS services ( AWS Managed Services are excluded)<\/td><td>x<\/td><td>&nbsp;<\/td><\/tr><tr><td>Restricted access to AWS services or any&nbsp; customer\u2019s custom applications, &nbsp;to only users who need it<\/td><td>x<\/td><td>&nbsp;<\/td><\/tr><tr><td>Update of Guest OS and security patch application<\/td><td>x<\/td><td>&nbsp;<\/td><\/tr><tr><td>Making sure that both, AWS and customer\u2019s custom applications usage complies to internal and external policies<\/td><td>x<\/td><td>x<\/td><\/tr><tr><td>Enabling and provisioning network security against attacks like DoS, MITM, port scanning<\/td><td>x<\/td><td>x<\/td><\/tr><tr><td>Securely managing and operating configurations of AWS Managed Services<\/td><td>&nbsp;<\/td><td>x<\/td><\/tr><tr><td>Provisioning of physical access control<\/td><td>&nbsp;<\/td><td>x<\/td><\/tr><tr><td>Securing against any environmental risks like natural disasters, mass power outages, etc<\/td><td>&nbsp;<\/td><td>x<\/td><\/tr><tr><td>patching and error fixing of database<\/td><td>&nbsp;<\/td><td>x<\/td><\/tr><tr><td>Securing against zero day exploits or related vulnerabilities<\/td><td>&nbsp;<\/td><td>x<\/td><\/tr><tr><td>Providing business continuity to customers and addressing availability, incident response<\/td><td>&nbsp;<\/td><td>x<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<div class=\"wp-block-image\">\r\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"334\" height=\"354\" class=\"wp-image-3769\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-163.png\" alt=\"\" \/><\/figure>\r\n<p><strong>Get ready to qualify <a href=\"https:\/\/www.testpreptraining.ai\/aws-certified-security-specialty-practice-exam\">AWS Certified Security &#8211; Specialty<\/a> with hundreds of practice exam and expert guidance. Take test Now!<\/strong><\/p>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>AWS cloud computing infrastructure offers multitude of services which are varied in nature and usage. Thus, there is an inherent need to isolate shared responsibility between customer and AWS physical security of the computing infrastructure is taken care by AWS, which includes resources of &nbsp; compute database storage networking Customer is accountable only for Software&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":2474,"menu_order":36,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[2],"tags":[7,301],"class_list":["post-3082","page","type-page","status-publish","hentry","category-amazon-aws","tag-aws","tag-shared-responsibility"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Understanding Shared Responsibility - Testprep Training Tutorials<\/title>\n<meta name=\"description\" content=\"Qualify AWS Certified Security - Specialty with hundreds of practice exam and expert guidance. Learn abour Shared Responsibility and Take test Now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Understanding Shared Responsibility - Testprep Training Tutorials\" \/>\n<meta property=\"og:description\" content=\"Qualify AWS Certified Security - Specialty with hundreds of practice exam and expert guidance. Learn abour Shared Responsibility and Take test Now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Testprep Training Tutorials\" \/>\n<meta property=\"article:modified_time\" content=\"2020-05-01T11:35:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-161.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/\",\"name\":\"Understanding Shared Responsibility - Testprep Training Tutorials\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\"},\"datePublished\":\"2019-08-31T11:45:36+00:00\",\"dateModified\":\"2020-05-01T11:35:24+00:00\",\"description\":\"Qualify AWS Certified Security - Specialty with hundreds of practice exam and expert guidance. Learn abour Shared Responsibility and Take test Now!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AWS Certified Security Specialty\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Understanding Shared Responsibility\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"name\":\"Testprep Training Tutorials\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\",\"name\":\"Testprep Training\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"contentUrl\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"width\":583,\"height\":153,\"caption\":\"Testprep Training\"},\"image\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Understanding Shared Responsibility - Testprep Training Tutorials","description":"Qualify AWS Certified Security - Specialty with hundreds of practice exam and expert guidance. Learn abour Shared Responsibility and Take test Now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/","og_locale":"en_US","og_type":"article","og_title":"Understanding Shared Responsibility - Testprep Training Tutorials","og_description":"Qualify AWS Certified Security - Specialty with hundreds of practice exam and expert guidance. Learn abour Shared Responsibility and Take test Now!","og_url":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/","og_site_name":"Testprep Training Tutorials","article_modified_time":"2020-05-01T11:35:24+00:00","og_image":[{"url":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2019\/09\/image-161.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/","url":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/","name":"Understanding Shared Responsibility - Testprep Training Tutorials","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website"},"datePublished":"2019-08-31T11:45:36+00:00","dateModified":"2020-05-01T11:35:24+00:00","description":"Qualify AWS Certified Security - Specialty with hundreds of practice exam and expert guidance. Learn abour Shared Responsibility and Take test Now!","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/shared-responsibility-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/tutorial\/"},{"@type":"ListItem","position":2,"name":"AWS Certified Security Specialty","item":"https:\/\/www.testpreptraining.ai\/tutorial\/aws-certified-security-specialty\/"},{"@type":"ListItem","position":3,"name":"Understanding Shared Responsibility"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","name":"Testprep Training Tutorials","description":"","publisher":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization","name":"Testprep Training","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","contentUrl":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","width":583,"height":153,"caption":"Testprep Training"},"image":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/3082","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/comments?post=3082"}],"version-history":[{"count":5,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/3082\/revisions"}],"predecessor-version":[{"id":5144,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/3082\/revisions\/5144"}],"up":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/2474"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/media?parent=3082"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/categories?post=3082"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/tags?post=3082"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}