Ravindra BagaleCourses & study guides

30. Cloud and AWS Security

30.1 The Shared Responsibility Model

AWS explains cloud security with the Shared Responsibility Model:

AWS is responsible for ("security of the cloud") You are responsible for ("security in the cloud")
Data centres, physical security, guards IAM users, passwords, MFA, access keys
Hardware, network cables, hypervisor Security groups and network design
The managed service software itself OS patching on EC2 (sudo yum update)
Global infrastructure availability Encryption choices, S3 bucket permissions
Your application code (OWASP, Chapter 29)

The line moves with the service. On EC2 you patch the OS; on RDS AWS patches the database engine but you still control who can connect; on S3 AWS runs storage but you decide whether a bucket is public.

Ravindra Bagale's Tip

Students la vatte "AWS var aahe mhanje safe aahe". Chuk! AWS tumcha bucket public karat nahi – tumhi karta. Cloud breach chya batmya vachlya tar bahutek veles karan misconfiguration asta, AWS hack nahi. Tumchi baju tumhich sambhala.

Practice task

For your reels app (EC2 + S3 + RDS from Chapter 16), make a two-column table: list five things AWS secures and five things you must secure yourself.