Cloud Shared Responsibility Mapper
Control area

Governance and policy: who owns it on each service model

Who decides which data may go into which service, who may buy one, and who answers for it. Each party governs its own side; the allocation between them is the first thing an assessor asks to see.

The split by service model

Service modelOwnerWhy, and the clause
Infrastructure as a servicesharedEach party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1
Platform as a servicesharedEach party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1
Software as a servicesharedEach party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1
Serverless functions and event servicessharedEach party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1
Hosted AI models and AI platformssharedEach party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1

The clauses each framework attaches

7 quoted
FrameworkClause
Cloud Controls Matrix v4.0.1CCM-GRC-06 Governance Responsibility Model
ISO/IEC 27017:2015ISO/IEC 27017 5.1.1 Policies for information security ยท ISO/IEC 27017 6.1.1 Information security roles and responsibilities
SOC 2 Trust Services CriteriaSOC 2 CC1.3 COSO principle 3: Management establishes structures, reporting lines, and authorities
ISO/IEC 27001:2022 Annex AISO/IEC 27001 5.2 Information security roles and responsibilities
CMMC 2.0CMMC CA.L2-3.12.4 System Security Plan
C5 cloud criteria catalogueC5-OIS-01 Information Security Management System (ISMS)
CCM-GRC-06 Governance Responsibility Model

Document who plans, implements, operates, assesses and improves the governance programme, and what each of those roles is accountable for.

What an assessor asks to see:
  • A responsibility model covering plan, implement, operate, assess and improve
  • Named roles or individuals against each
  • Evidence the assessment role is independent of the operate role
  • Review of the model as the organisation changes
Where it usually falls short:
  • Assessment and operation held by the same role, removing independence
  • Model documented at a level too abstract to hold anyone accountable
  • Improvement stage unassigned, so findings never drive change
Source: Cloud Controls Matrix v4.0.1
ISO/IEC 27017 5.1.1 Policies for information security

The cloud service customer's information security policy should address the use of cloud services: which information may be placed in which services, who may procure them, how the customer keeps accountability for information a provider processes, and the provider's obligations the customer expects to see in the agreement. The cloud service provider's policy should cover the security of the cloud service it delivers, including its baseline of protection for customer information, multi-tenancy, customer access to the service's security functions, and the boundary between its responsibilities and the customer's.

What an assessor asks to see:
  • Information security policy with a cloud services section (customer)
  • Provider policy stating the baseline security of the service and the shared-responsibility boundary
  • Approval record and communication of the policy to cloud users or customers
Where it usually falls short:
  • Corporate policy silent on cloud, so business units adopt services with no rule on what data may go there
  • Provider policy that does not state what the customer remains responsible for
Source: ISO/IEC 27017:2015
ISO/IEC 27017 6.1.1 Information security roles and responsibilities

Roles and responsibilities for the security of each cloud service should be allocated between the cloud service customer and the cloud service provider and inside each organisation. The customer should assign who owns the relationship, who manages customer-side controls and who evaluates the provider's information; the provider should state which responsibilities it accepts and which remain with the customer for each service it offers, so that no control falls between the two.

What an assessor asks to see:
  • Responsibility matrix per cloud service naming customer and provider owners
  • Provider service description or terms stating accepted responsibilities
  • Internal role assignments for cloud relationship and control ownership
Where it usually falls short:
  • A control both parties assume the other performs, typically backup, logging or key management
  • Responsibility matrix drafted at onboarding and never updated for new service features
Source: ISO/IEC 27017:2015
SOC 2 CC1.3 COSO principle 3: Management establishes structures, reporting lines, and authorities

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives

What an assessor asks to see:
  • Organisational charts showing structures and reporting lines in the period, with evidence of board oversight of that structure
  • Documented authorities and responsibilities, including delegation of authority limits and who may approve what
  • Job descriptions for roles with internal control or security responsibility
  • Evidence of review of the structure after change, such as reorganisation, acquisition or significant growth
  • Evidence responsibilities for outsourced functions are defined and assigned to an internal owner
Where it usually falls short:
  • Organisation chart current for the audit while the period contained an unrecorded restructure
  • Delegation of authority undocumented, so approvals cannot be tested against a defined limit
  • Outsourced functions treated as the vendor's responsibility with no named internal owner
  • Security responsibility assigned to a role that has no authority over the systems concerned
Source: SOC 2 Trust Services Criteria
ISO/IEC 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

What an assessor asks to see:
  • Role definitions
  • Responsibility matrix
  • Assignment records
  • Authority delegation
Where it usually falls short:
  • Roles not updated after staff changes
  • No documented acceptance of responsibilities
  • Unclear separation between ownership and operational duties
  • Delegated authority not reflected in policy documents
Source: ISO/IEC 27001:2022 Annex A
CMMC CA.L2-3.12.4 System Security Plan Level 2

Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.

What an assessor asks to see:
  • Current system security plan covering boundary, environment, implementation and interconnections
  • Version history showing periodic update
  • Approval record for the current version
Where it usually falls short:
  • Plan describes intent rather than actual implementation
  • Boundary and interconnections omitted or stale
  • No defined update trigger or cadence
Source: CMMC 2.0
C5-OIS-01 Information Security Management System (ISMS)

Operate an information security management system aligned to ISO/IEC 27001 covering the organisational units, sites and processes that deliver the cloud service, and retain documented scope, statement of applicability and the latest management review results.

What an assessor asks to see:
  • ISMS scope statement listing the in scope legal entities, sites and cloud delivery processes
  • Statement of Applicability with inclusion and exclusion justifications for every control
  • Minutes, inputs and decisions of the most recent management review
  • Valid certificate and certification body audit report for the management system
Where it usually falls short:
  • Scope leaves out subsidiaries or data centre sites that in fact operate production components
  • Statement of Applicability not reconciled with the control set actually in force
  • Management review last held more than twelve months ago or held without recorded decisions
Source: C5 cloud criteria catalogue