The contractual split between what the cloud provider secures and what the customer secures alone, whose dividing line decides who carries the loss.
The shared responsibility model is the split, written into the cloud provider's terms, between what the provider secures, namely the physical facility, the virtualization layer and the services it operates, and what the customer alone secures, namely its configurations, identities, access rights and data. The line moves with the service consumed: high for a bare virtual machine, where almost everything falls to the customer, low for a fully provider-operated service. It is a risk transfer instrument before it is a technical document, because it determines who the loss is attributable to, therefore which policy responds and against whom recovery is available. The dominant cause of cloud compromise is not intrusion into the provider's infrastructure but customer-side misconfiguration, as incident response vendors report year after year. An underwriter who has not seen where that line falls for the workloads actually in production does not know what is being covered.
In July 2019, Capital One disclosed the compromise of roughly 106 million customer records in the United States and Canada, achieved by exploiting a customer-side misconfigured web application firewall rather than a flaw in Amazon Web Services infrastructure. The US Office of the Comptroller of the Currency fined the bank 80 million dollars in August 2020.
shared responsibility model, partage de responsabilité cloud, frontière de sécurité cloud