30.1 The Shared Responsibility Model
AWS explains cloud security with the Shared Responsibility Model:
| AWS is responsible for ("security of the cloud") | You are responsible for ("security in the cloud") |
|---|---|
| Data centres, physical security, guards | IAM users, passwords, MFA, access keys |
| Hardware, network cables, hypervisor | Security groups and network design |
| The managed service software itself | OS patching on EC2 (sudo yum update) |
| Global infrastructure availability | Encryption choices, S3 bucket permissions |
| Your application code (OWASP, Chapter 29) |
The line moves with the service. On EC2 you patch the OS; on RDS AWS patches the database engine but you still control who can connect; on S3 AWS runs storage but you decide whether a bucket is public.
Ravindra Bagale's Tip
Students la vatte "AWS var aahe mhanje safe aahe". Chuk! AWS tumcha bucket public karat nahi – tumhi karta. Cloud breach chya batmya vachlya tar bahutek veles karan misconfiguration asta, AWS hack nahi. Tumchi baju tumhich sambhala.
Practice task
For your reels app (EC2 + S3 + RDS from Chapter 16), make a two-column table: list five things AWS secures and five things you must secure yourself.