CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
A multinational corporation is considering migrating its critical enterprise resource planning (ERP) system to a public cloud provider. The Chief Information Security Officer (CISO) is concerned about the shared responsibility model. Which of the following responsibilities typically remains with the customer in an Infrastructure as a Service (IaaS) model?
- AMaintenance of the networking hardware.
- BPhysical security of the data center.
- CManagement of the underlying virtualization layer.
- DSecurity configuration of the operating system and applications.
Show answer & explanationAnswer & explanation
Correct answer: D. Security configuration of the operating system and applications.
In an IaaS model, the customer is responsible for configuring and securing the operating system, applications, and data, while the cloud provider manages the underlying infrastructure.
Why the other options are wrong
- A. Networking hardware maintenance is a responsibility of the cloud provider.
- B. Physical security is typically the responsibility of the cloud provider across all cloud service models.
- C. The cloud provider manages the virtualization layer in an IaaS model.
Shared Responsibility Model (IaaS)
A framework outlining the security responsibilities between a cloud provider and a customer, where the customer is responsible for 'security in the cloud' and the provider for 'security of the cloud'.
- Customer manages OS, applications, data in IaaS.
- Provider manages physical infrastructure, virtualization.
- Responsibilities vary by cloud service model (IaaS, PaaS, SaaS).
Memory trick: Customer 'in' the cloud, Provider 'of' the cloud.