Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How To Overcome 3 Key Challenges Of Shared Responsibility In The Cloud
Articles

How To Overcome 3 Key Challenges Of Shared Responsibility In The Cloud

ISBuzz TeamBy ISBuzz TeamAugust 19, 20194 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
cloud-security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The cloud is changing the nature of business with a powerful approach to streamlining operations and staying current with the latest technology. But as the saying goes, with great power comes great responsibility. In this case, that responsibility breaks down into two sides: cloud vendors and the companies that use them.

Cloud service providers are responsible for security of the cloud; companies are responsible for security in the cloud. Without the right approach on both sides, companies risk cyberattacks that can crash services or compromise customer data.

For companies using CSPs, maintaining best security practices in the cloud is not simple. The cloud is a complex ecosystem of interacting components. They include software as a service, platform as a service, and infrastructure as a service — with each layer interacting. And in addition to protection of data assets, there are legal regulations to follow.

The company using the infrastructure service has control over security options. For example, many of the offerings for companies using Amazon Web Services, such as Amazon Elastic Compute Cloud, Amazon Virtual Private Cloud, and Amazon Simple Storage Service are IaaS, meaning that companies must configure security settings themselves.

Shared Cloud Responsibility Challenges

Getting these settings right can be challenging, so it’s useful to know what to expect when managing them. Let’s take a look at how to effectively deal with some of these challenges:

  1. Choose the right cloud platform.

First, you need a cloud platform that fits your business needs while keeping the company secure and agile. You’ll also need to decide whether your company can tackle securing and owning all data, even if the data is processed in a cloud platform. The cloud platform will need to provide you with visibility into how your data is processed.

Research what each CSP can provide and what tools you need to function. Most have shared controls for managing patches and configuring operating systems, databases, and applications. Think through how you might use these controls, who at your company will be responsible for them, and why they will serve your needs both now and as your company scales up.

  1. Understand your role — and theirs.

Sharing responsibility works best for companies when roles are understood. For example, consider IT controls at AWS. Not only is the IT environment shared between AWS and its customers, but so is the management, operation, and verification of IT controls. Given that degree of flexibility, it’s crucial to be clear on what your company is taking responsibility for and what will be left in the hands of the CSP. When these roles are not clearly defined, gaps in security can result — and that puts your company at risk.

The CSP typically manages controls associated with the physical infrastructure, thereby relieving that customer burden. Your company still typically manages access to the cloud platform. Customers can then use the CSP control and compliance documentation to perform their required control evaluation and verification procedures. Ambiguity can arise depending on the services of the CSP that are used, such as a serverless option that is managed versus one the customer manages. These roles need to be clearly defined and understood.

  1. Think carefully about security.

Data security is the company’s responsibility regardless of CSP, but having the right tools and knowing how to use them can enhance that mission. A foundational step is to make full use of tools that monitor incidents that can alert companies to security issues, because responding promptly to breaches can limit the damage to the company.

To ensure you’re approaching this correctly, empower a team that researches security and infrastructure abilities and limits. These teams will test controls and ideally will be able to identify areas where there are gaps in coverage or find places where tools can be better. A prime example would be multifactor authentication, a choice that the team can evaluate based on the company’s needs.

Cloud services can be transformational to companies small and large, but only if they are used effectively and securely. Understanding that security and service are a shared responsibility is the first step toward crafting the right approach. The key is to get the balance right. Taking total responsibility for every detail of your company’s cloud use is inefficient, but abdicating all control over how your settings are managed in the cloud is irresponsible.

Fortunately, some providers offer enough flexibility to allow just the right degree of control without it being burdensome. Companies that take advantage of this model of shared responsibility will be well positioned in the years ahead to focus on expanding their market share while knowing they have a highly optimized solution in the cloud.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}