Service model
Infrastructure as a service: the shared responsibility split
The provider runs the facility, the hardware and the hypervisor. You run everything from the guest operating system up: the image, its patches, the network you draw inside your account, the identities, the keys, the data and the application.
Of the 14 control areas: 10 yours, 3 shared, 1 the provider's, before any category moves the line.
Every control area
IaaS| Control area | Owner | Why, and the clause |
|---|---|---|
GOV Governance and policy | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
IAM Identity and access | yours | The accounts, roles and second factors inside your tenancy are yours to grant, review and remove; the provider secures only its own staff's privileged access. ISO/IEC 27017 9.2.3 |
DAT Data classification and handling | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
KEY Encryption and keys | yours | On infrastructure you choose whether volumes and objects are encrypted and who holds the keys; the provider supplies the key service, not the decision. ISO/IEC 27017 10.1.2 |
NET Network security | yours | You draw the virtual network, its segments and its rules; the provider keeps tenants apart underneath and runs the physical network. ISO/IEC 27017 CLD.9.5.1 |
LOG Logging and monitoring | yours | Logs from the operating system, your applications and your account activity are yours to switch on, keep and watch; the provider logs its own layers. ISO/IEC 27017 CLD.12.4.5 |
VUL Vulnerability and patch management | yours | You patch the guest operating system, the software on it and your images; the provider patches the hypervisor and the hardware. ISO/IEC 27017 12.6.1 |
CFG Configuration and hardening | yours | The image, the services enabled and every setting from the guest up are yours to harden and hold to a baseline. ISO/IEC 27017 CLD.9.5.2 |
APP Application security | yours | The code you deploy is yours to build and test securely; the provider has no view of it. ISO/IEC 27017 14.2.1 |
INC Incident response | shared | Both sides respond: the provider must report incidents affecting your data within the agreed time, and you must detect and handle incidents in what you run and report to the provider what affects its service. ISO/IEC 27017 16.1.2 |
BCP Business continuity and backup | yours | Backups of your machines and volumes are yours to schedule, protect and test a restore of; the provider keeps the hardware redundant, not your data. ISO/IEC 27017 12.3.1 |
PHY Physical and environmental | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
SUP Supplier and subservice | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
AIR AI use and data retention | yours | What data goes into the service, for what purpose and how long it is kept is yours to decide and delete; the provider stores what you give it. ISO/IEC 27017 CLD.8.1.5 |
Service categories delivered this way by default
10- Virtual machinescompute
- Bare metal serverscompute
- GPU instancescompute
- Object storagestorage
- Block storagestorage
- File storagestorage
- Archive storagestorage
- VPN and remote accessnetwork
- Private connectivitynetwork
- Virtual networknetwork