{"id":5173,"date":"2024-09-05T18:11:27","date_gmt":"2024-09-05T23:11:27","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/what-is-the-shared-fate-model"},"modified":"2024-09-05T18:11:27","modified_gmt":"2024-09-05T23:11:27","slug":"what-is-the-shared-fate-model","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/05\/what-is-the-shared-fate-model\/","title":{"rendered":"What is the Shared Fate Model?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltce83f3107a4cc92c\/66b01faa9d65e211213135c3\/Data_security%281800%29_ber1a_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold ContentText-BodyTextChunk_italic\">Question: What is the shared fate model, and how does it differ from the shared responsibility model?<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Nick Godfrey, Director of Office of the CISO, Google Cloud:&nbsp;<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Shared responsibility is a framework as old as cloud technology, designed to delineate security and privacy responsibilities between cloud service providers (CSPs) and their customers. For example, the CSP would be responsible for the physical environments that underpin the cloud, while the customer would be responsible for identity and access management. The problem with this model is that these rigid boundaries lead to gaps in security if either party fails to fulfill their role effectively.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the end of the day, if an organization has a security issue related to their operational responsibilities as part of the shared responsibility model, it&#8217;s also a problem for cloud providers. Today&#8217;s security landscape is more complex than ever before; new AI-powered threats, a growing talent shortage, and increasing regulatory pressures call for CSPs to go beyond the restricted shared responsibility framework and support a more resilient model \u2013 we call it &#8220;shared fate.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The shared fate model is centered on the customer&#8217;s needs, where the CSP leverages its expertise to play an active role in the customer&#8217;s security. This model provides enhanced support for organizations in three key ways:<\/span><\/p>\n<div data-component=\"basic-list\" class=\"BasicList BasicList_nestedLevel_0 BasicList_variant_ordered BasicList_limited\">\n<ol data-testid=\"basic-list-ordered\" class=\"BasicList-OrderedList BasicList-OrderedList_nestedLevel_0 body-normal\">\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_ordered\" readability=\"7.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_ordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"10\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Enhanced Collaboration: <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This model fosters a partnership where both cloud provider and customer work collaboratively to ensure a secure environment. Providers are not just delineating responsibilities but actively supporting the customer&#8217;s security posture. This results in a more integrated and supportive approach to managing risks.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_ordered\" readability=\"11\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_ordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"17\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Actionable Steps and Guidance: <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Through frameworks and best practices, providers can establish actionable steps and guidance to help customers meet policy, regulatory, and business objectives. This includes resources for securing data, access control, and threat protection. Offering customers tailored resources, advice, and support can significantly reduce the burden of implementing and managing complex security measures independently.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"BasicList-ListItem BasicList-ListItem_variant_ordered\" readability=\"8.5\"><span data-component=\"icon\" data-name=\"Circle\" class=\"BasicList-ListIcon BasicList-ListIcon_variant_ordered\"><\/span><\/p>\n<div class=\"BasicList-Item\" readability=\"12\">\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Robust Defaults for Cloud Services: <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The shared fate model suggests a CSP focus on delivering robust defaults for cloud services. This requires cloud providers to build products that are secure by design and secure by default, helping customers with the toil of securing their environment, not adding to it.<\/span><\/p>\n<\/div>\n<\/div>\n<\/li>\n<\/ol>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The shift from a shared responsibility model to a shared fate model creates a more collaborative approach to security. Of course, there will always be some responsibility on the customer for their security, as no cloud provider can claim accountability for 100% of an organization&#8217;s security or activity in the cloud. The difference with shared fate is that, under this approach, the cloud provider plays a significantly more active role in the customer&#8217;s security \u2013 to the point where, if something were to go wrong, the cloud provider would be heavily invested and can better support the customer through that journey. By having cloud providers and customers work closely together, we&#8217;re creating an environment that fosters a more integrated, and overwhelmingly more secure landscape and stronger cyber strategy.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/what-is-the-shared-fate-model\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Question: What is the shared fate model, and how does<\/p>\n","protected":false},"author":12,"featured_media":5174,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=1816%2C1121&ssl=1",1816,1121,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=300%2C185&ssl=1",300,185,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=640%2C395&ssl=1",640,395,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=640%2C395&ssl=1",640,395,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=1536%2C948&ssl=1",1536,948,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=1816%2C1121&ssl=1",1816,1121,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=1024%2C632&ssl=1",1024,632,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/what-is-the-shared-fate-model.jpg?fit=1816%2C1121&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5173"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5173\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5174"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}