Cloud Shared Responsibility Mapper
Control area

Physical and environmental: who owns it on each service model

The buildings, power, cooling and the disposal of storage media. On every public cloud model this is the provider's, and the evidence is its assurance report.

The split by service model

Service modelOwnerWhy, and the clause
Infrastructure as a servicethe provider'sThe data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7
Platform as a servicethe provider'sThe data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7
Software as a servicethe provider'sThe data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7
Serverless functions and event servicesthe provider'sThe data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7
Hosted AI models and AI platformsthe provider'sThe data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7

The clauses each framework attaches

5 quoted
FrameworkClause
Cloud Controls Matrix v4.0.1CCM-DCS-09 Secure Area Authorization
ISO/IEC 27017:2015ISO/IEC 27017 11.2.7 Secure disposal or re-use of equipment
SOC 2 Trust Services CriteriaSOC 2 CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
CMMC 2.0CMMC PE.L2-3.10.1 Limit Physical Access
C5 cloud criteria catalogueC5-PS-04 Physical site access control
CCM-DCS-09 Secure Area Authorization

Admit only authorised people to secure areas, restrict and monitor every entry and exit point with physical access mechanisms, and retain the access records for the period the organisation has set.

What an assessor asks to see:
  • The authorised access list per secure area and its review records
  • Physical access control configuration covering ingress and egress
  • Access logs retained for the defined period
  • Records of access reviews and removals
Where it usually falls short:
  • Egress not controlled or monitored, only entry
  • Access list never reviewed, so leavers retain badge rights
  • Retention period undefined, so logs are purged inconsistently
Source: Cloud Controls Matrix v4.0.1
ISO/IEC 27017 11.2.7 Secure disposal or re-use of equipment

The provider should arrange for secure disposal or re-use of equipment that has held customer information, so that customer data cannot be recovered from storage that is retired or reassigned to another tenant, and should tell customers about the arrangement. The customer should confirm that the provider's disposal practice meets its requirements for the information it places in the service.

What an assessor asks to see:
  • Provider media sanitisation and disposal procedure
  • Disposal or destruction records
  • Customer review of the provider's disposal statement
Where it usually falls short:
  • Storage reassigned between tenants without sanitisation
  • Customer requirement for certified destruction not passed to the provider
Source: ISO/IEC 27017:2015
SOC 2 CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives

Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives

What an assessor asks to see:
  • List of facilities and protected information assets in scope, including data centre space, back-up media storage and other sensitive locations
  • Authorisation records showing who is permitted physical access to each location and on what basis
  • Access control system configuration and badge listings for those locations, reconciled against the authorisation records
  • Records of periodic review of physical access rights and of removals made as a result
  • Visitor and third party access records for the same locations, including escort evidence
Where it usually falls short:
  • Primary data centre well controlled while back-up media storage and offsite locations rely on a provider attestation with no entity level review
  • Physical access rights reviewed less often than logical access, so leavers keep badge access after their accounts are disabled
  • Sensitive locations such as network rooms and media handling areas omitted from the scope list entirely
Source: SOC 2 Trust Services Criteria
CMMC PE.L2-3.10.1 Limit Physical Access Level 1 and 2

Limit physical access to systems, equipment and their operating environments to authorized individuals.

What an assessor asks to see:
  • Physical access authorization list for controlled areas
  • Access control mechanism evidence such as badge system configuration
  • Periodic review of who holds physical access
Where it usually falls short:
  • Access lists not reviewed so departed staff retain badges
  • Server and equipment areas within general office access
  • Authorization granted verbally without record
Source: CMMC 2.0
C5-PS-04 Physical site access control

Control entry at every access point using an access control system whose documented rules grant least privilege authorisations, revoke unused rights after two and six months, enforce two factor authentication for areas holding customer data, escort visitors and log all entries.

What an assessor asks to see:
  • Badge system export showing authorisation holders per security area
  • Report of automatically revoked credentials with the recorded inactivity dates
  • Visitor register with escort names and pass return times
  • Door reader event log for a sampled high security room
Where it usually falls short:
  • Dormant contractor badges still active well past the stated inactivity limit
  • Two factor reader on the machine room door bypassed through an adjacent office door
  • Visitors recorded at reception yet not tracked by the badge system inside the building
  • No periodic reconciliation of badge holders against current job roles
Source: C5 cloud criteria catalogue