TechKnowSurge
VideoSecurityFree

Shared Responsibility Model

The shared responsibility model defines how security duties are divided between cloud service providers and their customers, clarifying where one party's obligations end and the other's begin. Understanding this model is essential for IT professionals who rely on third-party vendors to host or manage any part of their infrastructure.

Complete this video to capture a CTF flag worth 1 point.

About this video

The shared responsibility model is a foundational concept in cloud security that defines how security obligations are divided between a cloud service provider and its customers. As organizations move workloads off-premises and into third-party environments, it becomes essential to establish a clear boundary between what the provider manages and what the customer remains accountable for. Without that clarity, critical security functions can fall through the cracks, leaving systems and data exposed. The model applies differently depending on the service type in use. In a fully on-premises environment, the organization owns every layer of security, from physical hardware to the application level. Colocation shifts some physical responsibility to the data center operator while the customer retains control over their own equipment. Infrastructure as a Service transfers hardware and networking responsibilities to the provider, but the customer still manages the operating system, applications, and data. Platform as a Service goes further, with the provider handling the runtime and underlying platform, leaving the customer responsible primarily for their applications and configurations. Software as a Service represents the greatest transfer of responsibility, where the provider manages nearly the entire stack and the customer's obligations are typically limited to access management and data governance. Understanding where each service model places the dividing line is a practical requirement for any IT or security professional working in cloud environments. Most providers document these boundaries formally, but the general framework remains consistent across the industry. Mapping out these responsibilities ensures that security controls are applied at every layer and that neither the provider nor the customer assumes the other is handling something they are not.

What you'll learn

What's covered

Shared Responsibility Model

Key terms

Infrastructure as a Service
IaaS
A cloud service model that provides virtualized computing infrastructure over the internet.
Platform as a Service
PaaS
A cloud service model that provides a platform for developing, running, and managing applications without managing infrastructure.
Software as a Service
SaaS
A cloud service model that delivers software applications over the internet on a subscription basis.
Cloud Computing
The delivery of computing services including servers, storage, and software over the internet on a pay-as-you-go basis.
Shared Responsibility Model
A framework that defines how security responsibilities are divided between a cloud service provider and its customers across different service and deployment models.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.

Topics

Shared Responsibility Model Cloud Security Cloud Computing Iaas Paas Saas

Transcript

As IT professionals, there is a lot of responsibility on us to make sure things are secure, but we are also hiring out certain aspects of the IT infrastructure. We are relying on other companies. And so what we are going to do is share the responsibility when it comes to security. So there is this model called the shared responsibility model, which gives us an idea of where our responsibility ends and then, whatever vendor we are using, where their responsibility begins.

The shared responsibility model is how security responsibility is divided amongst the cloud service provider and its customers. So we are the customers to these cloud service providers. I am going to go and take my services and run my services in these cloud providers. Now we need to understand where my responsibility starts and ends and where their responsibility starts and ends. And so it needs to be clear, and usually there is some sort of document that outlines this, but there is a general kind of outline of where these responsibilities are.

The Division Line

This really outlines that division line. What we have is on premise, which means that we have software and hardware and everything installed locally on our local network. Then there is colocation. Colocation is when we rent space, so we are going to rent space in somebody else's data center and then put our equipment there. Then there is infrastructure as a service, where they are taking care of the whole infrastructure and then we are adding our services on top of that. Then there is platform as a service, and that is when we are utilizing some sort of resources where they take care of most of it, even up through the runtime, and then we are just utilizing the application layer after that. Then there is SaaS, software as a service, where they pretty much take care of it all. We might be responsible for a few of the settings, like maybe making sure the proper people have the right access, but beyond that it really is mostly in their court on what they need to manage from a security perspective.

So this shared responsibility model really outlines what is my responsibility and then what is the cloud service provider's responsibility. And in this case right here, we see what is marked out as being their responsibility in red and what is going to be my responsibility in managing these services.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →