foundation Estimated learning time: 3 h

1.5 The shared responsibility model

You can name, for any service you use, exactly which failures are yours to prevent.

Before:00. Groundwork — Linux, Networking & GitUnlocks:02. Compute09. Cost Engineering

Every provider publishes a line: security OF the cloud is theirs, security IN the cloud is yours, and this topic is about knowing exactly where that line sits for each service model. It sits in the foundations because most real cloud breaches happen on the customer's side — an open bucket, a leaked key — not in the provider's data centre. What the topic asks for is writing your half down before deploying; the confusion it kills is assuming that paying a provider transfers the responsibility along with the work.

Work through these

  • Security 'of' the cloud vs security 'in' the cloud

    The provider secures the infrastructure the service runs on; you secure what you put into it and how you configure it. Almost every argument about a cloud incident comes down to which side of that line the failure sat on.

  • How the line moves between IaaS, PaaS and SaaS

    The line is not fixed: with raw infrastructure you patch the operating system, with a managed platform you do not, with software as a service you barely configure anything. Knowing where it sits for each service you use is the actual skill.

  • The breaches that happened on the customer's side of the line

    The well-known cloud data losses were overwhelmingly on the customer's side of the line, usually a storage container left open or a key committed to a repository. That is the pattern worth internalising.

  • Writing your half down before you deploy

    Writing down which failures are yours to prevent, before you deploy, turns an abstract diagram into a checklist you can act on. It also settles the argument in advance rather than during an incident.

Sign in to keep your progress.

Free resources

Links last checked 29 Aug 2026.

Stuck here?

Ask a mentor. A real person answers, and they can see exactly which topic you're on. Usually within a couple of working days.

Checking your session…

Topics shown in module order.