What is the Shared Responsibility Model?
Simplified Definition:
The Shared Responsibility Model defines what you (as an AWS account holder/user) and Amazon Web Services are responsible for when it comes to security and compliance.
AWS Definition:
Security and compliance is a shared responsiblity between AWS and the customer. This shared model can help relieve ducomster’s operational burden as AWS operates, manages, and controls the componets from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates. The customer assumes responsiblity and amangement of the guest operating system (including updates and security patches), other associated application software as well as the configuration of the AWS provided security group firewall.
What is the cusotmer responsible for under the Shared Responsibility Model?
Customer is responsible for security “in” the cloud. Includes:
What is AWS responsible for under the Shared Responsibility Model?
AWS is responsible for security “of” the cloud:
What 8 services does Amazon allow customers to carry out security assessment or penetration tests without prior approval?
Which security assessment or penetration tests does Amazon NOT allow customers to carry out ?
6 other AWS security-related services?
What is AWS Organizations?
AWS Organizations allows for centralized management of AWS accounts and billing, but it can also define policies that restrict, at the account level, what services and actions member accounts may take.
What is Amazon GuardDuty?
Amazon GuardDuty is a threat detection service that provides a way to continuously monitor and protect AWS accounts and workloads. GuardDuty uses threat intelligence feeds to detect threats to the environment. GuardDuty is designed to actively protect the environment from threats.
What is Amazon Inspector?
Amazon Inspector analyzes the VPC environment for potential security issues. Inspector uses a defined template and assesses the environment. It provides the findings and recommends steps to resolve any potential security issues found.
What is AWS Shield?
AWS Shield provides management DDoS protection. DDoS attacks happen when multiple compromised systems attempt to flood a target with traffec. That target could be DNS, a web application, or a network.
What is AWS Web Application Firewall (WAF)?
WAF monitors web requests forwarded by an ELB, CloudFront, or API Gateway. WAF can allow or deny access to content based on specified conditions.
What is AWS Artifact?
AWS Artifact is a portal that provides access to AWS’ compliance documentation, such as payment card industry (PCI) and ISO certifications, and System and Organization Control (SOC) reports.
What does KMS stand for?
Key Management Service
What is Key Management Service (KMS)?
AWS KMS enables encryption of data and provides centralized encryption key storage, management, and auditing. The data may be encrypted for use with applications or to encrypt data stored on AWS.
Key facts about KMS?
Key Management Storage: