Who is responsible when it breaks · Chapter 1 of 1
Where AWS responsibilities end and your responsibilities begin
AWS protects the underlying infrastructure of the cloud, but securing your data and configuring your services remains entirely your job.
FoundationsBuilds the idea from nothing. No prior AWS assumed.
The shared responsibility model
Who is responsible if an attacker steals customer records from your cloud database?
On EC2, you manage the operating system, network configuration, and application security.
- 01
Security of the cloud
AWS is responsible for the physical security of data centres, the host hardware, hypervisors, and the physical network. They ensure that unauthorised people cannot walk into their buildings, swap out hard drives, or tap the network cables connecting host machines.
- 02
Security in the cloud
You are responsible for what you run inside AWS. This includes configuring network access rules, managing identity permissions, applying security updates to virtual machine operating systems, and encrypting customer data. If you configure a database to be open to the internet with no password, AWS will not stop you.
- 03
The danger of default configurations
Many AWS services are designed to work out of the box with open defaults to help you learn. However, these defaults are rarely secure enough for production. Part of your job is to review and restrict these settings before deploying applications that handle sensitive information.
- Physical security of the data centre
- Patching the hypervisor
- Patching the operating system
- Upgrading the database engine version
- Bugs in your application code
- Who is allowed to read the data
- Deciding whether data is encrypted
- Which ports are open to the internet
- Correct
- 0 of 8
- Answered
- 0 of 8
Check yourself
If a security vulnerability in the Linux operating system of your EC2 instance allows an attacker to steal data, whose responsibility was it to patch the OS?
Under the hoodThe same thing from underneath: limits, failure modes, numbers.
How managed services shift the boundary
How does choosing a managed service change the list of tasks you must perform?
On EC2, you manage the operating system, network configuration, and application security.
- 01
Moving the line upward
When you use a managed service like Amazon RDS instead of running a database on an EC2 instance, AWS takes over more work. They handle operating system updates, database engine patching, and automatic backups. This shifts the boundary line up, reducing your operational maintenance load.
- 02
The line never disappears
Even with fully managed services, you retain critical responsibilities. For a managed database, you still control who has access to the tables, how database credentials are stored, and whether the data is encrypted. Selecting a managed service removes hardware management but does not secure your data.
- 03
Verifying compliance externally
Because you cannot audit AWS data centres yourself, you must rely on third-party audits. AWS provides access to these compliance reports through a service called AWS Artifact. These documents prove to your auditors that the underlying physical infrastructure complies with international security standards.
The numbers
- ISO and SOC compliance reports
- Available on demand via AWS ArtifactRequired by corporate auditors to prove the physical security of the underlying AWS infrastructure.
- Database engine minor patching
- Automated by AWS during maintenance windowsReduces your patching workload, but you must still schedule and approve major version upgrades.
- Default S3 bucket access
- Private by defaultAWS modified this default after numerous public data leaks caused by users configuring public buckets.
Check yourself
When using a managed database service like Amazon RDS, which of the following is still your responsibility?
Official references & further reading
These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.
Report an error or suggest a clearer explanation →