What Shared Responsibility Model means in practice
Every cloud provider publishes a version of this model, and every provider is asked about it after an incident. The principle is straightforward: the provider is responsible for the security of the cloud, and the customer is responsible for security in the cloud. The complication is that the boundary moves depending on whether the service is infrastructure, platform or software.
With infrastructure as a service — Azure virtual machines, for example — the provider handles physical facilities, hardware and the hypervisor, while the customer handles the guest operating system, patching, network configuration, applications, identity and data. With platform services the provider takes on the operating system and runtime, leaving configuration, access and data with the customer. With software as a service such as Microsoft 365, the provider runs almost the whole stack, but identities, access policy, sharing configuration, retention and the data itself remain the customer's responsibility.
Three things are always the customer's, regardless of service model: the data, the identities and their access rights, and the endpoints used to reach the service. Those three are also where the overwhelming majority of real incidents occur, which is why the model matters practically rather than academically.
The most expensive misunderstandings we encounter are assuming the provider backs up customer data, assuming default configuration is secure configuration, and assuming that because the provider holds certifications the customer's deployment inherits compliance. Certification of the platform reduces the assessment burden; it does not cover how the customer configured it.
The useful exercise is to write the split down for each significant service, name the internal or provider owner for each line, and reconcile it against the managed services contract. Gaps show up quickly, and they are almost always in patching, backup, log retention and identity governance.
How we help with this
Related terms
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
- Conditional AccessConditional Access is the policy engine in Microsoft Entra ID that decides what happens after a sign-in is authenticated.
