AWS Shared Responsibility Model

Learn how the AWS and customers share the responsibility of security and compliance with the shared responsibility model.

In AWS, two stakeholders are responsible for ensuring the security and compliance of the cloud resources: AWS and the customer. AWS is responsible for the security of the cloud, and customers are responsible for security in the cloud.

AWS responsibility

AWS is responsible for the cloud infrastructure’s security, including the hardware, software, networking, and facilities supporting AWS cloud services. The details of the responsibilities of AWS are discussed as follows:

  • Physical security: Securing the data centers where the cloud infrastructure resides and controlling physical access to these data centers, including environmental safeguards (e.g., power and temperature control).

  • Global network security: Securing AWS global network through firewalls, DDoS protection, and network isolation, ensuring secure connectivity between AWS regions and Availability Zones.

  • Hypervisor security: Maintaining and securing the hypervisor and virtualization infrastructure that manages virtual services like EC2 and ensuring the separation of customer data.

Get hands-on with 1400+ tech skills courses.