In the NIST model, the cloud infrastructure is provisioned for open use by the general public, operated by a cloud provider, and located on the provider’s premises. “Public” describes who may subscribe, not whether each customer resource is internet-accessible.
The provider operates the service, but customer responsibility varies across infrastructure, platform, and software services. Customers must identify inherited, shared, configurable, and unavailable controls; protect tenant administration; and assess provider isolation, resilience, data handling, support, and incident obligations.
Key points
Service selectionMatch data sensitivity, availability, location, portability, legal, and recovery needs to the provider, service model, contract, evidence, and controls.
Tenant operationApply strong administrative authentication, least privilege, defaults, exposure controls, encryption and key decisions, configuration review, logging, backup, and incident procedures.
Data and resilienceTrack copies, subprocessors, regions, deletion behavior, quotas, dependencies, and exit formats; plan for account compromise, disruption, and provider incidents.
Important limitationProvider certification or secure infrastructure does not establish that a customer tenant, identity policy, application, or dataset is secure. Public cloud is not inherently public-facing or less isolated than private infrastructure. Private endpoints still depend on provider controls and customer configuration.