It applies to custom applications, managed software services, and applications moved to cloud infrastructure, across design, development, deployment, administration, use, monitoring, response, and retirement.
Responsibility varies by service model and contract, but customers retain duties for areas such as identities, tenant configuration, data, and permitted use. Effective practice joins application-security testing with cloud configuration, access control, data protection, integration governance, logging, and response according to the application’s actual architecture.
Key points
Design and deliveryModel threats, define trust boundaries, review architecture, secure code and dependencies, test controls, protect deployment pipelines, and establish safe release and rollback processes.
Identity and dataApply least privilege to people and services, manage secrets and keys, validate authorization, classify data, constrain sharing, and protect data in transit and at rest.
Operations and integrationsHarden tenant and application settings, inventory interfaces and connected applications, monitor meaningful events, correct vulnerabilities and drift, and rehearse provider-aware response and recovery.
Important limitationProvider controls do not secure customer code, identities, configurations, or integrations automatically. A cloud access security broker (CASB) sees only supported paths, while encryption cannot prevent misuse at an authorized endpoint.