Full SANS Webcast | Decoding the Shared Responsibility Model: Securing Cloud Environments Together

Full SANS Webcast | Decoding the Shared Responsibility Model: Securing Cloud Environments Together

Source: YouTube · SANS Cloud Security · published Jun 17, 2025 · 49:15

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

Serge Borso explains that in cloud computing, responsibility for security is shared between the provider and the customer, with the core principle being that customers are responsible for securing whatever they control.

Key Takeaways:
• Borso introduces his 20+ years of experience as a SANS instructor and CEO of Spider, noting that while he knows much, he doesn't know everything in this vast field 0:00-0:55.
• The shared responsibility model dictates that customers secure what they control (e.g., OS, data, IAM), while providers secure the underlying infrastructure (e.g., physical data centers, hypervisors) 0:55-3:00.
• AWS uses "security of the cloud" vs. "security in the cloud"; Azure emphasizes identity as the primary perimeter; GCP calls it the "shared fate" model, implying mutual risk in breaches 3:00-6:00.
• In Infrastructure as a Service (IaaS), customers manage patching and configuration (e.g., EC2 OS, SSH ports); in Platform as a Service (PaaS), providers handle OS patching, but customers remain liable for application code vulnerabilities 6:00-9:00.
• For Software as a Service (SaaS) like M365, providers secure the platform, but customers must manage identity (MFA) and data loss prevention (DLP) 9:00-12:00.
• Borso highlights that while providers offer robust tools (CloudTrail, Sentinel), customers must actively configure and analyze them; he also notes GCP's Gemini leads in current AI utility for security tasks 12:00-15:00.

Ultimately, leveraging cloud security requires customers to actively use provider tools and adhere to best practices, as availability of services does not equate to automated protection.

Sources:

  • [0:00](http

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

My name is Serge Borso and I am a SANS certified instructor. I've been with SANS for about a decade or over a decade, a little over a decade now. Uh I taught classes way back in the day like uh SEK 542, web app pen testing, ethical hacking and here I am now teaching 488 which is our cloud security essentials course and I'm also the author for SEC 480 which is an ad secure build course. Outside of SANS, I've been in this industry for a little over 20 years now. And that's doing things anywhere from security awareness training in-house to system security to, you know, hardening endpoints to network security to application security, penetration testing, red teaming, purple teaming. And that's what I do now probably more more than anything else at least in terms of leading a team. And what I m…