Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A company is using a public cloud provider for its entire IT infrastructure. During a recent security audit, a critical finding was identified: several virtual machines (VMs) are running vulnerable operating system versions and unpatched applications. This indicates a failure in maintaining the security posture of the compute environment. Which cloud security responsibility model aspect is primarily highlighted by this finding?
- ACloud Service Provider (CSP) contractual obligations.
- BThird-party auditor's liability.
- CShared Responsibility Model: Customer's Responsibility in the Cloud.
- DShared Responsibility Model: Cloud Provider's Responsibility for the Cloud.
Show answer & explanationAnswer & explanation
Correct answer: C. Shared Responsibility Model: Customer's Responsibility in the Cloud.
In the Shared Responsibility Model, the cloud provider is responsible for the 'security *of* the cloud' (e.g., physical infrastructure, virtualization layer), while the customer is responsible for 'security *in* the cloud' (e.g., guest operating systems, applications, configurations, data). Maintaining patched operating systems and applications on VMs falls squarely under the customer's responsibility.
Why the other options are wrong
- A. While CSPs have contractual obligations, this finding relates to the operational security of customer-managed resources, which falls under the customer's direct responsibility, not a breach of CSP's core contract.
- B. The auditor's liability relates to their audit process, not the operational security of the cloud environment itself.
- D. The cloud provider is responsible for the underlying infrastructure, but not typically for patching guest operating systems or applications running within customer-provisioned VMs.
Shared Responsibility Model
A framework outlining security responsibilities between a cloud provider and its customers, differentiating between 'security of the cloud' and 'security in the cloud'.
- CSP: 'Security OF the cloud' (physical, hypervisor).
- Customer: 'Security IN the cloud' (OS, apps, data, config).
- Responsibility varies by service model (IaaS, PaaS, SaaS).
Memory trick: CSP secures the cloud beneath, customer handles all within.