Under the AWS Shared Responsibility Model, which security control is always the customer's responsibility regardless of the service type used?