Cloud Security Shared Responsibility Model

The cloud security model is shared between the cloud service provider and the customer.

The provider is responsible for securing the infrastructure beneath the customer workload, including physical facilities, network infrastructure, virtualization layers, and some core platform controls. The customer is responsible for security in the cloud, including identity and access, application security, data protection, configuration hygiene, and governance.

Examples of Shared Responsibilities

LayerProvider ResponsibilityCustomer Responsibility
Physical securityData center securityNone
NetworkCore network and connectivitySecurity groups, routing, firewall configuration
VirtualizationHypervisor infrastructureVM hardening and workload protection
Operating systemManaged platform servicesOS patching, access control
ApplicationPlatform servicesApp logic and secure development
DataStorage platform protectionClassification, encryption, retention
Identity & accessIAM platformUser provisioning, policies, least privilege

Security Controls

The model requires organizations to align identity, governance, configuration, monitoring, and auditing practices with the cloud provider’s model.