SimAWSby ShahriarLabs
Search

Who is responsible when it breaks · Chapter 1 of 1

Where AWS responsibilities end and your responsibilities begin

AWS protects the underlying infrastructure of the cloud, but securing your data and configuring your services remains entirely your job.

FoundationsBuilds the idea from nothing. No prior AWS assumed.

The shared responsibility model

Who is responsible if an attacker steals customer records from your cloud database?

IaaS (EC2)PaaS (RDS)Serverless (Lambda)OS PatchingCustomer ManagedDB EngineAWS ManagedYour CodeCustomer ManagedAccess ControlIAM & PoliciesThe Shared Responsibility Model shifts infrastructure management to AWS, but data security and access control always remain your responsibility.

On EC2, you manage the operating system, network configuration, and application security.

1/5
  1. 01

    Security of the cloud

    AWS is responsible for the physical security of data centres, the host hardware, hypervisors, and the physical network. They ensure that unauthorised people cannot walk into their buildings, swap out hard drives, or tap the network cables connecting host machines.

  2. 02

    Security in the cloud

    You are responsible for what you run inside AWS. This includes configuring network access rules, managing identity permissions, applying security updates to virtual machine operating systems, and encrypting customer data. If you configure a database to be open to the internet with no password, AWS will not stop you.

  3. 03

    The danger of default configurations

    Many AWS services are designed to work out of the box with open defaults to help you learn. However, these defaults are rarely secure enough for production. Part of your job is to review and restrict these settings before deploying applications that handle sensitive information.

  • Physical security of the data centre
  • Patching the hypervisor
  • Patching the operating system
  • Upgrading the database engine version
  • Bugs in your application code
  • Who is allowed to read the data
  • Deciding whether data is encrypted
  • Which ports are open to the internet
Correct
0 of 8
Answered
0 of 8

Check yourself

If a security vulnerability in the Linux operating system of your EC2 instance allows an attacker to steal data, whose responsibility was it to patch the OS?

Under the hoodThe same thing from underneath: limits, failure modes, numbers.

How managed services shift the boundary

How does choosing a managed service change the list of tasks you must perform?

IaaS (EC2)PaaS (RDS)Serverless (Lambda)OS PatchingCustomer ManagedDB EngineAWS ManagedYour CodeCustomer ManagedAccess ControlIAM & PoliciesThe Shared Responsibility Model shifts infrastructure management to AWS, but data security and access control always remain your responsibility.

On EC2, you manage the operating system, network configuration, and application security.

1/5
  1. 01

    Moving the line upward

    When you use a managed service like Amazon RDS instead of running a database on an EC2 instance, AWS takes over more work. They handle operating system updates, database engine patching, and automatic backups. This shifts the boundary line up, reducing your operational maintenance load.

  2. 02

    The line never disappears

    Even with fully managed services, you retain critical responsibilities. For a managed database, you still control who has access to the tables, how database credentials are stored, and whether the data is encrypted. Selecting a managed service removes hardware management but does not secure your data.

  3. 03

    Verifying compliance externally

    Because you cannot audit AWS data centres yourself, you must rely on third-party audits. AWS provides access to these compliance reports through a service called AWS Artifact. These documents prove to your auditors that the underlying physical infrastructure complies with international security standards.

The numbers

ISO and SOC compliance reports
Available on demand via AWS ArtifactRequired by corporate auditors to prove the physical security of the underlying AWS infrastructure.
Database engine minor patching
Automated by AWS during maintenance windowsReduces your patching workload, but you must still schedule and approve major version upgrades.
Default S3 bucket access
Private by defaultAWS modified this default after numerous public data leaks caused by users configuring public buckets.

Check yourself

When using a managed database service like Amazon RDS, which of the following is still your responsibility?

Official references & further reading

These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.

Report an error or suggest a clearer explanation →