The Acquia Cloud leverages a shared responsibility model for security in the cloud. At the infrastructure layer Acquia Cloud is built within Amazon’s AWS cloud environment and leverages Amazon’s Elastic Compute Cloud (EC2), Amazon Simple Storage Service (S3) and Elastic Block Store (EBS) technology. As such Acquia Cloud leverages Amazon’s certifications and accreditations for the infrastructure, network and physical security layers of the environment. Amazon personnel have no logical access to Acquia Cloud hosts or applications.
Acquia builds, manages, monitors, and secures the Operating System and LAMP stack layers of Acquia Cloud. At the application layer, depending on the customers requirements and preference, a third party developer may be employed, Acquia may have responsibility or the customer’s staff may have responsibility for ensuring application layer security controls such as account provisioning, access and ensuring secure coding, testing and change control best practices are employed.