官术网_书友最值得收藏!

Shared responsibility model for abstract services

The final model we will look at is the abstract shared responsibility model, shown here:

Right away, from a visual perspective, we can see that the shift in responsibility leans even greater toward AWS.

This model retains the level of security AWS has to manage from both the previous two models (infrastructure and container), with the addition of server-side encryption and network traffic protection. Example AWS services that fall within this model are the Amazon Simple Queue Service (SQS), Amazon DynamoDB, and Amazon S3.

These are defined as abstract services as almost all the control and management of the service has been abstracted away from the end customer; we simply access these services through endpoints. Customers do not have access to the underlying operating system (infrastructure) or to the actual platform that is running these services (container); instead, the customer is presented with the service frontend or endpoint to configure as required.

As a result, the customer has been totally abstracted away from having to maintain security updates for the operating system or any platform patches and security management. This also means that AWS now has the responsibility to implement and control any server-side encryption options, such as Amazon S3 Server-Side Encryption (S3-SSE), where the customer has no control over the access keys used for this encryption method; it's all managed by AWS.

Also, AWS will manage the secure transfer of data between the service components—for example, when S3 automatically copies customer data to multiple endpoints across different Availability Zones. As a customer, we have no control over how this data is transferred, and so the traffic has to be secured by AWS.

主站蜘蛛池模板: 云和县| 莱芜市| 武宁县| 新河县| 葫芦岛市| 天台县| 大石桥市| 台安县| 河间市| 泸西县| 蒲江县| 孟州市| 镇巴县| 商河县| 新和县| 金寨县| 扬中市| 上犹县| 元阳县| 荔波县| 烟台市| 崇阳县| 濮阳市| 大关县| 泰安市| 新河县| 万山特区| 吴江市| 寿阳县| 墨江| 四会市| 锦州市| 昌吉市| 绿春县| 赣州市| 信丰县| 英山县| 遂溪县| 沂源县| 高平市| 古蔺县|