Skip to content

Shared Responsibility Model

What is Shared Responsibility Model?

A cloud security framework that delineates security obligations between the cloud service provider and the customer. The provider secures the infrastructure ('security of the cloud'), while the customer secures their data and configurations ('security in the cloud').

Cloud

Each of these is named in at least one of the same controls as shared responsibility model. The number is how many controls name both.

What the standards actually require on shared responsibility model

Requirements naming shared responsibility model across 6 standards, quoted from the control text.

A shared responsibility model is created, documented and shared between suppliers and their customers in order to articulate the security responsibilities of each party.

ISM-1569 · A shared responsibility model is created, documented and shared between suppliers and thei
ISMAP (Japan)1 control

ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...

ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities

Shared responsibility model definition. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Governance.

NIST190-01 · Shared responsibility model definition

Develop and maintain processes and plans for responding to security incidents on cloud platforms, accounting for the shared responsibility model and how it varies across infrastructure, platform and software service models.

ASBv3-IR-1 · Preparation - update incident response plan and handling process

Implement, operate and assess the parts of the shared responsibility model that fall to the organisation, rather than assuming a provider covers them.

CCM-STA-06 · SSRM Control Implementation

GAMP 5 2nd Edition (July 2022) key updates + FDA Computer Software Assurance (CSA) coordination. AI/ML SYSTEMS: dedicated guidance on validation of AI/ML in pharma (predictive maintenance + image analysis + drug discovery + clinical decision support);

GAMP5-2nd-Edition-AI-Cloud-Agile-CSA · 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA)

Questions people ask about shared responsibility model

What is Shared Responsibility Model?
A cloud security framework that delineates security obligations between the cloud service provider and the customer. The provider secures the infrastructure ('security of the cloud'), while the customer secures their data and configurations ('security in the cloud').
Why is Shared Responsibility Model important for compliance?
Shared Responsibility Model is a key concept in Cloud. Understanding shared responsibility model helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Shared Responsibility Model?
Shared Responsibility Model appears in the requirement text of Australian Information Security Manual, ISMAP (Japan), NIST SP 800-190, Azure Security Benchmark, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Shared Responsibility Model?
Explore our compliance framework pages to see how shared responsibility model applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Shared Responsibility Model applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.