Skip to main content

AWS Glossary

AWS Shared Responsibility Model

Framework defining what security and compliance tasks AWS manages versus what customers must manage.

AI & assistant-friendly summary

This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.

Summary

Framework defining what security and compliance tasks AWS manages versus what customers must manage.

Key Facts

  • Framework defining what security and compliance tasks AWS manages versus what customers must manage
  • Definition The AWS Shared Responsibility Model splits security and compliance duties between AWS and the customer
  • AWS is responsible for **security of the cloud** — physical data centers, hypervisor, managed service infrastructure, and global network
  • The split shifts by service type: EC2 puts more on you; S3 and RDS put more on AWS for the underlying stack
  • Compliance certifications (SOC, ISO, HIPAA eligibility) cover AWS's portion; **your** audit still requires customer-side controls

Entity Definitions

Bedrock
Bedrock is an AWS service relevant to aws shared responsibility model.
Lambda
Lambda is an AWS service relevant to aws shared responsibility model.
EC2
EC2 is an AWS service relevant to aws shared responsibility model.
S3
S3 is an AWS service relevant to aws shared responsibility model.
RDS
RDS is an AWS service relevant to aws shared responsibility model.
Aurora
Aurora is an AWS service relevant to aws shared responsibility model.
IAM
IAM is an AWS service relevant to aws shared responsibility model.
EKS
EKS is an AWS service relevant to aws shared responsibility model.
compliance
compliance is a cloud computing concept relevant to aws shared responsibility model.
HIPAA
HIPAA is a cloud computing concept relevant to aws shared responsibility model.

Related Content

Definition

The AWS Shared Responsibility Model splits security and compliance duties between AWS and the customer. AWS is responsible for security of the cloud — physical data centers, hypervisor, managed service infrastructure, and global network. The customer is responsible for security in the cloud — data classification, encryption choices, IAM, network configuration, operating system and application patching (depending on service model), and logging. The split shifts by service type: EC2 puts more on you; S3 and RDS put more on AWS for the underlying stack. Compliance certifications (SOC, ISO, HIPAA eligibility) cover AWS’s portion; your audit still requires customer-side controls.

When to use it

When not to use it

Tips

Gotchas

Serious

Regular

Official references

Need help with this topic?

Our AWS-certified team implements, audits, and optimizes these services in production — from Bedrock RAG pipelines to multi-account landing zones.