Skip to content
SCA

Cloud Security · Concept

Shared Responsibility Model

Who secures what in the cloud — and how the line shifts with the service model.

Overview

In the cloud, security is shared: the provider secures the infrastructure (“security of the cloud”) and you secure what you put in it (“security in the cloud”). Getting this boundary right is the first step of every cloud-security program.

Where the line sits

The split shifts with the service model:

ModelYou secureProvider secures
IaaSOS, apps, data, IAM, network configHypervisor down
PaaSApps, data, IAMRuntime and OS
SaaSData, access, usageAlmost everything else

The constant

No matter the model, your data, your access control, and your configuration are almost always yours to secure. Most cloud breaches are misconfiguration — not a provider failure.

References

See the primary source below and the Control Explorer.

Primary sources