Cloud Shared Responsibility Mapper
Control area

Supplier and subservice: who owns it on each service model

The shared responsibility model itself: the provider publishes its side and its own suppliers, you hold the matrix for your estate and the agreement that binds both.

The split by service model

Service modelOwnerWhy, and the clause
Infrastructure as a servicesharedThe provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1
Platform as a servicesharedThe provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1
Software as a servicesharedThe provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1
Serverless functions and event servicessharedThe provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1
Hosted AI models and AI platformssharedThe provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1

The clauses each framework attaches

12 quoted
FrameworkClause
Cloud Controls Matrix v4.0.1CCM-STA-04 SSRM Control Ownership · CCM-STA-06 SSRM Control Implementation
ISO/IEC 27017:2015ISO/IEC 27017 CLD.6.3.1 Shared roles and responsibilities within a cloud computing environment · ISO/IEC 27017 15.1.2 Addressing security within supplier agreements
CSA STAR programmeSTAR-SHARED-01 Shared responsibility disclosure
ISO/IEC 27018:2019ISO/IEC 27018 A.8.1 Disclosure of sub-contracted PII processing
SOC 2 Trust Services CriteriaSOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls
ISO/IEC 27001:2022 Annex AISO/IEC 27001 5.23 Information security for use of cloud services
CMMC 2.0CMMC AC.L2-3.1.20 External Connections
FedRAMP ModerateFedRAMP SA-9 External System Services · FedRAMP CA-3 Information Exchange
C5 cloud criteria catalogueC5-SSO-01 Policies and instructions for controlling and monitoring third parties
CCM-STA-04 SSRM Control Ownership

State, control by control, which responsibilities sit with the provider, which sit with the customer and which are shared for the service offered.

What an assessor asks to see:
  • The control by control responsibility matrix for the service
  • Evidence every control in the framework carries an ownership determination
  • The basis for each shared designation
  • Review of the matrix as the service changes
Where it usually falls short:
  • Matrix covering a subset of controls with the rest left undetermined
  • Controls marked shared with no explanation of the split
  • Matrix not updated after a service change altered the boundary
Source: Cloud Controls Matrix v4.0.1
CCM-STA-06 SSRM Control Implementation

Implement, operate and assess the parts of the shared responsibility model that fall to the organisation, rather than assuming a provider covers them.

What an assessor asks to see:
  • Evidence of implementation for each customer-side responsibility
  • Operating records showing the controls run
  • Assessment or audit results covering those controls
  • Ownership assigned per responsibility
Where it usually falls short:
  • Customer-side responsibilities documented but not implemented
  • Implementation assumed from a provider certification that does not cover it
  • No assessment, so effectiveness of the customer side is unknown
Source: Cloud Controls Matrix v4.0.1
ISO/IEC 27017 CLD.6.3.1 Shared roles and responsibilities within a cloud computing environment

Responsibilities for information security in the use of a cloud service are shared, and the standard requires that they be allocated to identified parties, documented, communicated and implemented by both the cloud service customer and the cloud service provider. The provider should document and publish the responsibilities it takes on and those it leaves with the customer; the customer should record the allocation, assign owners inside its organisation, and act on its share.

What an assessor asks to see:
  • Shared responsibility document for each cloud service, agreed by both parties
  • Communication of the allocation to the customer's users and the provider's staff
  • Evidence the customer performs its allocated responsibilities
Where it usually falls short:
  • A published provider responsibility model that the customer never mapped to its own roles
  • Allocation that names organisations but no individuals
Source: ISO/IEC 27017:2015
ISO/IEC 27017 15.1.2 Addressing security within supplier agreements

The agreement between customer and provider should set out the information security requirements for the cloud service, including the responsibilities of each party, the provider's controls, handling of customer information, incident notification, the customer's rights to information and audit, and what happens at termination. The provider should offer terms that state these, and the customer should confirm the agreement covers its requirements before it uses the service.

