Map the shared responsibility model
For three cloud services you actually use, work out which security tasks the provider handles and which are yours.
Environment
A spreadsheet, plus the public security or trust documentation of the services you choose.
Before you start
- Read Cloud Service Models (p.155) and Responsibility Matrix (p.157).
You will
- Classify services as IaaS, PaaS or SaaS
- Assign each security task to provider or customer
Steps
-
1
Pick three services: for example a webmail or office suite (SaaS), an app-hosting platform (PaaS) and a virtual machine service (IaaS). Free tiers or services you already use are fine.
-
2
Make rows for: physical data center, hypervisor, operating system patching, application code, identity and access, data classification, backups, and account MFA.
-
3
For each service, mark every row Provider, Customer or Shared.
-
4
Check your answers against each provider's published shared responsibility page.
-
5
Circle the tasks that are always the customer's, whatever the model (hint: data and identities).
Check your understanding
- ?Who patches the guest operating system in IaaS?
- ?Why is account security the customer's job even in SaaS?
- ?Which service model gives you the most control, and the most responsibility?