- Regions
- Availabilty Zones
- Edge Locations
- Compute
- Storage
- Databases
- Networking
- Client side data encryption and data intergrity authentication
- Server-side encryption
- File system and/or data
- Networking traffic protection
- Ask your self if you can do this in the AWS console.
-
If yes, you are likely responsible
- Security groups
- IAM users
- OS patching
- Database patching
-
if no, AWS is likely responsible
- Data center management
- Data center security
- Data center cabling
-
Encryption is a Shared Responsibility