Defines allocation of responsibilities between cloud provider and customer for security, compliance and operations. It clarifies which controls the provider manages (infrastructure, physical security, global services) and which remain with the customer (data, identity, configurations). Widely used for public cloud, SaaS and managed services to reduce gaps an…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
The shared responsibility model divides security and operational duties between a cloud provider and its customer.
The model grew with the move of IT infrastructure into the cloud. AWS describes the provider as protecting the cloud infrastructure while the customer remains responsible, depending on the service, for configuration, data, and access; Microsoft describes the same shift across service types.
Think of a building with shared responsibility: the landlord secures the structure and utilities, while the tenant locks its rooms and protects its contents.
Responsibilities are divided across cloud layers.
Helps define controls and ownership.
It prevents blind spots in cloud security and compliance. The exact split depends on the service and still requires concrete control checks.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.