An enterprise financial institution is establishing a multi-tenant Community Cloud deployment model shared exclusively among partner credit unions to host a real-time collaborative fraud detection platform. The platform is constructed using managed Platform as a Service (PaaS) microservices that process customer transactions. The enterprise security architect must define control boundaries according to the cloud shared responsibility model and Zero Trust principles. Which of the following security responsibilities rests exclusively with the participating organization's security team?
- Defining granular application API authorization policies and managing customer data classification logicAnswer
- BApplying operating system security patches to the physical hypervisor and compute host infrastructure
- CImplicitly trusting all network traffic originating within the private inter-tenant dedicated circuit without application-level authentication
- DConfiguring physical biometric access controls and environmental redundant power units within the shared data center
Answer
Defining granular application API authorization policies and managing customer data classification logic is the sole responsibility of the tenant organization.
Under the cloud shared responsibility model for Platform as a Service (PaaS) and Community Cloud environments, the cloud service provider manages physical facilities, hypervisors, and runtime infrastructure. The participating customer organizations remain exclusively responsible for securing their data, defining data classification schemes, and configuring application-level access control and API authorization policies.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model in PaaS and Community Cloud Deployments