Cloud Shared Responsibility Mapper
Framework

CSA STAR programme: the clauses behind the split

The assurance programme built on the Cloud Controls Matrix. SHARED-01 asks the provider to disclose its side of the shared responsibility model. Always shown.

Shown on every map. The framework on the compliance library.

Control areas it anchors

1
AreaClause
Supplier and subserviceSTAR-SHARED-01

Every clause cited, quoted

2 of the 24 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

STAR-SHARED-01 Shared responsibility disclosure

The provider documents and discloses the shared security responsibility model for the service, identifying which CCM controls are the responsibility of the provider, the customer, or shared, consistent with the CCM Shared Security Responsibility Model.

What an assessor asks to see:
  • Shared responsibility matrix mapping CCM controls to provider/customer/shared
  • Customer-facing responsibility guidance
Where it usually falls short:
  • No shared responsibility model published
  • Responsibilities for key controls left undefined
Source: CSA STAR programme
STAR-SUPPLY-01 Subservice and supply chain disclosure

The provider identifies subservice organisations and supply chain dependencies relevant to the assessed service, and reflects their treatment (inclusive or carve-out) in the assurance statement.

What an assessor asks to see:
  • List of subservice organisations and the inclusive/carve-out treatment
  • Assurance over relevant subservice controls
Where it usually falls short:
  • Undisclosed subservice dependencies
  • Carve-out subservices with no complementary controls stated
Source: CSA STAR programme