Cloud providers secure the data centres, hypervisors and managed services; everything you configure on top is your responsibility. This "shared responsibility model" is why most cloud breaches are not exotic exploits but a public bucket, an over-privileged access key, or an SSH port open to the internet. A handful of settings, applied consistently, prevents nearly all of them.
In this lesson you will learn how to structure identity and access management, keep storage private by default, segment the network, and use logging and scanning to catch drift. Examples use AWS names; every major provider has direct equivalents.
IAM decides who can do what to which resource, and it is where least privilege matters most. The sample policy grants an application exactly two capabilities on exactly two resources; compare that with the common shortcut of attaching an administrator policy "to get it working".
"Resource": "*" is a finding, not a policy. Access analysers report unused permissions; remove what is not used within 90 days.Object storage is where the biggest leaks happen, because a single setting makes an entire bucket world-readable.
# Enforce private-by-default for the whole account
aws s3control put-public-access-block --account-id 123456789012 \
--public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true# Encryption at rest and versioning for recovery from deletion or ransomware
aws s3api put-bucket-encryption --bucket shop-uploads-prod \
--server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"aws:kms"}}]}'
aws s3api put-bucket-versioning --bucket shop-uploads-prod --versioning-configuration Status=EnabledServe user files through short-lived presigned URLs or a CDN with signed access, never by making the bucket public. Apply the same rules to database snapshots, disk images and backups.
0.0.0.0/0.You cannot detect misuse of an account whose activity is not recorded:
# Account-wide API audit trail into a locked-down bucket, and a config rule that flags public buckets
aws cloudtrail create-trail --name org-trail --s3-bucket-name audit-logs-prod --is-multi-region-trail
aws configservice put-config-rule --config-rule '{"ConfigRuleName":"s3-no-public-read","Source":{"Owner":"AWS","SourceIdentifier":"S3_BUCKET_PUBLIC_READ_PROHIBITED"}}'trivy image shop-api:1.4.2) and rebuild them on base-image security releases.Define all of this as infrastructure as code so every change is reviewed and drift shows up in a pull request, not in an incident.
Under the shared responsibility model, who is responsible for a storage bucket that was configured to be publicly readable?
Next lesson: Privacy and Data Protection: GDPR and DPDP for Developers — the legal side of handling personal data, translated into engineering tasks.