Glossary

    Shared Responsibility Model

    Compliance & Governance

    The Shared Responsibility Model divides security responsibilities between AWS and the customer:

    • AWS responsibility (security OF the cloud): physical data centers, hardware, networking, hypervisor, and the global infrastructure that runs all AWS services
    • Customer responsibility (security IN the cloud): data encryption, IAM configuration, security group rules, OS patching, application security, and network configuration

    The line shifts depending on the service type. With EC2 (IaaS), you manage the OS and everything above it. With Lambda (serverless), AWS manages the runtime - you only manage code and IAM permissions. With S3 (managed service), you manage access policies, encryption settings, and data classification.

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.