Shared Responsibility Model
The Shared Responsibility Model is an arrangement that divides cybersecurity and compliance duties between a cloud service provider (CSP) and the customer that uses its services. In general terms, the provider secures certain parts of the cloud environment while the customer remains responsible for other parts, such as how they configure and use the service. This division is meant to make clear who is accountable for which security tasks and can help reduce the customer's operational burden.
The Shared Responsibility Model is a security and compliance framework, typically formalized as an agreement between a cloud service provider and its customer, that delineates which cybersecurity processes, controls, and responsibilities belong to the CSP and which belong to the customer for a given public cloud deployment. The precise allocation generally varies by service model (for example, infrastructure, platform, or software offerings) and is defined by each provider, so practitioners should confirm the specific boundaries against the applicable CSP's documentation. Note that this model, as described in the provided evidence, is a commercial cloud construct and is not itself a federal control set or authorization; a clear assignment of responsibility does not by itself establish compliance with any particular framework, and readers should verify how a given deployment maps to their governing requirements (such as FedRAMP or DoD authorization obligations) against current authoritative sources.
Why it matters
The Shared Responsibility Model matters because ambiguity over who secures what is a recurring source of cloud risk. When a cloud service provider secures certain layers of the environment and the customer retains responsibility for others, such as how they configure and use the service, gaps can emerge if either party assumes the other has a task covered. A clear division of duties is meant to establish accountability and, as providers such as AWS describe it, can help relieve the customer's operational burden. That said, reducing operational burden is not the same as transferring accountability; the customer generally remains answerable for the portions allocated to them.
For defense and public sector readers, a critical caution applies: the Shared Responsibility Model as described here is a commercial cloud construct, not a federal control set or an authorization. A well-documented split of responsibilities does not by itself establish compliance with any particular framework. Practitioners should not assume that a provider's security of its portion satisfies obligations such as FedRAMP authorization or DoD authorization requirements, and should verify how a given deployment maps to their governing requirements against current authoritative sources.
Because the precise allocation of responsibilities generally varies by service model and is defined by each provider, treating the model as a fixed or universal division is a common mistake. What one provider handles under an infrastructure offering may fall to the customer under a different service model, and the boundaries should be confirmed against the applicable provider's documentation rather than assumed.
Who it's relevant to
Inside SRM
Common questions
Answers to the questions practitioners most commonly ask about SRM.