March 5, 2021 By David Bisson 3 min read

Have your security team members ever made a mistake in the cloud? Human error happens and it can take on many forms. But, none are as serious as failing to understand the way cloud defenses work. 

If a mistake does come to mind, be reassured you’re not alone.

Seven in 10 organizations suffered a public cloud security incident between July 2019 and July 2020, reports Help Net Security. Of those cloud computing security incidents, 66% involved the exposure of cloud-based data as the result of an exploited misconfiguration.

How can you be sure you’re getting the right type and level of protection? Let’s take a look at what you need to know about protecting your cloud security when using the Amazon Web Services (AWS) shared responsibility model.

Why a Cloud Shared Responsibly Model Makes Sense

For many, security goes hand-in-hand with control. One can’t secure something unless one has control over it, the logic goes. It takes a cue from the perimeter-based model. The holder of the data needs to not only own the apps and data but also the base infrastructure itself.

Not so in the cloud. This approach follows the AWS shared responsibility model. In this model, the data holder shares security duties with their cloud service provider (CSP). The latter is always in charge of physically securing the infrastructure. From there, the balance shifts depending on the cloud deployment model in use.

There are a few options when it comes to how to do this. Groups with a software-as-a-service (SaaS) model are solely responsible for the defense of their cloud-based data, for instance. The CSP is at least somewhat on the hook for everything else. In a platform-as-a-service (PaaS) model, organizations need to broaden their duties to focus more on their apps with client and endpoint protection. Lastly, one could use the infrastructure-as-a-service (IaaS) model. Here, customers’ obligations expand even further to share the load for using network controls and securing the host.

This brings us to human error and the AWS shared responsibility model. Most groups dealing with this model don’t understand it. Indeed, an Oracle and KPMG cybersecurity report found just 8% of IT security leaders felt they fully understood the AWS shared security model. Such confusion could lead them to overlook key cloud security functions or AWS shared controls for which they’re at least partially on the hook. It could also result in them doubling up on functions that aren’t theirs to provide, wasting budget and resources.

The Shared Responsibility Model in Action

So, how do you make sure your people understand what they need to do to secure the cloud? A good provider is honest about this potential confusion. For example, in an effort to help make the security balance clearer to its customers, Amazon Web Services published a breakdown of its shared responsibility model on its website.

AWS also partnered with QRadar to deliver free rules and reference sets in order to help customers gain more insight into the cloud. Users can view these and other data points from within the QRadar Console. They don’t have to go looking through piles of alerts in an attempt to understand what’s going on in their cloud networks. This complements AWS’s defense duties without customers needing to look elsewhere for tools, worry about adding third-party products or make cloud defense more complex than it needs to be. They can keep their end of the cloud safe solely through the AWS-QRadar partnership.

Tools as the Answer to Cloud Computing Security Incidents

Human error and misconfigurations can threaten your data in the cloud. That’s even more true when it comes to knowing what exactly you need to secure. In response, consider working with CSPs that are upfront about their shared responsibilities. Remember that sometimes the best solution to human error is the right tools. Using a partnership of solutions such as the AWS shared responsibility model and AWS-QRadar can help to simplify the process of cloud security and give you the insight you need. This will help cut down on misconfigurations in the cloud and keep your assets secure.

More from Cloud Security

2024 Cloud Threat Landscape Report: How does cloud security fail?

4 min read - Organizations often set up security rules to help reduce cybersecurity vulnerabilities and risks. The 2024 Cost of a Data Breach Report discovered that 40% of all data breaches involved data distributed across multiple environments, meaning that these best-laid plans often fail in the cloud environment.Not surprisingly, many organizations find keeping a robust security posture in the cloud to be exceptionally challenging, especially with the need to enforce security policies consistently across dynamic and expansive cloud infrastructures. The recently released X-Force…

Cloud threat report: Why have SaaS platforms on dark web marketplaces decreased?

3 min read - IBM’s X-Force team recently released the latest edition of the Cloud Threat Landscape Report for 2024, providing a comprehensive outlook on the rise of cloud infrastructure adoption and its associated risks.One of the key takeaways of this year’s report was focused on the gradual decrease in Software-as-a-Service (SaaS) platforms being mentioned across dark web marketplaces. While this trend potentially points to more cloud platforms increasing their defensive posture and limiting the number of exploits or compromised credentials that are surfacing,…

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today