A library consortium runs Platform as a Service web apps and argues that nobody on staff needs to do security work anymore. Which customer responsibilities still apply on PaaS?
Select an answer to reveal the explanation.
Short Explanation
PaaS is like a managed restaurant kitchen where the landlord keeps the appliances working, but you still decide who gets keys and what recipes go on the menu. Libraries still own data, access, and app configuration. Thinking security ends at PaaS signup leaves the front door wide open.
Full Explanation
Under PaaS, the provider typically manages operating systems and runtime platforms, but customers remain responsible for their data, identity and access controls, and application-level configuration and code security. Claiming that PaaS eliminates all security work misunderstands the shared-responsibility model. Physical facility and host controls stay with the provider, yet application and data risk remain with the consortium.