A company deploys a custom application on virtual machines within an Infrastructure as a Service (IaaS) cloud environment. A critical vulnerability is discovered in the operating system of these virtual machines. According to the shared responsibility model, who is primarily responsible for patching the operating system vulnerability?
-
A
The cloud service provider (CSP), as they manage the underlying infrastructure.
-
B
The customer, as they control the guest operating system and applications.
-
C
The operating system vendor, who is solely responsible for issuing patches.
-
D
Both the CSP and the customer, who must coordinate the patching process together.