Cloud Security: Who is Responsible for What?

Today, the benefits of cloud computing are very well established: it is less costly and provides increased flexibility and agility, including the ability to support on-demand computing at scale. The debate surrounding the security of cloud computing, specifically whether data was more secure in the cloud or not, has for the most part been settled. A growing number of organisations now view the cloud as secure, and in many cases, more so than an on-premises deployment.
Infrastructure-as-a-Service (IaaS) and Platform-as-a-service (PaaS) – where a company’s own applications and assets run on infrastructure operated by the public cloud vendors — have also grown in popularity. Amazon Web Services (AWS) and Microsoft Azure have experienced significant growth, in part because of the relative ease for an organisation to set up and deploy their applications at scale in cloud environments.
Public cloud vendors focus on the security of the cloud infrastructure, including the compute, storage and networking resources as well as the physical infrastructure, but they recognise that they are only able to provide a partial solution. In fact, as each of the public cloud vendors point out, security in the cloud is a shared responsibility – with the organisation as the application owner being responsible for protecting applications, the OS, supporting infrastructure, and other assets running IN the cloud.
Essentially, everything above the hypervisor or equivalent layer is the responsibility of the application owner. Organisations may also need to configure some of the services provided by the cloud vendor. For example, basic perimeter security is included with the cloud vendor’s infrastructure, but it is configured by the customer.
In case there is any doubt, the AWS Customer Agreement, for example, is very clear on the limits of AWS’ responsibilities for securing the enterprise’s applications and data. The liability is limited to refunding what the enterprise paid AWS for services in the past year. As a speaker at the recent HIMSS healthcare IT conference in the US pointed out, even if the cloud vendor could be proven to be at fault for a breach, and that’s a big if, it’s very unlikely the enterprise would be covered for direct financial loss caused by the loss of patient’s medical records. On top of that, there are other costs including regulatory fines, reputational loss and, most importantly, impact on the organisation’s customers.
While the public cloud vendors take steps to ensure the security OF the Cloud, ultimately, just like with an on-premises data centre, it is the enterprise and application owner that is responsible for security IN the Cloud, and for ensuring that your customer’s data is secure.
Unfortunately, that message may not be getting through to all cloud users.


