The shared responsibility model defines how security duties are divided between cloud service providers and their customers, clarifying where one party's obligations end and the other's begin. Understanding this model is essential for IT professionals who rely on third-party vendors to host or manage any part of their infrastructure.
Shared Responsibility Model
As IT professionals, there is a lot of responsibility on us to make sure things are secure, but we are also hiring out certain aspects of the IT infrastructure. We are relying on other companies. And so what we are going to do is share the responsibility when it comes to security. So there is this model called the shared responsibility model, which gives us an idea of where our responsibility ends and then, whatever vendor we are using, where their responsibility begins.
The shared responsibility model is how security responsibility is divided amongst the cloud service provider and its customers. So we are the customers to these cloud service providers. I am going to go and take my services and run my services in these cloud providers. Now we need to understand where my responsibility starts and ends and where their responsibility starts and ends. And so it needs to be clear, and usually there is some sort of document that outlines this, but there is a general kind of outline of where these responsibilities are.
This really outlines that division line. What we have is on premise, which means that we have software and hardware and everything installed locally on our local network. Then there is colocation. Colocation is when we rent space, so we are going to rent space in somebody else's data center and then put our equipment there. Then there is infrastructure as a service, where they are taking care of the whole infrastructure and then we are adding our services on top of that. Then there is platform as a service, and that is when we are utilizing some sort of resources where they take care of most of it, even up through the runtime, and then we are just utilizing the application layer after that. Then there is SaaS, software as a service, where they pretty much take care of it all. We might be responsible for a few of the settings, like maybe making sure the proper people have the right access, but beyond that it really is mostly in their court on what they need to manage from a security perspective.
So this shared responsibility model really outlines what is my responsibility and then what is the cloud service provider's responsibility. And in this case right here, we see what is marked out as being their responsibility in red and what is going to be my responsibility in managing these services.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →