Shared Responsibility Model Explained: IaaS, PaaS and SaaS for Security+
Every cloud contract contains a division of labor that most people only discover after something goes wrong. The shared responsibility model — also called the cloud responsibility matrix — is that division written down: which security tasks belong to the cloud service provider, and which remain yours. The provider secures the cloud. You secure what you put in it. Where the line falls depends entirely on the service model. It is the single most tested cloud security concept on CompTIA exams, and the reason is practical: the overwhelming majority of cloud breaches are customer-side misconfigurations, not provider failures. Understanding the line is what prevents assuming someone else is handling something nobody is handling. What Never Changes Regardless of service model, the provider is always responsible for the physical layer: data centers, physical access control, power, cooling, the host hardware, and the virtualization layer underneath your workloads. You cannot audit the...