# What is the Shared Responsibility Model?

> The shared responsibility model divides security duties between a cloud provider and its customer — the provider secures the cloud itself, while the customer secures what it places and configures in the cloud.

- Canonical URL: https://yellowcube.eu/glossary/shared-responsibility-model/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The exact split shifts by service model: with IaaS the customer owns more of the stack (OS, middleware, data); with SaaS the provider owns more, leaving the customer mainly identities, access, and data. Every provider publishes its own model, and the boundary is always documented per service — never assumed.

### Key points

- **Per-service mapping:** The split differs between IaaS, PaaS, SaaS, and even between individual services from the same vendor.
- **Non-delegable parts:** Identity, access rights, data classification, configuration, and usage remain the customer’s in every model — provider certifications do not cover them.
- **Important limitation:** “Shared” does not mean “halved.” Breaches blamed on providers often trace to customer-side configuration, credentials, or data decisions — the model describes who is accountable, not who is at fault when something fails.

### Related terms

[Cloud security](<https://yellowcube.eu/glossary/cloud-security/>) · [Cloud service models: IaaS, PaaS, and SaaS](<https://yellowcube.eu/glossary/cloud-service-models-iaas-paas-and-saas/>) · [SaaS security](<https://yellowcube.eu/glossary/saas-security/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Managed security service provider (MSSP)](<https://yellowcube.eu/glossary/managed-security-service-provider/>)

### Sources

[CISA, Cybersecurity Best Practices](https://www.cisa.gov/topics/cybersecurity-best-practices) · [CSA, Cloud Controls Matrix](https://cloudsecurityalliance.org/research/cloud-controls-matrix)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

