Short answer: A cloud provider secures parts of the underlying service, while the customer remains responsible for decisions such as identities, data, configuration, workloads, and access. The exact boundary depends on the provider and service model, so an SME should document the responsibility for each important service instead of relying on a generic diagram.
Start with the service, not the provider name
Record the cloud service, service model, region, business owner, data handled, and provider documentation used for the review. Responsibilities can change between infrastructure, platform, and software services, and between configurations within the same service.
Record the customer responsibilities
For each important service, identify who owns:
- Identity and privileged access.
- Tenant, network, and security configuration.
- Data classification, retention, and sharing.
- Workload code, dependencies, and secrets.
- Logging, monitoring, and incident reporting.
- Backup, recovery, and continuity decisions.
- Supplier review and contract requirements.
The provider’s controls may support these outcomes, but they do not automatically prove that the customer configured or operated its part correctly.
Turn the boundary into evidence
Link each responsibility to a policy, procedure, control owner, and operating record. Useful records may include access reviews, configuration reviews, restore tests, alert investigations, supplier assessments, and change approvals. Keep the provider’s responsibility documentation with the review record and note the date and service scope.
Review after change
Recheck the responsibility record when a service, plan, region, data flow, owner, or provider contract changes. Review it after an incident or material configuration change as well.
Sources and further reading
- AWS Shared Responsibility Model
- Microsoft Azure shared responsibility
- Google Cloud shared responsibility
Practical example
For a managed database, the cloud provider may operate the underlying service, while the customer still configures identities, network access, data protection, backups, and logging. The service record should name each customer responsibility and its owner instead of copying a provider diagram.
FAQ
Does the cloud provider handle all security?
No. Responsibility depends on the service model. Customers still own many identity, configuration, data, workload, and access decisions.
What should an SME document for each cloud service?
Record the service, data, owner, provider boundary, customer responsibilities, evidence, dependencies, and review trigger.
How Framework Pro fits
Aneo Framework Pro uses questionnaire answers and business context to generate tailored, editable security policy drafts and supporting readiness documents. The outputs still require human review, approval, implementation, and evidence. They do not certify a business, guarantee compliance, replace controls, or provide legal advice.
