Cyberstudy
Supplementary — not from your PDF Beginner ~25 min

Map the shared responsibility model

For three cloud services you actually use, work out which security tasks the provider handles and which are yours.

Environment

A spreadsheet, plus the public security or trust documentation of the services you choose.

Before you start

  • Read Cloud Service Models (p.155) and Responsibility Matrix (p.157).

You will

  • Classify services as IaaS, PaaS or SaaS
  • Assign each security task to provider or customer

Steps

  1. 1

    Pick three services: for example a webmail or office suite (SaaS), an app-hosting platform (PaaS) and a virtual machine service (IaaS). Free tiers or services you already use are fine.

  2. 2

    Make rows for: physical data center, hypervisor, operating system patching, application code, identity and access, data classification, backups, and account MFA.

  3. 3

    For each service, mark every row Provider, Customer or Shared.

  4. 4

    Check your answers against each provider's published shared responsibility page.

  5. 5

    Circle the tasks that are always the customer's, whatever the model (hint: data and identities).

Check your understanding

  • ?Who patches the guest operating system in IaaS?
  • ?Why is account security the customer's job even in SaaS?
  • ?Which service model gives you the most control, and the most responsibility?