Shared Responsibility Model for IAM
What I am responsible for and what AWS is responsible for when it comes to IAM.
Key takeaways
| Infrastructure (global network security) | Users, Groups, Roles, Policies management and monitoring |
| Configuration and vulnerability analysis | Enable MFA on all accounts |
| Compliance validation | Rotate all your keys often |
| Use IAM tools to apply appropriate permissions | |
| Analyze access patterns & review permissions |
This is a very simple example, but an obvious one. AWS is responsible for all the infrastructure, and you are responsible for how you use that infrastructure.