Framework that defines clear allocation of security, compliance and operational responsibilities between cloud providers and customers.
Defines allocation of responsibilities between cloud provider and customer for security, compliance and operations. It clarifies which controls the provider manages (infrastructure, physical security, global services) and which remain with the customer (data, identity, configurations). Widely used for public cloud, SaaS and managed services to reduce gaps and define governance.
Counts services with a written responsibility model.
Time between incident detection and assignment of clear ownership.
Measures available evidences for provider and customer controls.
AWS defines the separation between infrastructure and customer responsibilities for cloud services.
Marketing uses a SaaS tool; backup and access management remain customer-managed.
A cloud data lake combines provider and customer responsibilities for encryption and access control.
Inventory all used cloud and SaaS services and map providers.
Develop a responsibility matrix per service with provider and customer duties.
Adjust runbooks, operational and security processes according to the matrix.
Clarify open contractual points and schedule regular reviews.