Governance and policy: who owns it on each service model
Who decides which data may go into which service, who may buy one, and who answers for it. Each party governs its own side; the allocation between them is the first thing an assessor asks to see.
The split by service model
| Service model | Owner | Why, and the clause |
|---|---|---|
| Infrastructure as a service | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
| Platform as a service | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
| Software as a service | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
| Serverless functions and event services | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
| Hosted AI models and AI platforms | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
The clauses each framework attaches
7 quoted| Framework | Clause |
|---|---|
| Cloud Controls Matrix v4.0.1 | CCM-GRC-06 Governance Responsibility Model |
| ISO/IEC 27017:2015 | ISO/IEC 27017 5.1.1 Policies for information security ยท ISO/IEC 27017 6.1.1 Information security roles and responsibilities |
| SOC 2 Trust Services Criteria | SOC 2 CC1.3 COSO principle 3: Management establishes structures, reporting lines, and authorities |
| ISO/IEC 27001:2022 Annex A | ISO/IEC 27001 5.2 Information security roles and responsibilities |
| CMMC 2.0 | CMMC CA.L2-3.12.4 System Security Plan |
| C5 cloud criteria catalogue | C5-OIS-01 Information Security Management System (ISMS) |
CCM-GRC-06 Governance Responsibility ModelDocument who plans, implements, operates, assesses and improves the governance programme, and what each of those roles is accountable for.
- A responsibility model covering plan, implement, operate, assess and improve
- Named roles or individuals against each
- Evidence the assessment role is independent of the operate role
- Review of the model as the organisation changes
- Assessment and operation held by the same role, removing independence
- Model documented at a level too abstract to hold anyone accountable
- Improvement stage unassigned, so findings never drive change
ISO/IEC 27017 5.1.1 Policies for information securityThe cloud service customer's information security policy should address the use of cloud services: which information may be placed in which services, who may procure them, how the customer keeps accountability for information a provider processes, and the provider's obligations the customer expects to see in the agreement. The cloud service provider's policy should cover the security of the cloud service it delivers, including its baseline of protection for customer information, multi-tenancy, customer access to the service's security functions, and the boundary between its responsibilities and the customer's.
- Information security policy with a cloud services section (customer)
- Provider policy stating the baseline security of the service and the shared-responsibility boundary
- Approval record and communication of the policy to cloud users or customers
- Corporate policy silent on cloud, so business units adopt services with no rule on what data may go there
- Provider policy that does not state what the customer remains responsible for
ISO/IEC 27017 6.1.1 Information security roles and responsibilitiesRoles and responsibilities for the security of each cloud service should be allocated between the cloud service customer and the cloud service provider and inside each organisation. The customer should assign who owns the relationship, who manages customer-side controls and who evaluates the provider's information; the provider should state which responsibilities it accepts and which remain with the customer for each service it offers, so that no control falls between the two.
- Responsibility matrix per cloud service naming customer and provider owners
- Provider service description or terms stating accepted responsibilities
- Internal role assignments for cloud relationship and control ownership
- A control both parties assume the other performs, typically backup, logging or key management
- Responsibility matrix drafted at onboarding and never updated for new service features
SOC 2 CC1.3 COSO principle 3: Management establishes structures, reporting lines, and authoritiesManagement establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives
- Organisational charts showing structures and reporting lines in the period, with evidence of board oversight of that structure
- Documented authorities and responsibilities, including delegation of authority limits and who may approve what
- Job descriptions for roles with internal control or security responsibility
- Evidence of review of the structure after change, such as reorganisation, acquisition or significant growth
- Evidence responsibilities for outsourced functions are defined and assigned to an internal owner
- Organisation chart current for the audit while the period contained an unrecorded restructure
- Delegation of authority undocumented, so approvals cannot be tested against a defined limit
- Outsourced functions treated as the vendor's responsibility with no named internal owner
- Security responsibility assigned to a role that has no authority over the systems concerned
ISO/IEC 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
- Role definitions
- Responsibility matrix
- Assignment records
- Authority delegation
- Roles not updated after staff changes
- No documented acceptance of responsibilities
- Unclear separation between ownership and operational duties
- Delegated authority not reflected in policy documents
CMMC CA.L2-3.12.4 System Security Plan Level 2Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.
- Current system security plan covering boundary, environment, implementation and interconnections
- Version history showing periodic update
- Approval record for the current version
- Plan describes intent rather than actual implementation
- Boundary and interconnections omitted or stale
- No defined update trigger or cadence
C5-OIS-01 Information Security Management System (ISMS)Operate an information security management system aligned to ISO/IEC 27001 covering the organisational units, sites and processes that deliver the cloud service, and retain documented scope, statement of applicability and the latest management review results.
- ISMS scope statement listing the in scope legal entities, sites and cloud delivery processes
- Statement of Applicability with inclusion and exclusion justifications for every control
- Minutes, inputs and decisions of the most recent management review
- Valid certificate and certification body audit report for the management system
- Scope leaves out subsidiaries or data centre sites that in fact operate production components
- Statement of Applicability not reconciled with the control set actually in force
- Management review last held more than twelve months ago or held without recorded decisions