A regional financial institution migrates its customer ticketing platform to a public cloud provider under a Software as a Service (SaaS) model. During an architectural security review, the team evaluates operational duties under the cloud shared responsibility model. Which of the following security controls remains the sole responsibility of the financial institution?
- Managing user identity lifecycles, access role assignments, and data classification policiesCevap
- BPatching and applying security updates to the application software and host operating systems
- CConfiguring hypervisor security settings and physical host network infrastructure
- DGranting implicit trust and unrestricted access to requests originating from the internal enterprise network
Cevap
Managing user identity lifecycles, access role assignments, and data classification policies remains the sole responsibility of the institution.
Under the cloud shared responsibility model for Software as a Service (SaaS), the cloud service provider manages all lower-tier components including physical security, infrastructure hardware, hypervisors, operating systems, and application code. The customer maintains full responsibility for managing their own data, classifying sensitivity levels, and configuring identity and access management (IAM) policies.
Adım Adım Çözüm
Anahtar Kavram
Cloud Shared Responsibility Model in SaaS
Tahmini Süre:1m 15s