Cloud Shared Responsibility Mapper
Control area

Data classification and handling: who owns it on each service model

What the data is, how it is labelled, where it may be stored and who may move it. No service model moves this to the provider.

The split by service model

Service modelOwnerWhy, and the clause
Infrastructure as a serviceyoursWhat the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2
Platform as a serviceyoursWhat the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2
Software as a serviceyoursWhat the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2
Serverless functions and event servicesyoursWhat the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2
Hosted AI models and AI platformsyoursWhat the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2

The clauses each framework attaches

8 quoted
FrameworkClause
Cloud Controls Matrix v4.0.1CCM-DSP-04 Data Classification ยท CCM-DSP-19 Data Location
ISO/IEC 27017:2015ISO/IEC 27017 8.2.2 Labelling of information
ISO/IEC 27018:2019ISO/IEC 27018 A.12.1 Geographical location of PII
SOC 2 Trust Services CriteriaSOC 2 C1.1 Confidential information is identified and protected during receipt, processing, storage
ISO/IEC 27001:2022 Annex AISO/IEC 27001 5.12 Classification of information
CMMC 2.0CMMC AC.L2-3.1.3 Control CUI Flow
C5 cloud criteria catalogueC5-PSS-12 Locations of Data Processing and Storage
CCM-DSP-04 Data Classification

Assign each dataset a classification reflecting its type and sensitivity.

What an assessor asks to see:
  • The classification scheme with defined levels and criteria
  • Classification values recorded against datasets
  • Evidence classification drives handling, such as differing controls by level
  • Review records for reclassification
Where it usually falls short:
  • Scheme published but most data left unclassified
  • Classification assigned without any control difference between levels
  • Datasets classified at creation and never reassessed when their content changed
Source: Cloud Controls Matrix v4.0.1
CCM-DSP-19 Data Location

Record the physical locations where data is held, processed and backed up, and be able to produce that record.

What an assessor asks to see:
  • The data location record covering processing, storage and backup sites
  • The method that keeps it current as infrastructure changes
  • Evidence it is available to customers or regulators who may ask
  • Coverage of sub-processor locations
Where it usually falls short:
  • Locations recorded for primary storage with backup and replica locations omitted
  • Record based on contracted regions rather than actual deployment
  • Sub-processor locations unknown
Source: Cloud Controls Matrix v4.0.1
ISO/IEC 27017 8.2.2 Labelling of information

The customer should label information according to its classification before and while it is in a cloud service, using labelling the service can carry, and the provider should describe what labelling capability the service offers and whether labels survive processing. Both should agree how labels are handled where the provider's staff can see customer information.

What an assessor asks to see:
  • Labelling scheme applied to cloud-hosted information
  • Provider documentation of labelling features
  • Test that labels persist through the service
Where it usually falls short:
  • Labels stripped when information is uploaded to a service that cannot carry them
  • No labelling rule for information created inside the cloud service
Source: ISO/IEC 27017:2015
ISO/IEC 27018 A.12.1 Geographical location of PII

The public cloud PII processor should specify and document the countries in which PII can possibly be stored, so that the cloud service customer can assess whether the locations meet its legal and contractual obligations.

What an assessor asks to see:
  • Published or contractual list of countries where PII may be stored
  • Change notification when locations change
Where it usually falls short:
  • Locations stated for primary storage but not backups, support access or sub-contractors
  • Location list not updated when regions are added
Source: ISO/IEC 27018:2019
SOC 2 C1.1 Confidential information is identified and protected during receipt, processing, storage

Identifies and maintains confidential information to meet the entity's objectives related to confidentiality

What an assessor asks to see:
  • The definition of confidential information for the entity, including information designated confidential by customers or by contract
  • Evidence confidential information is identified across the system, covering where it is received, processed, stored and transmitted
  • The protections applied, such as access restriction, encryption and handling rules, tied to the identification
  • Evidence of the retention period applied to confidential information and of its basis
  • Evidence customers are informed of and agree the confidentiality commitments the entity makes
Where it usually falls short:
  • Confidentiality commitments made in contracts that were never translated into an internal definition anyone operates against
  • Confidential information identified in the primary system while copies in analytics, support tooling and non production environments are unidentified
  • Retention undefined, so confidential information is held indefinitely with no basis
  • Protection applied uniformly with no relation to the identification, so the identification step adds nothing
Source: SOC 2 Trust Services Criteria
ISO/IEC 27001 5.12 Classification of information

Classify information by confidentiality, integrity, availability and interested-party requirements.

What an assessor asks to see:
  • Classification policy
  • Classification scheme
  • Labeling guidelines
  • Asset inventory with classification
  • Training records
Where it usually falls short:
  • Classification levels not aligned with business impact
  • Inconsistent labeling across departments
  • Missing periodic review of classifications
  • Unclear ownership for classification decisions
Source: ISO/IEC 27001:2022 Annex A
CMMC AC.L2-3.1.3 Control CUI Flow Level 2

Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.

What an assessor asks to see:
  • Documented CUI flow authorizations and approved flow paths
  • Firewall, proxy, DLP or gateway rules enforcing those flows
  • Data flow diagrams identifying CUI sources, stores and destinations
  • Records of blocked or exception-approved transfers
Where it usually falls short:
  • CUI flows documented but not technically enforced
  • Egress to cloud and email paths unmonitored for CUI
  • No defined authorization for flows to external partners
Source: CMMC 2.0
C5-PSS-12 Locations of Data Processing and Storage

Let the cloud customer choose, from the options available under its contract, the location or country in which its data is processed, stored and backed up, and ensure the cloud architecture itself enforces that choice.

What an assessor asks to see:
  • Contract or ordering options listing the selectable processing and storage regions
  • Architecture documentation showing regional placement is technically enforced
  • Configuration evidence that backup copies remain within the chosen region
  • Record confirming a tenant's actual data placement matches its selection
Where it usually falls short:
  • Primary storage pinned regionally while backups or replicas leave the region
  • Placement honoured by process alone with nothing preventing a cross region deployment
  • Support tooling and telemetry data processed outside the selected location
  • Customers given a choice with no means of verifying where data actually resides
Source: C5 cloud criteria catalogue