THE SHORT ANSWER

Cloud security combines the provider's platform responsibilities with the customer's responsibility for accounts, permissions, data, configuration, applications and recovery. Exact boundaries depend on the service, so teams must understand what the provider manages and what remains theirs.

Shared responsibility varies by service

Cloud shared responsibility
Business responsibilityQuestion
AccountsWho controls tenant and billing administration?
Data/storageWhat is stored, shared, encrypted and retained?
ConfigurationWhich public access and security settings exist?
SecretsWhere are environment variables and keys held?
LogsWhich important events are retained and reviewed?
RecoveryWhat is backed up and independently restorable?

Protect the control plane

  • Secure primary admin and recovery identities.
  • Use roles instead of shared credentials.
  • Separate environments where risk requires it.
  • Review public sharing and storage settings.
  • Enable useful logs and owned alerts.
  • Document backups and restore responsibility.

Do not assume default means appropriate

Provider defaults optimize broad usability, not every business's risk. Review configurations after setup, integration and major change.

Turn guidance into an owned business action

Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.

Sources & further reading

  1. The NIST Cybersecurity Framework 2.0

    National Institute of Standards and Technology. Current outcome-based guidance for governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risk. It does not prescribe one implementation.

  2. Secrets Management Cheat Sheet

    OWASP Foundation. Security guidance on secret creation, storage, distribution, rotation and revocation. It supports the principle that private credentials do not belong in public client code.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