The Shared Responsibility Model defines who handles what in cloud security:

The line between responsibilities shifts depending on the cloud service model you’re using: SaaS, PaaS, IaaS.

  • Cloud provider: Secures the infrastructure.
  • You (the customer): Secures your usage — data, access, config.

Who’s Responsible for What?

Service ModelProvider HandlesYou Handle
SaaSInfra, app, OS, runtimeUsers, data, permissions, configs
PaaSInfra, OS, runtimeApp code, data, IAM, environment settings
IaaSInfra, networking, hypervisorOS patching, firewall, data, access, monitoring

Further Resources:

https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai