Topic

Cloud Security

Who owns which security task in the cloud, how identity and encryption enforce that ownership, and how governance and compliance prove it holds up under audit.

Cloud Security opens the Security and Reliability domain by answering the question every team eventually gets asked: who is actually responsible for keeping this secure, us or the provider? The topic starts with the shared responsibility model, then follows that boundary into the two controls that enforce it day to day, identity and encryption, before closing with how a team proves any of it to an outside auditor.

What This Topic Covers

  • the shared responsibility model, and how the line between provider and customer duties shifts across IaaS, PaaS, and SaaS
  • identity and access management, including authentication versus authorization, least privilege, roles, and multi-factor authentication
  • encryption at rest and in transit, key management, and where encryption's protection ends
  • governance and compliance, including major frameworks like ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR, and the difference between data residency and data sovereignty

Why It Matters

Nearly every cloud security incident that makes headlines traces back to a team assuming the provider had already handled something that was actually its own job: an exposed storage bucket, an overprivileged access key, unencrypted data on a stolen drive. This topic removes that guesswork. Once you can place a scenario correctly on the shared responsibility model, you can answer "who patches this" and "who configures that" without guessing.

The same boundary reappears at the end of the topic in a different form: a provider's compliance certification covers its own infrastructure, never a customer's application on top of it. Understanding that distinction is what keeps a team from telling its board, or its auditor, something that isn't actually true.

Lessons in this topic

  1. 1The Shared Responsibility ModelFree
  2. 2Identity and Access Management
  3. 3Encryption and Data Protection
  4. 4Governance and Compliance
Send us a message

Have a question about a course, a partnership, or the product? Drop us a line, we reply by email.

We reply within 2 business days.

© 2026 Syllaro Academy. All rights reserved.