01Introduction
Every major cloud provider publishes the same message in different words: we secure the cloud, you secure what you put in it. Most cloud breaches happen on the customer's side of that line.
02What is Shared responsibility model?
The shared responsibility model is the division of security duties between a cloud provider and its customer. The provider secures the physical data centers, hardware, hypervisor and core services. The customer secures identities, configuration, data, applications and, depending on the service, operating systems and networks.
03How Shared responsibility model works
The customer's share depends on how much of the stack they run.
- 1.
IaaS
You manage operating systems, patching, network rules, identities, applications and data. See patch management.
- 2.
PaaS and containers
The provider manages the runtime, you manage configuration, code, identities and data. See KSPM.
- 3.
Serverless
You own function code, permissions, triggers and the data they touch.
- 4.
SaaS
You own user access, sharing settings, integrations and data governance.
04Threats and risks
Breaches cluster where teams assume someone else is responsible.
Assumed defaults
Believing the provider makes storage private or encrypts everything by default.
Misconfiguration
Public resources and open network rules, the most common cause of cloud breaches.
Identity sprawl
Over-permissioned roles that are always the customer's responsibility.
Compliance gaps
Relying on the provider's certification for controls that frameworks such as SOC 2 and FedRAMP expect you to own.
05How Parameter helps
Parameter is built for the customer side of the line.
Your configuration
Cloud Security finds the misconfigurations and identity paths in your AWS, Google Cloud, Azure and Oracle Cloud accounts.
Your applications
The pentesting agents test the code you deploy on top of the provider.
Proof for auditors
Evidence maps to frameworks on the compliance pages.

