What is the shared responsibility model?
When speaking about cloud security and cloud service models (IaaS/PaaS/SaaS), one thing that we all hear about is the shared responsibility model, which tries to draw a line between the cloud provider and the customer’s responsibilities regarding security (but also resiliency, sustainability, and more).
As you can see in the following diagram, the cloud provider is always responsible for the lower layers – from the physical security of their data centers, through networking, storage, host servers, and the virtualization layers:

Figure 1.1 – The shared responsibility model
Above the virtualization layer is where the responsibility begins to change (and even shared between the cloud provider and its customers).
The line between the CSP’s responsibilities and the customer’s responsibilities may not be clear enough (from security, availability, sustainability, etc.). Organizations...