This whitepaper is for historical reference only. Some content might be outdated and some links might not be available.
Introduction
AWS and its customers share control over the IT environment. Therefore, security is a shared responsibility. When it comes to managing security and compliance in the AWS Cloud, each party has distinct responsibilities. A customer’s responsibility depends on which services they are using. However, in general, customers are responsible for building their IT environment in a manner that aligns with their specific security and compliance requirements.
This paper provides more details about each party’s security responsibilities and the ways customers can benefit from the AWS Risk and Compliance Program.