Supplier and subservice: who owns it on each service model
The shared responsibility model itself: the provider publishes its side and its own suppliers, you hold the matrix for your estate and the agreement that binds both.
The split by service model
| Service model | Owner | Why, and the clause |
|---|---|---|
| Infrastructure as a service | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
| Platform as a service | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
| Software as a service | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
| Serverless functions and event services | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
| Hosted AI models and AI platforms | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
The clauses each framework attaches
12 quoted| Framework | Clause |
|---|---|
| Cloud Controls Matrix v4.0.1 | CCM-STA-04 SSRM Control Ownership · CCM-STA-06 SSRM Control Implementation |
| ISO/IEC 27017:2015 | ISO/IEC 27017 CLD.6.3.1 Shared roles and responsibilities within a cloud computing environment · ISO/IEC 27017 15.1.2 Addressing security within supplier agreements |
| CSA STAR programme | STAR-SHARED-01 Shared responsibility disclosure |
| ISO/IEC 27018:2019 | ISO/IEC 27018 A.8.1 Disclosure of sub-contracted PII processing |
| SOC 2 Trust Services Criteria | SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls |
| ISO/IEC 27001:2022 Annex A | ISO/IEC 27001 5.23 Information security for use of cloud services |
| CMMC 2.0 | CMMC AC.L2-3.1.20 External Connections |
| FedRAMP Moderate | FedRAMP SA-9 External System Services · FedRAMP CA-3 Information Exchange |
| C5 cloud criteria catalogue | C5-SSO-01 Policies and instructions for controlling and monitoring third parties |
CCM-STA-04 SSRM Control OwnershipState, control by control, which responsibilities sit with the provider, which sit with the customer and which are shared for the service offered.
- The control by control responsibility matrix for the service
- Evidence every control in the framework carries an ownership determination
- The basis for each shared designation
- Review of the matrix as the service changes
- Matrix covering a subset of controls with the rest left undetermined
- Controls marked shared with no explanation of the split
- Matrix not updated after a service change altered the boundary
CCM-STA-06 SSRM Control ImplementationImplement, operate and assess the parts of the shared responsibility model that fall to the organisation, rather than assuming a provider covers them.
- Evidence of implementation for each customer-side responsibility
- Operating records showing the controls run
- Assessment or audit results covering those controls
- Ownership assigned per responsibility
- Customer-side responsibilities documented but not implemented
- Implementation assumed from a provider certification that does not cover it
- No assessment, so effectiveness of the customer side is unknown
ISO/IEC 27017 CLD.6.3.1 Shared roles and responsibilities within a cloud computing environmentResponsibilities for information security in the use of a cloud service are shared, and the standard requires that they be allocated to identified parties, documented, communicated and implemented by both the cloud service customer and the cloud service provider. The provider should document and publish the responsibilities it takes on and those it leaves with the customer; the customer should record the allocation, assign owners inside its organisation, and act on its share.
- Shared responsibility document for each cloud service, agreed by both parties
- Communication of the allocation to the customer's users and the provider's staff
- Evidence the customer performs its allocated responsibilities
- A published provider responsibility model that the customer never mapped to its own roles
- Allocation that names organisations but no individuals
ISO/IEC 27017 15.1.2 Addressing security within supplier agreementsThe agreement between customer and provider should set out the information security requirements for the cloud service, including the responsibilities of each party, the provider's controls, handling of customer information, incident notification, the customer's rights to information and audit, and what happens at termination. The provider should offer terms that state these, and the customer should confirm the agreement covers its requirements before it uses the service.
- Cloud service agreement with the security provisions identified
- Customer review of the agreement against its requirements
- Record of negotiated security terms
- Click-through terms accepted with no review of the security clauses
- Agreement silent on incident notification or on return of data at termination
STAR-SHARED-01 Shared responsibility disclosureThe provider documents and discloses the shared security responsibility model for the service, identifying which CCM controls are the responsibility of the provider, the customer, or shared, consistent with the CCM Shared Security Responsibility Model.
- Shared responsibility matrix mapping CCM controls to provider/customer/shared
- Customer-facing responsibility guidance
- No shared responsibility model published
- Responsibilities for key controls left undefined
ISO/IEC 27018 A.8.1 Disclosure of sub-contracted PII processingIf the public cloud PII processor uses sub-contractors to process PII, it should disclose this to the relevant cloud service customers before use, so that the customer can object or decline, and should keep the disclosure current as sub-contractors change.
- Published or contractual list of sub-contractors processing PII
- Notification of changes before use
- Customer objection mechanism
- Sub-processors added without notice
- List published once and never updated
SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controlsAssesses and manages risks associated with vendors and business partners
- The vendor and business partner inventory, with risk tiering based on data access and criticality
- Due diligence records performed before engagement, at the depth the tier requires
- Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess
- Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them
- Evidence of termination handling, including return or deletion of data and revocation of access
- Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs
- Inventory covering vendors known to procurement, missing services engaged directly by teams
- Due diligence performed at onboarding with no reassessment during a multi year relationship
- Subservice organisations engaged by the vendor never identified, so risk stops at the first tier
ISO/IEC 27001 5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
- Cloud service selection
- Cloud contract management
- Cloud security monitoring
- Cloud exit plan
- Relying solely on provider's security assurances
- No documented exit or data migration procedures
- Insufficient risk assessment before cloud onboarding
- Contracts missing specific security and audit clauses
CMMC AC.L2-3.1.20 External Connections Level 1 and 2Verify, then control or limit, connections to and use of external systems that are outside organizational control.
- Inventory of approved external systems and connection terms
- Agreements or terms governing external system use
- Technical controls limiting external system connections
- External cloud services used without review
- Connections permitted with no verification of the external party
- No limit on what CUI may be processed externally
FedRAMP SA-9 External System ServicesRequire providers of external system services to comply with security/privacy requirements; document oversight roles.
- Control implementation statement for SA-9 citing the system mission and inheritance from common controls
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
FedRAMP CA-3 Information ExchangeApprove and manage exchange of information with external systems using ISA, MOU, contract; review annually.
- Control implementation statement for CA-3 citing the system mission and inheritance from common controls
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- POAM items past due without justification or risk acceptance
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
C5-SSO-01 Policies and instructions for controlling and monitoring third partiesDocument, communicate and make available policies governing third parties whose services support the cloud service, covering procurement risk assessment, subcontractor classification, security and training obligations, legal duties, vulnerability handling, contractual wording, monitoring, and flow down to their own providers.
- Approved third party control policy with version history and publication record
- Distribution list showing which procurement and legal staff received the policy
- Template contract clause library covering security, training and vulnerability obligations
- Classification rubric distinguishing subcontractors from other suppliers
- Policy silent on flow down of obligations to a supplier's own subcontractors
- No documented rule for deciding when a third party counts as a subcontractor
- Policy exists but was never issued to the teams that sign supplier contracts