Security 'of' the cloud is everything AWS operates and you cannot touch: facilities, hardware, the hypervisor and the managed service software. Everything you create inside the account — identities, guest operating systems, network rules, data — is security 'in' the cloud and stays yours, which is why a misconfigured security group is never an AWS failure.
Official docs