Cloud computing is not new to the cyber world; it’s here to stay. Web services are common in our everyday lives and workplaces, with things like Facebook, Salesforce, JIRA, Adobe, and GSuite all falling into the cloud-based category. But who is responsible for breaches in the cloud data, the service provider or the organization using their services?
When organizations integrate cloud services to help make their business more efficient, they are also incorporating the risks of extending their network into new environments which require security methods they may not fully understand. The shared responsibility model created by Amazon, which runs cloud computing platform Amazon Web Services (AWS), is one example and offers guidelines for which areas the user of the cloud service should be responsible for, and which the provider needs to control in order to mitigate cloud computing vulnerabilities for both sides. Different cloud providers have offered varying versions of a user responsibility framework with the goal of nailing down which areas of security the user and the provider are responsible for.
One Cloud Provider’s Solution: The Shared Responsibility Model
AWS is used by over 1,000,000 organizations to aid in processes like content delivery, analytics, AR & VR, computing, storage, and much more. Following their shared responsibility model, Amazon agrees to take responsibility for the security “of” the cloud, including the software behind Amazon’s services, as well as the physical infrastructure where the data from the products lives.
Amazon gives the users of their cloud computing services the responsibility of the security “in” the cloud, which is determined by the level of services they use AWS for. This includes responsibility for who has entry to their cloud platforms, the operating system and integration into a company’s system, as well as the client-side data, including a company’s customer and employee information. As long as Amazon is providing the network and protection of the physical locations where the network servers are stored, their users are responsible for configuring their systems to successfully integrate with Amazon.
So what types of errors and security breaches resulted in the need for a responsibility model? Data shows that 90% of data breaches related to cloud computing vulnerabilities are due to human error. Below are the human error hotspots businesses should prepare for, and how they can use the Amazon-provided model as a framework for where they should take responsibility.
The Biggest Cloud Vulnerabilities: Three Types of Human Errors
Misconfiguration and Integration
One cloud computing vulnerability that has caused companies major headaches is the misconfiguration and integration of a cloud service into their internal platform, a product of a human error. Engineers that have worked with cloud computing systems have frequently noted that system integrations are not always straightforward, and specifically “are not like IKEA”. The Capital One data breach in 2019 is a real-world example of the devastating impacts associated with a misconfiguration by an employee. When Capital One engineers integrated cloud solutions from AWS, human error left a firewall “poorly configured”, allowing hackers to sneak into the system and remain undetected for months. By the tie engineers realized the breach, information from over 106 million credit card customers was already in the hands of hackers.
The shared responsibility model designates a company’s internal employees are responsible for the correct integration of cloud service platforms, which is why Capital One was held accountable for the monetary loss and time spent fixing the error. Needless to say, the Capital One engineers’ pain has warned integration teams everywhere of the need to monitor their cloud service platforms long after the initial introduction into the internal company software.