What an assessor asks to see:
  • Cloud service agreement with the security provisions identified
  • Customer review of the agreement against its requirements
  • Record of negotiated security terms
Where it usually falls short:
  • Click-through terms accepted with no review of the security clauses
  • Agreement silent on incident notification or on return of data at termination
Source: ISO/IEC 27017:2015
STAR-SHARED-01 Shared responsibility disclosure

The provider documents and discloses the shared security responsibility model for the service, identifying which CCM controls are the responsibility of the provider, the customer, or shared, consistent with the CCM Shared Security Responsibility Model.

What an assessor asks to see:
  • Shared responsibility matrix mapping CCM controls to provider/customer/shared
  • Customer-facing responsibility guidance
Where it usually falls short:
  • No shared responsibility model published
  • Responsibilities for key controls left undefined
Source: CSA STAR programme
ISO/IEC 27018 A.8.1 Disclosure of sub-contracted PII processing

If the public cloud PII processor uses sub-contractors to process PII, it should disclose this to the relevant cloud service customers before use, so that the customer can object or decline, and should keep the disclosure current as sub-contractors change.

What an assessor asks to see:
  • Published or contractual list of sub-contractors processing PII
  • Notification of changes before use
  • Customer objection mechanism
Where it usually falls short:
  • Sub-processors added without notice
  • List published once and never updated
Source: ISO/IEC 27018:2019
SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls

Assesses and manages risks associated with vendors and business partners

What an assessor asks to see:
  • The vendor and business partner inventory, with risk tiering based on data access and criticality
  • Due diligence records performed before engagement, at the depth the tier requires
  • Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess
  • Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them
  • Evidence of termination handling, including return or deletion of data and revocation of access
Where it usually falls short:
  • Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs
  • Inventory covering vendors known to procurement, missing services engaged directly by teams
  • Due diligence performed at onboarding with no reassessment during a multi year relationship
  • Subservice organisations engaged by the vendor never identified, so risk stops at the first tier
Source: SOC 2 Trust Services Criteria
ISO/IEC 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

What an assessor asks to see:
  • Cloud service selection
  • Cloud contract management
  • Cloud security monitoring
  • Cloud exit plan
Where it usually falls short:
  • Relying solely on provider's security assurances
  • No documented exit or data migration procedures
  • Insufficient risk assessment before cloud onboarding
  • Contracts missing specific security and audit clauses
Source: ISO/IEC 27001:2022 Annex A
CMMC AC.L2-3.1.20 External Connections Level 1 and 2

Verify, then control or limit, connections to and use of external systems that are outside organizational control.

What an assessor asks to see:
  • Inventory of approved external systems and connection terms
  • Agreements or terms governing external system use
  • Technical controls limiting external system connections
Where it usually falls short:
  • External cloud services used without review
  • Connections permitted with no verification of the external party
  • No limit on what CUI may be processed externally
Source: CMMC 2.0
FedRAMP SA-9 External System Services

Require providers of external system services to comply with security/privacy requirements; document oversight roles.

What an assessor asks to see:
  • Control implementation statement for SA-9 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where it usually falls short:
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
Source: FedRAMP Moderate
FedRAMP CA-3 Information Exchange

Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.

What an assessor asks to see:
  • Control implementation statement for CA-3 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where it usually falls short:
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
Source: FedRAMP Moderate
C5-SSO-01 Policies and instructions for controlling and monitoring third parties

Document, communicate and make available policies governing third parties whose services support the cloud service, covering procurement risk assessment, subcontractor classification, security and training obligations, legal duties, vulnerability handling, contractual wording, monitoring, and flow down to their own providers.

What an assessor asks to see:
  • Approved third party control policy with version history and publication record
  • Distribution list showing which procurement and legal staff received the policy
  • Template contract clause library covering security, training and vulnerability obligations
  • Classification rubric distinguishing subcontractors from other suppliers
Where it usually falls short:
  • Policy silent on flow down of obligations to a supplier's own subcontractors
  • No documented rule for deciding when a third party counts as a subcontractor
  • Policy exists but was never issued to the teams that sign supplier contracts
Source: C5 cloud criteria catalogue