Shared Responsibility Model
AWS, "SECURITY, OF, the, CLOUD" ke, liye, RESPONSIBLE, hai — physical, DATA, CENTERS, hardware, aur, NETWORKING, infrastructure. Customer, "SECURITY, IN, the, CLOUD" ke, liye, RESPONSIBLE, hai — DATA, IAM, permissions, aur, application, security.
YE, DIVIDE, service, ke, TYPE, PAR, DEPEND, karta hai — Managed, services, (RDS, Lambda) mein, AWS, ZYAADA, LETA, hai, EC2, jaise, unmanaged, services, mein, CUSTOMER, ZYAADA, RESPONSIBLE, hai (OS, patching).
# Customer responsibility example: EC2 security group configure karna
aws ec2 authorize-security-group-ingress --group-id sg-123 --protocol tcp --port 443 --cidr 0.0.0.0/0- AWS = security OF the cloud (physical infra, hardware)
- Customer = security IN the cloud (data, IAM, app config)
- Managed services mein AWS zyada responsibility leta hai
AWS, "SECURITY, OF, the, CLOUD" ke, liye, RESPONSIBLE, hai — physical, DATA, CENTERS, hardware, networking, infrastructure. CUSTOMER, "SECURITY, IN, the, CLOUD" ke, liye, RESPONSIBLE, hai — DATA, encryption, IAM, permissions, OS, patching, (agar, EC2, use, ho, RAHA, hai).
AWS, MULTIPLE, COMPLIANCE, certifications, (jaise, ISO, 27001, SOC, 2, HIPAA) maintain, karta hai — LEKIN, CUSTOMER, ko, KHUD, ye, ENSURE, karna, PADTA, hai, ki, UNKI, application, ki, CONFIGURATION, bhi, COMPLIANT, hai (jaise, correct, region, mein, DATA, STORE, karna).
# Data ko specific region mein rakhne ke liye bucket create karo
aws s3api create-bucket --bucket my-eu-bucket --region eu-west-1 --create-bucket-configuration LocationConstraint=eu-west-1